# Problem with mustache on watcher action

**URL:** <https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [June 7, 2019, 11:10am UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745 "2019-06-07T11:10:28Z")\
**Posts on this page:** 8\
**Page:** 2

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 17, 2019, 12:50pm UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/21 "2019-06-17T12:50:10Z")

</div>

```auto
        "body": "{{#toJson}}payload{{/toJson}}"

```

this must be (in hook tornado2)

```auto
        "body": "{{#toJson}}ctx.payload{{/toJson}}"

```

the logging message you shared above still references `{{payload.hits.totals}}` instead of `{{ctx.payload.hits.totals}}`

---

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [June 17, 2019, 1:16pm UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/22 "2019-06-17T13:16:45Z")

</div>

Hi @spinscale

I change the watcher following your note but the result of the message is the same

```
    "msg": "Watcher Notification Encountered {{ctx.payload.hits.totals}} failed logon from user {{ctx.payload.hits.hits.0._source.winlog.event_data.TargetUserName}}.",

```

The watcher is here

```
{
  "trigger": {
    "schedule": {
      "interval": "5m"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "winlogbeat-*"
        ],
        "types": [],
        "body": {
          "query": {
            "bool": {
              "filter": [
                {
                  "range": {
                    "@timestamp": {
                      "from": "now-5m",
                      "to": "now"
                    }
                  }
                },
                {
                  "match": {
                    "winlog.event_id": "4625"
                  }
                }
              ]
            }
          },
          "aggs": {
            "users": {
              "terms": {
                "field": "winlog.event_data.TargetUserName.keyword",
                "size": 10
              }
            }
          }
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "gte": 10
      }
    }
  },
  "actions": {
    "my-logging-action": {
      "logging": {
        "level": "info",
        "text": "Watcher Notification Encountered {{ctx.payload.hits.total}} failed logon from user {{#ctx.payload.hits.hits.0}}{{_source.winlog.event_data.TargetUserName}}{{/ctx.payload.hits.hits.0}}."
      }
    },
    "hook-tornado": {
      "webhook": {
        "scheme": "http",
        "host": "localhost",
        "port": 8080,
        "method": "post",
        "path": "/event/webhook-elastic",
        "params": {
          "token": "123"
        },
        "headers": {},
        "body": "{{#toJson}}ctx.payload{{/toJson}}"
      }
    },
    "hook-tornado2": {
      "transform" : { 
      	"script" : "def payload = ctx.payload; payload.msg = 'Watcher Notification Encountered {{ctx.payload.hits.totals}} failed logon from user {{ctx.payload.hits.hits.0._source.winlog.event_data.TargetUserName}}.'; return payload;"
      },           
      "webhook": {
        "scheme": "http",
        "host": "localhost",
        "port": 8080,
        "method": "post",
        "path": "/event/failed-passwords",
        "params": {
          "token": "abc"
        },
        "headers": {},
        "body": "{{#toJson}}ctx.payload{{/toJson}}"
      }
    }
  }
}

```

And the output is here

[https://jsonblob.com/16e29212-9102-11e9-959d-1337d0458def](https://jsonblob.com/16e29212-9102-11e9-959d-1337d0458def)

Thank you  
Franco

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 18, 2019, 12:12pm UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/23 "2019-06-18T12:12:51Z")

</div>

sorry, I misread your scripting. The issue here is that you cannot use mustache within painless.

You need to do something like this in a painless script to concatenate strings (or you are using mustache again to create strings and only painless to provide the proper data structures).

```auto
"script": "def payload = ctx.payload; payload.msg = 'Watcher Notification Encountered ' + ctx.payload.hits.total + ' failed logon from user ' + ctx.payload.hits.hits[0]._source.winlog.event_data.TargetUserName+ '.'; return payload;"

```

---

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [June 18, 2019, 12:48pm UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/24 "2019-06-18T12:48:54Z")

</div>

Do you give me an example that could do a concatenate of string in this watcher?

Thank you  
Franco

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 18, 2019, 12:53pm UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/25 "2019-06-18T12:53:07Z")

</div>

if you keep using `{{toJson}}` in the `body` I think the above approach is the most suitable one.

---

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [June 18, 2019, 8:53pm UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/26 "2019-06-18T20:53:50Z")

</div>

Thank you @spinscale. I hope to have understand. I test it in the next days and I give you a feedback.

I see that I use wrong concatenate string in my script

```auto
"script" : "def payload = ctx.payload; payload.msg = 'Watcher Notification Encountered {{ctx.payload.hits.totals}} failed logon from user {{ctx.payload.hits.hits.0._source.winlog.event_data.TargetUserName}}.'; return payload;"

```

instead of your script code

```auto
"script": "def payload = ctx.payload; payload.msg = 'Watcher Notification Encountered ' + ctx.payload.hits.total + ' failed logon from user ' + ctx.payload.hits.hits[0]._source.winlog.event_data.TargetUserName+ '.'; return payload;"

```

At the end I set again

```auto
"body": "{{#toJson}}payload{{/toJson}}"

```

Because in the transform I return payload  
See you soon  
Franco

---

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [June 23, 2019, 9:01pm UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/27 "2019-06-23T21:01:41Z")

</div>

Great @spinscale!!!!

Now it's ok, I tried it.

I will start this week with this new knowledge 🙂

Thank you  
Franco

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 21, 2019, 9:01pm UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745/28 "2019-07-21T21:01:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

[Previous page](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745.md?page=1)
