# Unable to modify values from Payload

**URL:** <https://discuss.elastic.co/t/unable-to-modify-values-from-payload/129047>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [April 23, 2018, 7:00am UTC](https://discuss.elastic.co/t/unable-to-modify-values-from-payload/129047 "2018-04-23T07:00:13Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Himanshu\_Rajput](https://avatars.discourse-cdn.com/v4/letter/h/f05b48/32.png) [@Himanshu\_Rajput](https://discuss.elastic.co/u/Himanshu_Rajput)\
**Post date:** [April 23, 2018, 7:00am UTC](https://discuss.elastic.co/t/unable-to-modify-values-from-payload/129047/1 "2018-04-23T07:00:14Z")

</div>

Hi,

I am trying to create this watch-

{  
"trigger": {  
"schedule": {  
"interval": "5s"  
}  
},  
"input": {  
"search": {  
"request": {  
"indices": [  
".marvel-\*"  
],  
"search\_type": "count",  
"body": {  
"query": {  
"filtered": {  
"filter": {  
"range": {  
"@timestamp": {  
"gte": "now-2m",  
"lte": "now"  
}  
}  
}  
}  
},  
"aggs": {  
"minutes": {  
"date\_histogram": {  
"field": "@timestamp",  
"interval": "minute"  
},  
"aggs": {  
"nodes": {  
"terms": {  
"field": "node.name.raw",  
"size": 24,  
"order": {  
"memory": "desc"  
}  
},  
"aggs": {  
"memory": {  
"avg": {  
"field": "fs.data.available\_in\_bytes"  
}  
}  
}  
}  
}  
}  
}  
}  
}  
}  
},  
"throttle\_period": "20s",  
"condition": {  
"script": "if (ctx.payload.aggregations.minutes.buckets.size() == 0) return false; def latest = ctx.payload.aggregations.minutes.buckets[-1]; def node = latest.nodes.buckets[0]; return node && node.memory && node.memory.value \>= 0;"  
},  
"actions": {  
"send\_email": {  
"transform": {  
"script": "def latest = ctx.payload.aggregations.minutes.buckets[-1]; return latest.nodes.buckets.findAll { return it.memory && it.memory.value \>= 0 };"  
},  
"email": {  
"to": "abcd@123.com",  
"subject": "Watcher Notification - HIGH Disk USAGE",  
"body": "Nodes with HIGH DISK Usage (above 0):\n\n{{#ctx.payload.\_value}}"{{key}}" - Available Disk {{ memory.value }}\n{{/ctx.payload.\_value}}"  
}  
}  
}  
}

This is creating an email with the available disk on each node of an ES cluster. Here the size is in Bytes. Now I want to convert it to GBs but It's failing every time with "Failed to transform payload".

Note- ES version 1.7.1  
Watcher version 1.3.1

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 23, 2018, 1:17pm UTC](https://discuss.elastic.co/t/unable-to-modify-values-from-payload/129047/2 "2018-04-23T13:17:34Z")

</div>

this is ancient version of elasticsearch and watcher. you should really upgrade.

can you share the execute watch api output?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 21, 2018, 1:17pm UTC](https://discuss.elastic.co/t/unable-to-modify-values-from-payload/129047/3 "2018-05-21T13:17:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
