# Storing Message in an Array for Slack Notification

**URL:** <https://discuss.elastic.co/t/storing-message-in-an-array-for-slack-notification/97949>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [August 22, 2017, 5:03pm UTC](https://discuss.elastic.co/t/storing-message-in-an-array-for-slack-notification/97949 "2017-08-22T17:03:01Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![lincoln.coe](https://avatars.discourse-cdn.com/v4/letter/l/e99b99/32.png) [@lincoln.coe](https://discuss.elastic.co/u/lincoln.coe)\
**Post date:** [August 22, 2017, 5:03pm UTC](https://discuss.elastic.co/t/storing-message-in-an-array-for-slack-notification/97949/1 "2017-08-22T17:03:01Z")

</div>

I've got most of my watcher setup and running, but right now I'm trying to get the message from all hits to return in the slack notification, but I get a Warning Internal Server Error when saving it and I'm not sure where I've gone wrong.

```
{
      "trigger": {
        "schedule": {
          "interval": "5m"
        }
      },
      "input": {
        "search": {
          "request": {
            "search_type": "query_then_fetch",
            "indices": [],
            "types": [],
            "body": {
              "query": {
                "bool": {
                  "must": {
                    "range": {
                      "Users": {
                        "gte": 2
                      }
                    }
                  },
                  "filter": {
                    "range": {
                      "TimeStamp": {
                        "from": "{{ctx.trigger.scheduled_time}}||-10m",
                        "to": "{{ctx.trigger.triggered_time}}"
                      }
                    }
                  }
                }
              }
            }
          }
        }
      },
      "condition": {
        "compare": {
          "ctx.payload.hits.total": {
            "gt": 0
          }
        }
      },
      "actions": {
        "notify-slack": {
          "throttle_period_in_millis": 9,
          "slack": {
            "message": {
              "from": "Non-Prod Alerts",
              "to": [
                "#alerts"
              ],
              "text": "Non-prod Monitoring",
              "attachments": [
                {
                  "color": "#006000",
                  "title": "Users Found",
                  "text": "{{ctx.payload.hits.total}} Servers have more than 2 users. They are {{ctx.payload.message}} "
                }
              ]
            }
          }
        }
      },
      "transform": {
        "script": {
          "inline": "return ['message' : ctx.payload.hits.hits.collect { it._source.Message }]",
          "lang": "painless"
        }
      }
    }

```

I've also tried taking out it.\_source.Message and saving it still has the same internal server error.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 23, 2017, 7:07am UTC](https://discuss.elastic.co/t/storing-message-in-an-array-for-slack-notification/97949/2 "2017-08-23T07:07:01Z")

</div>

Do you mind pasting the warning (including full possible stack trace) plus anything like that in the log files as well, so everyone can take a look?

Also the Elasticsearch version would be helpful.

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 20, 2017, 7:07am UTC](https://discuss.elastic.co/t/storing-message-in-an-array-for-slack-notification/97949/3 "2017-09-20T07:07:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
