# Variable to store list of recipient addresses for Elastic Watcher

**URL:** <https://discuss.elastic.co/t/variable-to-store-list-of-recipient-addresses-for-elastic-watcher/306108>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [June 1, 2022, 10:21am UTC](https://discuss.elastic.co/t/variable-to-store-list-of-recipient-addresses-for-elastic-watcher/306108 "2022-06-01T10:21:52Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Souvik\_Das](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/souvik_das/32/107606_2.png) [@Souvik\_Das](https://discuss.elastic.co/u/Souvik_Das)\
**Post date:** [June 1, 2022, 10:21am UTC](https://discuss.elastic.co/t/variable-to-store-list-of-recipient-addresses-for-elastic-watcher/306108/1 "2022-06-01T10:21:52Z")

</div>

Hi Team,

In our production setup, we have multiple watcher alerts (around 100), having different sets of recipient email addresses. Now if there is any requirement from the client to update the list, we need to edit 100 watcher scripts which is not a good solution.

Is there a way like an environment variable in watcher scripting? So that if we need to change/update anything in the list, we just need to update that variable and all the watcher scripts will then fetch the updated list from there. No need to edit 100 scripts.

Please guide!

Regards,  
Souvik

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [June 1, 2022, 11:38pm UTC](https://discuss.elastic.co/t/variable-to-store-list-of-recipient-addresses-for-elastic-watcher/306108/2 "2022-06-01T23:38:44Z")

</div>

Perhaps...you could make an Elasticsearch index of the email addresses, driven by a key of some kind and then in your Watch you could load that index as a subsearch within a chained input. An example of a chain input and a lookup (albeit for a different use-case) can be seen here: [example watch with a lookup table of thresholds per term · GitHub](https://gist.github.com/richcollier/2564d80062f6dddf72777f7257285a54)

Then, you can merely modify the email addresses in the lookup index as necessary.

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [June 1, 2022, 11:41pm UTC](https://discuss.elastic.co/t/variable-to-store-list-of-recipient-addresses-for-elastic-watcher/306108/3 "2022-06-01T23:41:47Z")

</div>

Or I guess more simply you can define/edit Watches via the API and use some variables in some scripting language that is making the API calls 😃

---

<div class="post-metadata">

**Author:** ![Souvik\_Das](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/souvik_das/32/107606_2.png) [@Souvik\_Das](https://discuss.elastic.co/u/Souvik_Das)\
**Post date:** [June 3, 2022, 7:02am UTC](https://discuss.elastic.co/t/variable-to-store-list-of-recipient-addresses-for-elastic-watcher/306108/4 "2022-06-03T07:02:55Z")

</div>

Hi @richcollier , thanks for the suggestions, let me work on this. will share the outcome.

---

<div class="post-metadata">

**Author:** ![Souvik\_Das](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/souvik_das/32/107606_2.png) [@Souvik\_Das](https://discuss.elastic.co/u/Souvik_Das)\
**Post date:** [June 14, 2022, 11:34am UTC](https://discuss.elastic.co/t/variable-to-store-list-of-recipient-addresses-for-elastic-watcher/306108/5 "2022-06-14T11:34:27Z")

</div>

Thank you so much @richcollier, Your suggestion worked!!  
Created an index consisting of recipient lists and then used that in the chained input of the watches.  
Below are the steps of my success.

```auto
		  "first": {
			"search": {
			  "request": {
				"search_type": "query_then_fetch",
				"indices": [
				  "recipients"
				],
				"rest_total_hits_as_int": true,
				"body": {
				  "size": 0,
				  "query": {
					"bool": {
					  "minimum_should_match": 1,
					  "should": [
						{
						  "match_phrase": {
							"org": "abc"
						  }
						}
					  ]
					}
				  },
				  "aggs": {
					"emails": {
					  "terms": {
						"field": "email.keyword",
						"size": 1000
					  }
					}
				  }
				}
			  }
			}
		  }

```

And used `{{ctx.payload.first.aggregations.emails.buckets.0.key}}` instead of hard coded email ids and it worked!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 12, 2022, 11:34am UTC](https://discuss.elastic.co/t/variable-to-store-list-of-recipient-addresses-for-elastic-watcher/306108/6 "2022-07-12T11:34:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
