# Watcher action: substitute the found data in the "path" of action

**URL:** <https://discuss.elastic.co/t/watcher-action-substitute-the-found-data-in-the-path-of-action/234158>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [May 25, 2020, 1:37pm UTC](https://discuss.elastic.co/t/watcher-action-substitute-the-found-data-in-the-path-of-action/234158 "2020-05-25T13:37:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![kurdit](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kurdit/32/54994_2.png) [@kurdit](https://discuss.elastic.co/u/kurdit)\
**Post date:** [May 25, 2020, 1:37pm UTC](https://discuss.elastic.co/t/watcher-action-substitute-the-found-data-in-the-path-of-action/234158/1 "2020-05-25T13:37:14Z")

</div>

hi!  
I have a system for blocking IP addresses.  
you can send a lock request to this system using curl:

```
curl -u username: password http://ipban.myhostname.com:4389/index.php?action=add&ip=122.54.95.111

```

I have a watcher that tracks an abnormally high number of requests from IP. I want it to block these IPs, which create a high number of requests.

but there is one problem:

1. how to substitute the found IP address in the required section in the "path" field to send the correct curl to my system? data can be substituted only in the body field, but this field cannot be used as part of the path for curl (or am I mistaken?).

2. how can I implement such a send curl with the necessary IP from the data received by the watcher?

---

<div class="post-metadata">

**Author:** ![andres-perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andres-perez/32/136461_2.png) [@andres-perez](https://discuss.elastic.co/u/andres-perez)\
**Post date:** [May 25, 2020, 7:01pm UTC](https://discuss.elastic.co/t/watcher-action-substitute-the-found-data-in-the-path-of-action/234158/2 "2020-05-25T19:01:48Z")

</div>

Hi!  
If your search returns:

1. Just 1 IP, that task should be straightforward: just add the (mustache template) variable which contains it within your payload.

2. A list of results and your ipban web service can handle multiple IPs passed in the url: you might build the variable section of your path using the mustache template options to iterate a list.

There is a good example of 1 and 2 in this response:

> [@Iterate over hits to get value of fields for my hits in my Mail box body from Watcher](https://discuss.elastic.co/t/iterate-over-hits-to-get-value-of-fields-for-my-hits-in-my-mail-box-body-from-watcher/48549/2):
>
> Hey, the number in the mustache template represents the index {{ctx.payload.hits.hits.0.\_source.CardNumber}}, so you could access other elements by increasing it. However what you really want, is looping through your results... try this snippet and check your logs if that suits your use-case DELETE foo PUT foo/bar/1 { "name" : { "first" : "Kobe", "last" : "Bryant" } } PUT foo/bar/2 { "name" : { "first" : "Stephen", "last" : "Curry" } } PUT foo/bar/3 { "name" : { …

You can see the exact contents of your search using the simulation tab of your watch.

If you need more complex processing, you can also include a transform section with a script to make the modifications and replace the payload or add a field with the desired value.  
Then you can use the resulting field like the previous points 1 or 2.

> **[Payload transforms | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/transform.html)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 22, 2020, 7:01pm UTC](https://discuss.elastic.co/t/watcher-action-substitute-the-found-data-in-the-path-of-action/234158/3 "2020-06-22T19:01:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
