# Watcher : Action Body's Text

**URL:** <https://discuss.elastic.co/t/watcher-action-bodys-text/293245>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting, painless\
**Created:** [December 31, 2021, 9:23am UTC](https://discuss.elastic.co/t/watcher-action-bodys-text/293245 "2021-12-31T09:23:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![appleyin1](https://avatars.discourse-cdn.com/v4/letter/a/5f8ce5/32.png) [@appleyin1](https://discuss.elastic.co/u/appleyin1)\
**Post date:** [December 31, 2021, 9:23am UTC](https://discuss.elastic.co/t/watcher-action-bodys-text/293245/1 "2021-12-31T09:23:02Z")

</div>

Hi there:  
I'm stuck at the Watch Action body text section, I have a payload below. Is that possible to only retrieve which service and host's doc\_count \< 5 ? in order to determine what are the services are unavailable with their hosts.

I might need a loop but don't think "body" allows painless script? Pls advise, thank you so much.

Expected email body output eg:

_The following services with their respective host are unavailable,_  
serviceA-health-check-status, host2  
serviceB-health-check-status, host2  
serviceC-health-check-status, host2

```auto
"payload": {
        "ServiceUnavailable": [
          {
            "serviceId": "serviceA-health-check-status",
            "serviceId-details": [
              {
                "doc_count": 5,
                "key": "host1"
              },
              {
                "doc_count": 3,
                "key": "host2"
              }
            ]
          },
          {
            "serviceId": "serviceB-health-check-status",
            "serviceId-details": [
              {
                "doc_count": 5,
                "key": "host1"
              },
              {
                "doc_count": 3,
                "key": "host2"
              }
            ]
          },
          {
            "serviceId": "serviceC-health-check-status",
            "serviceId-details": [
              {
                "doc_count": 5,
                "key": "host1"
              },
              {
                "doc_count": 3,
                "key": "host2"
              }
            ]
          }
        ]
      }
    }

```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [January 5, 2022, 3:42pm UTC](https://discuss.elastic.co/t/watcher-action-bodys-text/293245/2 "2022-01-05T15:42:15Z")

</div>

Two possibilities:

1. First, you can use list iterations in the mustache language, but I find it a little clunky. See [Watching event data | Elasticsearch Guide [7.16] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.16/watching-meetup-data.html)

2. You can use a transform to change your payload to use it more easily in your actions. See [Payload transforms | Elasticsearch Guide [7.16] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.16/transform.html)

---

<div class="post-metadata">

**Author:** ![appleyin1](https://avatars.discourse-cdn.com/v4/letter/a/5f8ce5/32.png) [@appleyin1](https://discuss.elastic.co/u/appleyin1)\
**Post date:** [January 5, 2022, 9:47pm UTC](https://discuss.elastic.co/t/watcher-action-bodys-text/293245/4 "2022-01-05T21:47:01Z")

</div>

Happy New Year, Alex. Thanks so much for your replied. The payload that I have put up was already being transformed. I know something need to be fixed in "Transform" but I don't know how after working on it for quite some time.

I'm sending you the Watcher JSON file, pls help me if you can point out what needs to be fixed in order to have the desired output. Thanks again and appreciate your advise, Alex

```auto
PUT _watcher/watch/ServiceUnavailable_watcher
{
  "trigger": {
    "schedule": {
      "interval": "5m"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "heartbeat"
        ],
        "rest_total_hits_as_int": true,
        "body": {
          "size": 0,
          "query": {
            "bool": {
              "filter": [
                {
                  "term": {
                    "tags": "cn3a"
                  }
                },
                {
                  "range": {
                    "@timestamp": {
                      "gte": "now-5m",
                      "lte": "now"
                    }
                  }
                }
              ]
            }
          },
          "aggs": {
            "applService": {
              "terms": {
                "field": "applService.id",
                "size": 50
              },
              "aggs": {
                "servicesHost": {
                  "terms": {
                    "field": "servicesHost.hostname",
                    "size": 50
                  }
                }
              }
            }
          }
        }
      }
    }
  },
  "condition": {
    "script": """
    ctx.payload.aggregations.applService.buckets.stream()
    .filter(service -> service.servicesHost.buckets.stream()
      .anyMatch(service -> service.doc_count < 5))
    .count() > 0
  """
  },
  "transform": {
    "script": """
    return [
      "ServiceUnavailable": ctx.payload.aggregations.applService.buckets.stream()
        .filter(service -> service.servicesHost.buckets.stream()
          .anyMatch(service -> { 
            return service.doc_count < 5
          }))
        .map(t -> {
          return ['serviceId': t.key, 'service-details': t.servicesHost.buckets]
        })
      .collect(Collectors.toList())
    ]
  """
  },
  "actions": {
    "Email_Support": {
      "email": {
        "profile": "standard",
        "to": [
          "abc@lgmail.com"
        ],
        "subject": "Servicess are currently unavailable",
        "body": {
          "text": "{{ctx.payload}}"
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 2, 2022, 9:48pm UTC](https://discuss.elastic.co/t/watcher-action-bodys-text/293245/5 "2022-02-02T21:48:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
