# Use Painless to only return a subset of the Watch payload

**URL:** <https://discuss.elastic.co/t/use-painless-to-only-return-a-subset-of-the-watch-payload/205553>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [October 28, 2019, 9:18pm UTC](https://discuss.elastic.co/t/use-painless-to-only-return-a-subset-of-the-watch-payload/205553 "2019-10-28T21:18:13Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bobes](https://avatars.discourse-cdn.com/v4/letter/b/bcef8e/32.png) [@bobes](https://discuss.elastic.co/u/bobes)\
**Post date:** [October 28, 2019, 9:18pm UTC](https://discuss.elastic.co/t/use-painless-to-only-return-a-subset-of-the-watch-payload/205553/1 "2019-10-28T21:18:14Z")

</div>

Apologies if this has been asked before, but i'm really stumped on this. What i'm trying to do is populate an email action in Watcher with a list of all results where an aggregation returns a doc\_count \> 5. I know the problem is within the action transform but I can't figure out the syntax I am looking for. Removed some info from the query and the actions for privacy reasons.

```
{
  "trigger": {
    "schedule": {
      "interval": "15m"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "heartbeat-*"
        ],
        "rest_total_hits_as_int": true,
        "body": {
          "size": 0,
          "query": {
            "bool": {
              "must": [
                {
                  "range": {
                    "@timestamp": {
                      "from": "now-15m",
                      "to": "now"
                    }
                  }
                }
              ],
              "filter": [
                {
                  "bool": {
                    "filter": [
                      {
                        "bool": {
                          "should": [
                            {
                              "match_phrase": {
                                "monitor.status": "down"
                              }
                            }
                          ]
                        }
                      }
                    ]
                  }
                }
              ]
            }
          },
          "aggs": {
            "endpoints_down": {
              "terms": {
                "field": "agent.hostname",
                "size": 50
              },
              "aggs": {
                "endpoint": {
                  "terms": {
                    "field": "url.full",
                    "size": 50
                  }
                }
              }
            }
          }
        }
      }
    }
  },
  "condition": {
    "script": {
      "source": "return ctx.payload.aggregations.endpoints_down.buckets.size() > 0",
      "lang": "painless"
    }
  },
  "actions": {
    "send_email": {
      "transform": {
        "script": {
          "source": "return ctx.payload.aggregations.endpoints_down.buckets.stream().map(e -> e.key).collect(Collectors.toList());", 
          "lang": "painless"
        }
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 31, 2019, 12:29pm UTC](https://discuss.elastic.co/t/use-painless-to-only-return-a-subset-of-the-watch-payload/205553/2 "2019-10-31T12:29:56Z")

</div>

The `terms` aggregation supports a `min_doc_count` field, so there would not be any need for you to transform your data.

hope this helps!

---

<div class="post-metadata">

**Author:** ![bobes](https://avatars.discourse-cdn.com/v4/letter/b/bcef8e/32.png) [@bobes](https://discuss.elastic.co/u/bobes)\
**Post date:** [October 31, 2019, 3:24pm UTC](https://discuss.elastic.co/t/use-painless-to-only-return-a-subset-of-the-watch-payload/205553/3 "2019-10-31T15:24:10Z")

</div>

thank you! I'll give that a shot. I did manage to get it working with a transform for the time being.

```
"transform": {
   "script": {
   "source": "return ctx.payload.aggregations.endpoint.buckets.stream().filter(endpt -> endpt.doc_count >= 5).map(e -> e.key).collect(Collectors.toList());",
   "lang": "painless"
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 28, 2019, 3:24pm UTC](https://discuss.elastic.co/t/use-painless-to-only-return-a-subset-of-the-watch-payload/205553/4 "2019-11-28T15:24:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
