# Posting my watcher body to a server via webhook

**URL:** <https://discuss.elastic.co/t/posting-my-watcher-body-to-a-server-via-webhook/140179>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [July 16, 2018, 3:31pm UTC](https://discuss.elastic.co/t/posting-my-watcher-body-to-a-server-via-webhook/140179 "2018-07-16T15:31:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![max17](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/max17/32/42694_2.png) [@max17](https://discuss.elastic.co/u/max17)\
**Post date:** [July 16, 2018, 3:31pm UTC](https://discuss.elastic.co/t/posting-my-watcher-body-to-a-server-via-webhook/140179/1 "2018-07-16T15:31:06Z")

</div>

Hello,

I have created a watcher to monitor my server memory usage, which is working fine but here I want to post the email result to a 3rd platform or the same server. I searched about it and found that we can do it via webhook. As I am completely new to webhook concept, I request you to please explain me how I will able to post the email result to a platform and where I require to configure the details of the host where I want to post the details.

Below is the watcher I created. Please have a look

---

<div class="post-metadata">

**Author:** ![max17](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/max17/32/42694_2.png) [@max17](https://discuss.elastic.co/u/max17)\
**Post date:** [July 16, 2018, 3:35pm UTC](https://discuss.elastic.co/t/posting-my-watcher-body-to-a-server-via-webhook/140179/2 "2018-07-16T15:35:57Z")

</div>

{  
"trigger": {  
"schedule": {  
"interval": "1m"  
}

},

"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"metricbeat-wp-xyz\*"

```
    ], 
    "types": [],
    "body": {
      "size": 0,
      "query": {
        "bool": {
          "filter": {
            "range": {
              "@timestamp": {
                "gte": "{{ctx.trigger.scheduled_time}}||-1d",
                "lte": "{{ctx.trigger.scheduled_time}}",
                "format": "strict_date_optional_time||epoch_millis"
              }
            }
          }
        }
      },
      "aggs": {
        "bucketAgg": {
          "terms": {
            "field": "beat.hostname",
            "size": 50,
            "order": {
              "metricAgg": "desc"
            }
          },
          "aggs": {
            "metricAgg": {
              "avg": {
                "field": "system.memory.used.pct"
              }
            }
          }
        }
      }
    }
  }
}

```

},  
"condition": {  
"script": {  
"source": "ArrayList arr = ctx.payload.aggregations.bucketAgg.buckets; for (int i = 0; i \< arr.length; i++)  
{ if (arr[i]['metricAgg'].value \> params.threshold) { return true; } } return false;",  
"lang": "painless",  
"params": {  
"threshold": 0.9  
}  
}  
},  
"actions": {  
"email\_1": {  
"email": {  
"account": "gmail\_account",  
"profile": "gmail",  
"to": [  
"xyz@gmail.com"

```
    ],
    "subject": "Alert! High Memory Consumption Found On The Server",
    "body": {
      "text": "The following hosts have exceeded the Memory threshold: \n{{#ctx.payload.results}}{{key}}:{{value}}%\n{{/ctx.payload.results}} \n\n at times: {{ctx.trigger.triggered_time}} \n\n"
    }
  }
}

```

},

"metadata": {  
"watcherui": {  
"trigger\_interval\_unit": "m",  
"agg\_type": "avg",  
"time\_field": "@timestamp",  
"trigger\_interval\_size": 1,  
"term\_size": 50,  
"time\_window\_unit": "d",  
"threshold\_comparator": "\>",  
"term\_field": "beat.hostname",  
"index": [  
"metricbeat-wp-xyz\*"

```
  ],
  "time_window_size": 1,
  "threshold": 0.9,
  "agg_field": "system.memory.used.pct"
}

```

},  
"transform": {  
"script": {  
"source": "HashMap result = new HashMap(); ArrayList arr = ctx.payload.aggregations.bucketAgg.buckets; ArrayList filteredHits = new ArrayList(); for (int i = 0; i \< arr.length; i++) { HashMap filteredHit = new HashMap(); filteredHit.key = arr[i].key; filteredHit.value = Math.round(arr[i]['metricAgg'].value\*100); if (filteredHit.value \> params.threshold) { filteredHits.add(filteredHit); } } result.results = filteredHits; return result;",  
"lang": "painless",  
"params": {  
"threshold": 0.9  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [July 17, 2018, 6:52am UTC](https://discuss.elastic.co/t/posting-my-watcher-body-to-a-server-via-webhook/140179/3 "2018-07-17T06:52:55Z")

</div>

hey,

you would indeed replace the email action with a webhook action, if you email provider wants you to use HTTP instead of SMTP. The documentation for the [webhook action](https://www.elastic.co/guide/en/elastic-stack-overview/6.3/actions-webhook.html) also shows how to use it.

Is there any concrete problem we can help with?

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 14, 2018, 6:52am UTC](https://discuss.elastic.co/t/posting-my-watcher-body-to-a-server-via-webhook/140179/4 "2018-08-14T06:52:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
