# Using the payload data (fields) after aggregated to bucket, in Elastic Watcher Action email

**URL:** <https://discuss.elastic.co/t/using-the-payload-data-fields-after-aggregated-to-bucket-in-elastic-watcher-action-email/300779>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [March 27, 2022, 11:26am UTC](https://discuss.elastic.co/t/using-the-payload-data-fields-after-aggregated-to-bucket-in-elastic-watcher-action-email/300779 "2022-03-27T11:26:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![SararhHewage](https://avatars.discourse-cdn.com/v4/letter/s/b5ac83/32.png) [@SararhHewage](https://discuss.elastic.co/u/SararhHewage)\
**Post date:** [March 27, 2022, 11:26am UTC](https://discuss.elastic.co/t/using-the-payload-data-fields-after-aggregated-to-bucket-in-elastic-watcher-action-email/300779/1 "2022-03-27T11:26:08Z")

</div>

HI,

I am seeking some help to resolve an issue that I am having in one of my Elastic Watchers. First of all, I must say this is a complex Watcher.

In our environment, we gather some log data from file transferring jobs from various nodes' log files and send them to elastic via Logstash. This part works and we variously use those documents.

I am developing a watcher to find any errors from log files and send alert emails. That is working(This is version one of my solution).

I am running the watcher for every 15 minutes and scan the data for 15 minutes periods back from now and then aggregate the documents to brackets based on the log file name filed. That part also works.

The email action I run for each aggregated buckets ("foreach": "ctx.payload.aggregations._ **failed\_transfers** _.buckets") and email Subject line I print {{ctx.payload.doc\_count}} and {{ctx.payload.key}}. That part also works.

What I am failed to do is, in the email body repeat each document’s-related information.

This means each email will have several lines, one line per document saying what is the error and @timestamp of the error and other information about that error. For this, I am unable to get the correct variable names.

I can see the ctx.payload.hits.hits have all this information, but after aggregating to buckets based on the source of the error (in this case the log file name), I don't know how to access those initial payload field values.

If someone can help me with the proper syntax, highly appreciated it.

Best Regards

Sarath

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 28, 2022, 8:04am UTC](https://discuss.elastic.co/t/using-the-payload-data-fields-after-aggregated-to-bucket-in-elastic-watcher-action-email/300779/2 "2022-03-28T08:04:32Z")

</div>

Hey,

you cannot access the global payload within a for loop currently, just the part of that iteration. Feel free to open a feature request in the Elasticsearch repo.

As a workaround, you could use a transform to include the bucket data from your aggregation and the hits in your own list, and then use `foreach` on that list.

--Alex

---

<div class="post-metadata">

**Author:** ![SararhHewage](https://avatars.discourse-cdn.com/v4/letter/s/b5ac83/32.png) [@SararhHewage](https://discuss.elastic.co/u/SararhHewage)\
**Post date:** [March 29, 2022, 11:21am UTC](https://discuss.elastic.co/t/using-the-payload-data-fields-after-aggregated-to-bucket-in-elastic-watcher-action-email/300779/3 "2022-03-29T11:21:21Z")

</div>

Hi Alex,

Thanks for the reply.

_"As a workaround, you could use a transform to include the bucket data from your aggregation and the hits in your own list, and then use `foreach` on that list."_  
How can do this? I am already using 'foreach', for the bucket aggregate

Best Regards  
Sarath

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 29, 2022, 12:08pm UTC](https://discuss.elastic.co/t/using-the-payload-data-fields-after-aggregated-to-bucket-in-elastic-watcher-action-email/300779/4 "2022-03-29T12:08:40Z")

</div>

Transforms allow you to modify your data... see [Watcher script payload transform | Elasticsearch Guide [8.1] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.1/transform-script.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 26, 2022, 12:09pm UTC](https://discuss.elastic.co/t/using-the-payload-data-fields-after-aggregated-to-bucket-in-elastic-watcher-action-email/300779/5 "2022-04-26T12:09:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
