# Watch payload options

**URL:** <https://discuss.elastic.co/t/watch-payload-options/57141>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [August 3, 2016, 6:35pm UTC](https://discuss.elastic.co/t/watch-payload-options/57141 "2016-08-03T18:35:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![piyush](https://avatars.discourse-cdn.com/v4/letter/p/ecb155/32.png) [@piyush](https://discuss.elastic.co/u/piyush)\
**Post date:** [August 3, 2016, 6:35pm UTC](https://discuss.elastic.co/t/watch-payload-options/57141/1 "2016-08-03T18:35:43Z")

</div>

Hi Team,  
I read about watcher "script and template" documentation that suggests writing Groovy scripts and all to add index fields along with alert message body. But i didn't understand it much, obviously being a new bee.

can you share an example or document for below requirement:

1. topbeat disk alert
2. message body should contain value of "fs.used\_p"

Below might put some more light:

# Note: my actual input condition is below one, match\_all query is just for testing to include match\_all result in input payload "filter": { "range": { "fs.used\_p": {"gt": 0.40} } }

put \_watcher/watch/fs\_disk\_top1  
{  
"trigger": {  
"schedule": {  
"interval": "300s"  
}  
},  
"input": {  
"search": {  
"request": {  
"indices": [  
"topbeat-2016.08.03"  
],  
"body": {  
"query" :{  
"match\_all": {}  
}  
}  
}  
}  
},  
"condition": {  
"compare": {  
"ctx.payload.hits.total": {  
"gt": 0  
}  
}  
},  
"actions": {  
"email\_admin": {  
"email": {  
"to": "abc",  
"subject": "{{ctx.watch\_id}} executed",  
"body": "Disc utilization is more than 50 {{ctx.metadata.\*}}"  
}  
}  
}  
}

Result (copied only relevant lines):

```
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "topbeat-2016.08.03"
        ],
        "types": [],
        "template": {
          "template": {
            "query": {
              "match_all": {}
            }
          },
          "params": {
            "ctx": {
              "id": "fs_disk_top1_0-2016-08-03T17:47:00.118Z",
              "vars": {},
              "trigger": {
                "triggered_time": "2016-08-03T17:47:00.118Z",
                "scheduled_time": "2016-08-03T17:47:00.118Z"
              },
              "execution_time": "2016-08-03T17:47:00.118Z",
              "watch_id": "fs_disk_top1",
              "metadata": null
            }
          }
        }
      }
    }
  },
  "condition": {
    "type": "compare",
    "status": "success",
    "met": true,
    "compare": {
      "resolved_values": {
        "ctx.payload.hits.total": 2293856
      }
    }
  },
  "actions": [
    {
      "id": "email_admin",
      "type": "email",
      "status": "success",
      "email": {
        "account": "exchange_account",
        "message": {
          "id": "fs_disk_top1_0-2016-08-03T17:47:00.118Z",
          "from": "abc",
          "sent_date": "2016-08-03T17:47:00.127Z",
          "to": [
            "abc"
          ],
          "subject": "fs_disk_top1 executed",
          "body": {
            "text": "Disc utilization is more than 50 "
          }
        }
      }
    }
  ]
}

```

}  
}

Thanks & Regards

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 4, 2016, 6:18am UTC](https://discuss.elastic.co/t/watch-payload-options/57141/2 "2016-08-04T06:18:06Z")

</div>

Hey,

the snippet you pasted shows you, which parameters are used for the template based search input (which you can specify as part of that search).

Your problem seems to be a different one. You want to access the payload of the search result in the action. The search response is stored in `ctx.payload`, which you already accessed in the script condition. If you want to specify a certain field, you have to specify it instead of `hits.total`

--Alex

---

<div class="post-metadata">

**Author:** ![piyush](https://avatars.discourse-cdn.com/v4/letter/p/ecb155/32.png) [@piyush](https://discuss.elastic.co/u/piyush)\
**Post date:** [August 4, 2016, 8:14pm UTC](https://discuss.elastic.co/t/watch-payload-options/57141/3 "2016-08-04T20:14:27Z")

</div>

Thanks 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:43pm UTC](https://discuss.elastic.co/t/watch-payload-options/57141/4 "2017-07-06T13:43:43Z")

</div>


