# Watcher actions body

**URL:** <https://discuss.elastic.co/t/watcher-actions-body/247943>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [September 9, 2020, 4:04am UTC](https://discuss.elastic.co/t/watcher-actions-body/247943 "2020-09-09T04:04:25Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![hero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hero/32/75284_2.png) [@hero](https://discuss.elastic.co/u/hero)\
**Post date:** [September 9, 2020, 4:04am UTC](https://discuss.elastic.co/t/watcher-actions-body/247943/1 "2020-09-09T04:04:25Z")

</div>

> Watcher actions body How to save search query  
> watcher configure:

```auto
{
  "trigger": {
    "schedule": {
      "interval": "10s"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "logstash-*"
        ],
        "rest_total_hits_as_int": true,
        "body": {
          "query": {
            "bool": {
              "must": {
                "match": {
                  "path": "/api/v1"
                }
              },
              "filter": {
                "range": {
                  "@timestamp": {
                    "from": "{{ctx.trigger.scheduled_time}}||-5m",
                    "to": "{{ctx.trigger.triggered_time}}"
                  }
                }
              }
            }
          }
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "lt": 10
      }
    }
  },
  "actions": {
    "ops": {
      "webhook": {
        "scheme": "http",
        "host": "xxx",
        "port": 5000,
        "method": "post",
        "path": "/xxx",
        "body": "{{#toJson}}ctx{{/toJson}}"
      }
    }
  }
}

```

> I'am want to add input search query or kibana search query url in webhook body, How?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 16, 2020, 10:01am UTC](https://discuss.elastic.co/t/watcher-actions-body/247943/2 "2020-09-16T10:01:38Z")

</div>

The search results are available in the `ctx.payload` variable. If you need to modify the data before sending it somewhere else, you can use a [transform script](https://www.elastic.co/guide/en/elasticsearch/reference/7.8/transform-script.html) to do so.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 14, 2020, 10:02am UTC](https://discuss.elastic.co/t/watcher-actions-body/247943/3 "2020-10-14T10:02:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
