# Problem creating Watch - unable to parse \[search\] input

**URL:** <https://discuss.elastic.co/t/problem-creating-watch-unable-to-parse-search-input/57799>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [August 11, 2016, 11:07am UTC](https://discuss.elastic.co/t/problem-creating-watch-unable-to-parse-search-input/57799 "2016-08-11T11:07:28Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kodkod](https://avatars.discourse-cdn.com/v4/letter/k/82dd89/32.png) [@kodkod](https://discuss.elastic.co/u/kodkod)\
**Post date:** [August 11, 2016, 11:07am UTC](https://discuss.elastic.co/t/problem-creating-watch-unable-to-parse-search-input/57799/1 "2016-08-11T11:07:28Z")

</div>

Ahoy hoy everyone,  
I am unable to create a Watch both using Sense and the REST API as well as using [elasticsearch-watcher-py](https://github.com/elastic/elasticsearch-watcher-py) - somehow I can't seem to get the search request right.  
I've also posted a [question on stackoverflow](http://stackoverflow.com/questions/38892912/elasticsearch-watcher-could-not-parse-search-input) regarding the issue.  
I'm using the following code in elasticsearch-watcher-py.

```auto
est.watcher.put_watch(
    id='a1b_error',
    body={
        # run the watch every night at midnight
        'trigger': { 'schedule': { 'daily': { 'at': 'midnight' }}},
        'condition': { 'script': { 'inline': 'ctx.payload.hits.total > 0' } },
        'input': {
            'search': {
                'requests': {
                    'indices': ['logstash-*'],
                    'body': {
                        'query': {
                            'bool': {
                                'must': [
                                    { 'match': { 'Projekt': 'ourproject' }},
                                    { 'match': { 'Modus': 'production' }},
                                    { 'match': { 'facility': 'somebackend.log' }},
                                    { 'wildcard': { 'message': 'SOMEERROR*' }},
                                    { 'range': { '@timestamp' : { 'gte': 'now-30d', 'lt': 'now' }}}
                                ]
                            }
                        }
                    }
                }
            }
        },
        'actions': {
            'log' : {
                'logging' : {
                    'test': 'Watch triggered!'
                }
            }
        }
    }
)

```

If I use the same search-query in a search using elasticsearch-py it returns results just fine, but when trying to create a watch, I get a status 400 and a parse\_exception telling me "could not parse [search] input for watch [testwatch]. unexpected token [START\_OBJECT]"

Can somebody point out what I'm doing wrong here?  
Thanks in advance, Simon

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [August 11, 2016, 12:09pm UTC](https://discuss.elastic.co/t/problem-creating-watch-unable-to-parse-search-input/57799/2 "2016-08-11T12:09:41Z")

</div>

Hi Simon,

It looks like there may just be a typo - The input search type is looking for `request` rather than `requests`.

You can see an example here:

[https://www.elastic.co/guide/en/watcher/current/watching-marvel-data.html](https://www.elastic.co/guide/en/watcher/current/watching-marvel-data.html)

Let me know if that does the trick!

Thanks,  
Steve

---

<div class="post-metadata">

**Author:** ![kodkod](https://avatars.discourse-cdn.com/v4/letter/k/82dd89/32.png) [@kodkod](https://discuss.elastic.co/u/kodkod)\
**Post date:** [August 11, 2016, 12:36pm UTC](https://discuss.elastic.co/t/problem-creating-watch-unable-to-parse-search-input/57799/3 "2016-08-11T12:36:38Z")

</div>

Hallelujah. You won't believe how often I've compared the example with my code, apparently always missing that stupid typo. Well, I don't know whether to feel stupid for missing it or glad you found it. In any case: Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:43pm UTC](https://discuss.elastic.co/t/problem-creating-watch-unable-to-parse-search-input/57799/4 "2017-07-06T13:43:31Z")

</div>


