# Watch-history fieldname error

**URL:** <https://discuss.elastic.co/t/watch-history-fieldname-error/73364>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [January 31, 2017, 12:45pm UTC](https://discuss.elastic.co/t/watch-history-fieldname-error/73364 "2017-01-31T12:45:52Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ryan\_Grannell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_grannell/32/41712_2.png) [@Ryan\_Grannell](https://discuss.elastic.co/u/Ryan_Grannell)\
**Post date:** [January 31, 2017, 12:45pm UTC](https://discuss.elastic.co/t/watch-history-fieldname-error/73364/1 "2017-01-31T12:45:52Z")

</div>

Version: v2.4.3

Hi,

I'm currently running into a problem where the watch-history record for a particular watcher isn't index due complains about the fieldname `ctx.payload.hits.total`:

```
[2017-01-31 11:33:51,687][ERROR][watcher.execution] failed to update watch record [recovery_ceased_log_source_***_dev_wa_userapi_cus_1689-2017-01-31T11:33:51.268Z] MapperParsingException[Field name [ctx.payload.hits.total] cannot contain '.']

```

This is unfortunate, as I need my `watch-history-*` indices to contain 100% accurate data. I have a series of "recovery" watchers that read through the execution history, and send a 'recovered' message when things are back to normal (e.g excess disk usage watcher stopped triggering)

Is there any easy way to fix this?

The watcher that triggered this error is included below. It is a chained-input watcher that checks:

- did the `ceased_log_source` watcher execute?
- did the `ceased_log_source` watcher "recover"?
- did this watcher trigger?
  - if so, don't pass this watcher's condition

- otherwise, was the input-order the order `executed -> recovered`?
  - if so, trigger this watcher

> <http://pastebin.com/raw/UTT1iQFX>

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [January 31, 2017, 1:11pm UTC](https://discuss.elastic.co/t/watch-history-fieldname-error/73364/2 "2017-01-31T13:11:32Z")

</div>

Hey,

can you paste the output of an `_execute` run, so that we can see the output that is supposed to be stored in the watch history?

--Alex

---

<div class="post-metadata">

**Author:** ![Ryan\_Grannell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_grannell/32/41712_2.png) [@Ryan\_Grannell](https://discuss.elastic.co/u/Ryan_Grannell)\
**Post date:** [January 31, 2017, 2:24pm UTC](https://discuss.elastic.co/t/watch-history-fieldname-error/73364/3 "2017-01-31T14:24:59Z")

</div>

Hi Alex,

Sure; here's

> <http://pastebin.com/raw/XT2Ve7KL>

and with `"ignore-condition": true`

> <http://pastebin.com/raw/SpRZAuYz>

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [January 31, 2017, 4:28pm UTC](https://discuss.elastic.co/t/watch-history-fieldname-error/73364/4 "2017-01-31T16:28:32Z")

</div>

Hey,

After a quick glance I think there is an issue with the mapping of chained inputs, where fields are accidentally mapped that should not be... will keep you posted

--Alex

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [January 31, 2017, 5:11pm UTC](https://discuss.elastic.co/t/watch-history-fieldname-error/73364/5 "2017-01-31T17:11:01Z")

</div>

Hey,

so the the default setup looks ok to me (tested with a fresh installation, no old data). Can you show me

- The output of `GET /_template/watch_history`
- The output of a mapping of the affected watch history index

Thanks!

--Alex

---

<div class="post-metadata">

**Author:** ![Ryan\_Grannell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_grannell/32/41712_2.png) [@Ryan\_Grannell](https://discuss.elastic.co/u/Ryan_Grannell)\
**Post date:** [January 31, 2017, 5:20pm UTC](https://discuss.elastic.co/t/watch-history-fieldname-error/73364/6 "2017-01-31T17:20:40Z")

</div>

Sure;

- [Watcher template](http://pastebin.com/raw/9Bes2wJP)
- [Affected index mapping](http://pastebin.com/raw/z6Bikv3D)

Just for clarity, I used today's mapping since that's when the error I provided occurred ( `2017-01-31 11:33:51,687` )

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 1, 2017, 7:57am UTC](https://discuss.elastic.co/t/watch-history-fieldname-error/73364/7 "2017-02-01T07:57:22Z")

</div>

Hey,

it looks as if you are using an old watcher history template can you run

```auto
DELETE _template/watch_history
# wait a moment and the new template should be added
GET _template/watch_history

```

The new template should have a different `path_math` value for the `disabled_payload_fields` in the dynamic templates.

P.S. This also means, that the new template is only applied the next day, unless you delete todays watch history.

--Alex

---

<div class="post-metadata">

**Author:** ![Ryan\_Grannell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_grannell/32/41712_2.png) [@Ryan\_Grannell](https://discuss.elastic.co/u/Ryan_Grannell)\
**Post date:** [February 1, 2017, 4:50pm UTC](https://discuss.elastic.co/t/watch-history-fieldname-error/73364/8 "2017-02-01T16:50:58Z")

</div>

Thanks a million for helping. I recreated the template as described, I'll comment here tomorrow letting you know if this resolved the problem

**Edit:** or tomorrow, as my cluster went into a red-state today & needed to be restored, ...

---

<div class="post-metadata">

**Author:** ![Ryan\_Grannell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_grannell/32/41712_2.png) [@Ryan\_Grannell](https://discuss.elastic.co/u/Ryan_Grannell)\
**Post date:** [February 3, 2017, 10:39am UTC](https://discuss.elastic.co/t/watch-history-fieldname-error/73364/9 "2017-02-03T10:39:16Z")

</div>

Thanks, that worked perfectly

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 3, 2017, 10:39am UTC](https://discuss.elastic.co/t/watch-history-fieldname-error/73364/10 "2017-03-03T10:39:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
