# Watcher action: substitute the found data in the "path" of action

**URL:** <https://discuss.elastic.co/t/watcher-action-substitute-the-found-data-in-the-path-of-action/234158>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [May 25, 2020, 1:37pm UTC](https://discuss.elastic.co/t/watcher-action-substitute-the-found-data-in-the-path-of-action/234158 "2020-05-25T13:37:14Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![andres-perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andres-perez/32/136461_2.png) [@andres-perez](https://discuss.elastic.co/u/andres-perez)\
**Post date:** [May 25, 2020, 7:01pm UTC](https://discuss.elastic.co/t/watcher-action-substitute-the-found-data-in-the-path-of-action/234158/2 "2020-05-25T19:01:48Z")

</div>

Hi!  
If your search returns:

1. Just 1 IP, that task should be straightforward: just add the (mustache template) variable which contains it within your payload.

2. A list of results and your ipban web service can handle multiple IPs passed in the url: you might build the variable section of your path using the mustache template options to iterate a list.

There is a good example of 1 and 2 in this response:

> [@Iterate over hits to get value of fields for my hits in my Mail box body from Watcher](https://discuss.elastic.co/t/iterate-over-hits-to-get-value-of-fields-for-my-hits-in-my-mail-box-body-from-watcher/48549/2):
>
> Hey, the number in the mustache template represents the index {{ctx.payload.hits.hits.0.\_source.CardNumber}}, so you could access other elements by increasing it. However what you really want, is looping through your results... try this snippet and check your logs if that suits your use-case DELETE foo PUT foo/bar/1 { "name" : { "first" : "Kobe", "last" : "Bryant" } } PUT foo/bar/2 { "name" : { "first" : "Stephen", "last" : "Curry" } } PUT foo/bar/3 { "name" : { …

You can see the exact contents of your search using the simulation tab of your watch.

If you need more complex processing, you can also include a transform section with a script to make the modifications and replace the payload or add a field with the desired value.  
Then you can use the resulting field like the previous points 1 or 2.

> **[Payload transforms | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/transform.html)**

---

_[View the full topic](https://discuss.elastic.co/t/watcher-action-substitute-the-found-data-in-the-path-of-action/234158)._
