# Unable to parse watcher payload field which contains a json

**URL:** <https://discuss.elastic.co/t/unable-to-parse-watcher-payload-field-which-contains-a-json/351157>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [January 16, 2024, 11:45am UTC](https://discuss.elastic.co/t/unable-to-parse-watcher-payload-field-which-contains-a-json/351157 "2024-01-16T11:45:34Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![AlekseyK](https://avatars.discourse-cdn.com/v4/letter/a/bbe5ce/32.png) [@AlekseyK](https://discuss.elastic.co/u/AlekseyK)\
**Post date:** [January 16, 2024, 11:45am UTC](https://discuss.elastic.co/t/unable-to-parse-watcher-payload-field-which-contains-a-json/351157/1 "2024-01-16T11:45:34Z")

</div>

Hello,  
I have a watcher that works perfectly fine and when executed I get an email in html format listing basic string and numeric fields I chose to select from a hit. I use a webhook action to email the results. Now, I want to extract another field, however, its value is a json and for the life of me I cannot figure out how to. I get an error when I simulate within execute mode for my webhook action.

```auto
"body": "{\"statusCode\":400,\"messages\":[\"JSON parse error: Unexpected character ('c' (code 99)): was expecting comma to separate Object entries;

```

'c' happens to be the first character of the first element inside a json object. When I look at the simulator response I can see that the json is provided as a string and therefore " are escaped with `\"` , but when it tries to format it for the email body it is expecting straight json.

so, I decided to user "transform" parameter and script it to return the field string replacing `\"` with " or even just `\` with nothing.

```auto
"transform" : {
      "script" : "return ['requestBody': ctx.payload.hits.hits.0._source.message.ApiData.RequestBody.replace('\\','')]"
  }

```

but I cannot find the right syntax to properly replace the darn thing. I have tried `'\\'` and `/\/g` and I ether ger syntax compile error when simulating or nothing is removed. I can replace any other char withing my message.ApiData.RequestBody field, just not the \ one

it could be something to do with the webhook and the mustache template and I'd be clueless. I know it works groovy if I dont try to extract that field and fails when I do (fails only when I execute the webhook action to get an email) . Actual watcher executes just fine and input looks good.

```auto
 "transform" : {
      "script" : "return ['requestBody': ctx.payload.hits.hits.0._source.message.ApiData.RequestBody.replace('\\','')]"
  },
  "actions": {
    "notification_webhook": {
      "webhook": {
        "scheme": "http",
        "host": "host.com",
        "port": 80,
        "method": "post",
        "path": "our_notifications_path",
        "params": {},
        "headers": {
          "Content-Type": "application/json"
        },
        "body": {
          "source": {
            "notificationRequest": {
              "email": {
                "to": [
                  "me@me.com"
                ],
                "from": "them@them.com",
                "subject": "I got errors!",
                "text": """I have <b>{{ctx.payload.hits.total}} errors in past 10 minutes.</b>
                <br><br> {{ctx.payload.requestBody}} 
                </b><br>ctx.payload.hits.hits.0._source.@timestamp""",
                "priority": "high"
              }
            }
          },
          "lang": "mustache",
          "options": {
            "content_type": "application/html; charset=UTF-8"
          }
        }
      }
    }
  }

```

any ideas?

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [January 30, 2024, 10:55am UTC](https://discuss.elastic.co/t/unable-to-parse-watcher-payload-field-which-contains-a-json/351157/2 "2024-01-30T10:55:06Z")

</div>

> [@AlekseyK](#):
>
> Hello,  
> I have a watcher that works perfectly fine and when executed I get an email in html format listing basic string and numeric fields I chose to select from a hit. I use a webhook action to email the results. Now, I want to extract another field, however, its value is a json and for the life of me I cannot figure out how to. I get an error when I simulate within execute mode for my webhook action.
> 
> ```auto
> "body": "{\"statusCode\":400,\"messages\":[\"JSON parse error: Unexpected character ('c' (code 99)): was expecting comma to separate Object entries;
> 
> ```
> 
> 'c' happens to be the first character of the first element inside a json object. When I look at the simulator response I can see that the json is provided as a string and therefore " are escaped with `\"` , but when it tries to format it for the email body it is expecting straight json.
> 
> so, I decided to user "transform" parameter and script it to return the field string replacing `\"` with " or even just `\` with nothing.
> 
> ```auto
> "transform" : {
> "script" : "return ['requestBody': ctx.payload.hits.hits.0._source.message.ApiData.RequestBody.replace('\\','')]"
> }
> 
> ```
> 
> but I cannot find the right syntax to properly replace the darn thing. I have tried `'\\'` and `/\/g` and I ether ger syntax compile error when simulating or nothing is removed. I can replace any other char withing my message.ApiData.RequestBody field, just not the \ one
> 
> it could be something to do with the webhook and the mustache template and I'd be clueless. I know it works groovy if I dont try to extract that field and fails when I do (fails only when I execute the webhook action to get an email) . Actual watcher executes just fine and input looks good.
> 
> ```auto
> "transform" : {
> "script" : "return ['requestBody': ctx.payload.hits.hits.0._source.message.ApiData.RequestBody.replace('\\','')]"
> },
> "actions": {
> "notification_webhook": {
> "webhook": {
> "scheme": "http",
> "host": "host.com",
> "port": 80,
> "method": "post",
> "path": "our_notifications_path",
> "params": {},
> "headers": {
> "Content-Type": "application/json"
> },
> "body": {
> "source": {
> "notificationRequest": {
> "email": {
> "to": [
> "me@me.com"
> ],
> "from": "them@them.com",
> "subject": "I got errors!",
> "text": """I have <b>{{ctx.payload.hits.total}} errors in past 10 minutes.</b>
> <br><br> {{ctx.payload.requestBody}} 
> </b><br>ctx.payload.hits.hits.0._source.@timestamp""",
> "priority": "high"
> }
> }
> },
> "lang": "mustache",
> "options": {
> "content_type": "application/html; charset=UTF-8"
> }
> }
> }
> }
> }
> 
> ```
> 
> any ideas?

Hi,

In your case, the backslash `\` is a special character that needs to be escaped.

In your transform script, you're trying to replace the backslash `\` with an empty string. However, the backslash itself needs to be escaped, so you should use double backslashes `\\` to represent a single backslash.

Regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 27, 2024, 10:56am UTC](https://discuss.elastic.co/t/unable-to-parse-watcher-payload-field-which-contains-a-json/351157/3 "2024-02-27T10:56:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
