# Unable to return multiple returns from transform

**URL:** <https://discuss.elastic.co/t/unable-to-return-multiple-returns-from-transform/134814>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [June 6, 2018, 1:26pm UTC](https://discuss.elastic.co/t/unable-to-return-multiple-returns-from-transform/134814 "2018-06-06T13:26:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![prasad\_dls](https://avatars.discourse-cdn.com/v4/letter/p/dc4da7/32.png) [@prasad\_dls](https://discuss.elastic.co/u/prasad_dls)\
**Post date:** [June 6, 2018, 1:26pm UTC](https://discuss.elastic.co/t/unable-to-return-multiple-returns-from-transform/134814/1 "2018-06-06T13:26:43Z")

</div>

I am new to writing watchers, could you please help on below usecase

Trying to write a watcher which has requirement to have two table in the body of e-mail. Attachment contains table information.

 ![output](https://us1.discourse-cdn.com/elastic/original/3X/6/8/68f81d125e8ba1d4343aaf11327316a8dcdef788.png)

I am unable to return multiple values from "transform" and iterate in Body of the send\_email action.

Here is is my watcher transform,

"transform": {  
"chain": [{  
"script": "return ctx.payload.global\_data.aggregations.group\_by\_exception.buckets.stream().filter( dr -\> { ((dr.range.buckets.earlier.total\_count.value \< 100 && ((dr.range.buckets.latest.total\_count.value-dr.range.buckets.earlier.total\_count.value \> 50) || (dr.range.buckets.earlier.total\_count.value-dr.range.buckets.latest.total\_count.value \> 50))) || (dr.range.buckets.earlier.total\_count.value \> 100 && ((dr.range.buckets.latest.total\_count.value-dr.range.buckets.earlier.total\_count.value \> 50) || (dr.range.buckets.earlier.total\_count.value-dr.range.buckets.latest.total\_count.value \> 50))))}).map(i -\>['app\_name':i.key,'earlier\_count':(int)i.range.buckets.earlier.total\_count.value,'latest\_count':(int)i.range.buckets.latest.total\_count.value, 'gpercentage':((float)((i.range.buckets.latest.total\_count.value - i.range.buckets.earlier.total\_count.value)/(float)(i.range.buckets.earlier.total\_count.value))\*100)]).collect(Collectors.toList());"  
}, {  
"script": "return ctx.payload.app\_wise\_data.aggregations.group\_by\_app.buckets.stream().map(app -\>['App': app.key,'Brands': app.by\_brand.buckets.stream().map(bmap -\>['brand': bmap.key,'DataCenters':bmap.by\_dc.buckets.stream().filter(dm -\> { ((dm.range.buckets.earlier.total\_count.value \< 100 && ((dm.range.buckets.latest.total\_count.value-dm.range.buckets.earlier.total\_count.value \> 50) || (dm.range.buckets.earlier.total\_count.value-dm.range.buckets.latest.total\_count.value \> 50))) || (dm.range.buckets.earlier.total\_count.value \> 100 && ((dm.range.buckets.latest.total\_count.value-dm.range.buckets.earlier.total\_count.value \> 50) || (dm.range.buckets.earlier.total\_count.value-dm.range.buckets.latest.total\_count.value \> 500))))}).map(dcmap -\> ['dc':dcmap.key,'earlier':(int)dcmap.range.buckets.earlier.total\_count.value,'latest':(int)dcmap.range.buckets.latest.total\_count.value,'percentage':(int)(((dcmap.range.buckets.latest.total\_count.value - dcmap.range.buckets.earlier.total\_count.value)/(dcmap.range.buckets.earlier.total\_count.value))\*100),'up':(((dcmap.range.buckets.latest.total\_count.value - dcmap.range.buckets.earlier.total\_count.value)/(dcmap.range.buckets.earlier.total\_count.value))\*100) \> 0.0]).collect(Collectors.toList())]).collect(Collectors.toList())]).collect(Collectors.toList());"  
}]  
}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [July 3, 2018, 8:28am UTC](https://discuss.elastic.co/t/unable-to-return-multiple-returns-from-transform/134814/2 "2018-07-03T08:28:01Z")

</div>

you need to use a script transform, where you do **both** table creations in a single script.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 31, 2018, 8:32am UTC](https://discuss.elastic.co/t/unable-to-return-multiple-returns-from-transform/134814/3 "2018-07-31T08:32:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
