# Passing ctx fields to stored proc as parameter

**URL:** <https://discuss.elastic.co/t/passing-ctx-fields-to-stored-proc-as-parameter/149742>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [September 24, 2018, 10:04pm UTC](https://discuss.elastic.co/t/passing-ctx-fields-to-stored-proc-as-parameter/149742 "2018-09-24T22:04:17Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Matt\_McGovern](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_mcgovern/32/90131_2.png) [@Matt\_McGovern](https://discuss.elastic.co/u/Matt_McGovern)\
**Post date:** [September 24, 2018, 10:04pm UTC](https://discuss.elastic.co/t/passing-ctx-fields-to-stored-proc-as-parameter/149742/1 "2018-09-24T22:04:17Z")

</div>

I am managing hundreds of scripts that all use an inline script to go through the nested buckets inside the ctx.payload structure. We've recently run into the circuit break error of: "reason": "[script] Too many dynamic script compilations within, max: [75/5m]; please use indexed, or scripts with parameters instead; this limit can be changed by the [script.max\_compilations\_rate] setting".

We can increase that setting, but going forward it would be better if I could create a stored script and have all the watchers call it. The problem is I haven't been able to send the ctx.payload structure through as a parameter.

Is there any way of doing this?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 25, 2018, 9:10am UTC](https://discuss.elastic.co/t/passing-ctx-fields-to-stored-proc-as-parameter/149742/2 "2018-09-25T09:10:54Z")

</div>

Can you explain what you are doing instead of sending ctx.payload as a parameter? Can you show the request you want to generate?

Maybe just share a whole sample watch, if possible?

--Alex

---

<div class="post-metadata">

**Author:** ![elastock](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elastock/32/35672_2.png) [@elastock](https://discuss.elastic.co/u/elastock)\
**Post date:** [September 25, 2018, 1:52pm UTC](https://discuss.elastic.co/t/passing-ctx-fields-to-stored-proc-as-parameter/149742/3 "2018-09-25T13:52:55Z")

</div>

stored scripts have access to the payload .

> ```
> POST _scripts/the_script`
> {"script": {
> "lang": "painless",
> "code": """ def docs = []
> docs.add(['_id': ctx.payload.hits.hits[0]._id]);
> """
> }
> }
> 
> ```

they must be executed after the payload has been returned

---

<div class="post-metadata">

**Author:** ![Matt\_McGovern](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_mcgovern/32/90131_2.png) [@Matt\_McGovern](https://discuss.elastic.co/u/Matt_McGovern)\
**Post date:** [September 25, 2018, 2:30pm UTC](https://discuss.elastic.co/t/passing-ctx-fields-to-stored-proc-as-parameter/149742/4 "2018-09-25T14:30:29Z")

</div>

//here is the stored script \_scripts/IsAppTotalsInErrPct:  
if(params.ApplicationTotals.buckets.length\>0)  
{  
for(int a=0;a\<params.ApplicationTotals.buckets.length;++a)  
{  
if(params.ApplicationTotals.buckets[a].ContractTotals.buckets.length\>0)  
{  
for(int c=0;c\<params.ApplicationTotals.buckets[a].ContractTotals.buckets.length;++c)  
{  
if(params.ApplicationTotals.buckets[a].ContractTotals.buckets[c].Errorpercent.value\>=params.Threshold)  
{  
if(params.ApplicationTotals.buckets[a].ContractTotals.buckets[c].Contract\_Errors.doc\_count\>=params.MinimumErrRecords)  
{  
return true;  
}  
}  
}  
}  
}  
}  
return false;

//here is the watcher that will call the stored script above:  
{  
"trigger": {  
"schedule": {  
"interval": "1m"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"prod-logs\*"  
],  
"types": [],  
"body": {  
"size": 0,  
"query": {  
"bool": {  
"filter": [  
{  
"term": {  
"BaseUrl": "[https://login.comcast.net](https://login.comcast.net)"  
}  
},  
{  
"range": {  
"@timestamp": {  
"gte": "now-10m"  
}  
}  
}  
]  
}  
},  
"aggs": {  
"ApplicationTotals": {  
"terms": {  
"field": "AppName"  
},  
"aggs": {  
"ContractTotals": {  
"terms": {  
"field": "Resource"  
},  
"aggs": {  
"Contract\_Errors": {  
"filter": {  
"term": {  
"Severity": "high"  
}  
}  
},  
"Errorpercent": {  
"bucket\_script": {  
"buckets\_path": {  
"totalcount": "\_count",  
"failurecount": "Contract\_Errors.\_count"  
},  
"script": "Math.round(params.failurecount / params.totalcount \* 10000.000) / 100.000"  
}  
}  
}  
}  
}  
}  
}  
}  
}  
}  
},  
"condition": {  
"script": {  
"id": "IsAppTotalsInErrPct",  
"params": {  
"ApplicationTotals": "{{ctx.payload.aggregations.ApplicationTotals}}",  
"Threshold": "0",  
"MinimumErrRecords": "0"  
}  
}  
},  
"actions": {  
"notify-slack": {  
"throttle\_period\_in\_millis": 300000,  
"transform" : {  
"script" : {  
"source" : "String errMsg='';if(ctx.payload.aggregations.ApplicationTotals.buckets.length\>0){for(int a=0;a\<ctx.payload.aggregations.ApplicationTotals.buckets.length;++a){if(ctx.payload.aggregations.ApplicationTotals.buckets[a].ContractTotals.buckets.length\>0){for(int c=0;c\<ctx.payload.aggregations.ApplicationTotals.buckets[a].ContractTotals.buckets.length;++c){if(ctx.payload.aggregations.ApplicationTotals.buckets[a].ContractTotals.buckets[c].Errorpercent.value\>=\<\>){if(ctx.payload.aggregations.ApplicationTotals.buckets[a].ContractTotals.buckets[c].Contract\_Errors.doc\_count\>=\<\>){errMsg+=ctx.payload.aggregations.ApplicationTotals.buckets[a].key+', '+ctx.payload.aggregations.ApplicationTotals.buckets[a].ContractTotals.buckets[c].key+' '+ctx.payload.aggregations.ApplicationTotals.buckets[a].ContractTotals.buckets[c].Errorpercent.value+'%\n'+ctx.payload.aggregations.ApplicationTotals.buckets[a].ContractTotals.buckets[c].Contract\_Errors.doc\_count + ' errors out of ' + ctx.payload.aggregations.ApplicationTotals.buckets[a].ContractTotals.buckets[c].doc\_count + ' documents.\n'}}}}}}return errMsg;",  
"lang" : "painless"  
}  
},  
"slack": {  
"message": {  
"from": "Kibana Watcher",  
"to": [  
"#slackchannel"  
],  
"text": "Exception rate alert received",  
"attachments": [  
{  
"color": "danger",  
"title": "Elevated Error Rate above \<\>% for time: \<\>",  
"title\_link": "Our Kibana URL",  
"text": "{{ctx.payload.\_value}}"  
}  
]  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![Matt\_McGovern](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_mcgovern/32/90131_2.png) [@Matt\_McGovern](https://discuss.elastic.co/u/Matt_McGovern)\
**Post date:** [September 25, 2018, 2:44pm UTC](https://discuss.elastic.co/t/passing-ctx-fields-to-stored-proc-as-parameter/149742/5 "2018-09-25T14:44:38Z")

</div>

Elastock, to do this, my watcher (posted above) would have to first post the payload to the docs array, then call the stored script which would access it?

---

<div class="post-metadata">

**Author:** ![Matt\_McGovern](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_mcgovern/32/90131_2.png) [@Matt\_McGovern](https://discuss.elastic.co/u/Matt_McGovern)\
**Post date:** [October 8, 2018, 9:26pm UTC](https://discuss.elastic.co/t/passing-ctx-fields-to-stored-proc-as-parameter/149742/6 "2018-10-08T21:26:27Z")

</div>

I was able to solve my problem....the ctx is not passed through as a parameter; it is recognized by session. I have many watchers all calling the same stored script which references ctx.payload. When the script is called it references the ctx that corresponds to the session of the watcher that calls it at the time. I didn't think this would work but that is exactly how it works.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 5, 2018, 9:26pm UTC](https://discuss.elastic.co/t/passing-ctx-fields-to-stored-proc-as-parameter/149742/7 "2018-11-05T21:26:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
