# Watcher advanced scripts

**URL:** <https://discuss.elastic.co/t/watcher-advanced-scripts/251197>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [October 6, 2020, 11:45pm UTC](https://discuss.elastic.co/t/watcher-advanced-scripts/251197 "2020-10-06T23:45:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![anjana1](https://avatars.discourse-cdn.com/v4/letter/a/22d042/32.png) [@anjana1](https://discuss.elastic.co/u/anjana1)\
**Post date:** [October 6, 2020, 11:45pm UTC](https://discuss.elastic.co/t/watcher-advanced-scripts/251197/1 "2020-10-06T23:45:23Z")

</div>

I am using Kibana 7.8 and below is the result of my `POST _xpack/watcher/watch/949f7606-97dc-42ce-86b7-ddcf5a77d804/_execute`

````auto
"result" : {
      "execution_time" : "2020-10-06T23:40:33.976Z",
      "execution_duration" : 11944,
      "input" : {
        "type" : "search",
        "status" : "success",
        "payload" : {
          "_shards" : {
            "total" : 1,
            "failed" : 0,
            "successful" : 1,
            "skipped" : 0
          },
          "hits" : {
            "hits" : [
              {
                "_index" : "apm-retmon",
                "_type" : "_doc",
                "_source" : {
                  "labels.ServiceStatus" : "2",
                  "labels.LatLong" : "41.378197,-81.462354",
                  "labels.StoreNum" : "101",
                  "labels.OrgHier" : {
                    "OrgId" : 1000,
                    "RegsterNum" : "1",
                    "Store" : "101",
                    "Region" : "West",
                    "District" : "1"
                  },```

*****************************************************
I have the below script in my watcher. I am not able to get the value of labels.ServiceStatus using below script . What is the correct syntax.

 ``` "subject": "Watcher Notification",
        "body": {
          "html": "{{#ctx.payload.hits.hits}} {{_source.labels.ServiceStatus}} {{/ctx.payload.hits.hits}}"
        }```
````

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 7, 2020, 7:03am UTC](https://discuss.elastic.co/t/watcher-advanced-scripts/251197/2 "2020-10-07T07:03:42Z")

</div>

please take your time to write up a proper question instead of just pasting an incomplete output of an API call.

What is your problem? What is not working as expected? Which version of Elastic Stack are you using? etc...

Just dumping a question will not result in a lot of people helping if they don't get any information about the actual problem.

See also [https://www.elastic.co/help](https://www.elastic.co/help)

Thanks!

---

<div class="post-metadata">

**Author:** ![anjana1](https://avatars.discourse-cdn.com/v4/letter/a/22d042/32.png) [@anjana1](https://discuss.elastic.co/u/anjana1)\
**Post date:** [October 7, 2020, 4:09pm UTC](https://discuss.elastic.co/t/watcher-advanced-scripts/251197/3 "2020-10-07T16:09:10Z")

</div>

**Kibana version** : 7.9

**Elasticsearch version** : 7.9

**APM Server version** : 7.9

**APM Agent language and version** : java 1.8

**Fresh install or upgraded from other version?** fresh install

**Is there anything special in your setup?** For example, are you using the Logstash or Kafka outputs? Are you using a load balancer in front of the APM Servers? Have you changed index pattern, generated custom templates, changed agent configuration etc. :-no

I am trying to create watcher alert and I am using advanced watcher . I am trying to print values of index pattern fields in my watcher. My question is . can we access those fields by using {{\_source.nameofIndexpatternfeild}} .

I tried to use the below in my json watcher email body to display index pattern field and **it shows empty**. Is this the right syntax to follow?

I hope is question is clear now . sorry for the mix up earlier

"body": {  
"html": "{{#ctx.payload.hits.hits}} {{\_source.labels.ServiceStatus}} {{/ctx.payload.hits.hits}}"  
}

Note: labels.ServiceStatus is my field from index pattern and it is also present in watcher payload as well.

if you want to check my watcher payload it looks as below

````auto
     "execution_time" : "2020-10-06T23:40:33.976Z",
     "execution_duration" : 11944,
     "input" : {
       "type" : "search",
       "status" : "success",
       "payload" : {
         "_shards" : {
           "total" : 1,
           "failed" : 0,
           "successful" : 1,
           "skipped" : 0
         },
         "hits" : {
           "hits" : [
             {
               "_index" : "apm-retmon",
               "_type" : "_doc",
               "_source" : {
                 "labels.ServiceStatus" : "2",
                 "labels.LatLong" : "41.378197,-81.462354",
                 "labels.StoreNum" : "101",
                 "labels.OrgHier" : {
                   "OrgId" : 1000,
                   "RegsterNum" : "1",
                   "Store" : "101",
                   "Region" : "West",
                   "District" : "1"
                 }, ```
````

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 8, 2020, 8:33am UTC](https://discuss.elastic.co/t/watcher-advanced-scripts/251197/4 "2020-10-08T08:33:14Z")

</div>

Hey,

now, we're talking 🙂 this helps a lot to identify the problem.

This is due to the way that the mustache template languages interpretes a dot. By using `_source.labels.ServiceStatus` the JSON structure is assumed as

```auto
{
  "_source" : {
    "labels" : {
      "ServiceStatus" : "2"
    }
  }

```

As this structures does not exist, the field is null. I do not see an immediate workaround with mustache only here.

You can use a painless script and access those fields as `ctx.payload.hits.hits[0]._source["labels.ServiceStatus"]` and rename them in a transform, so that they are available in a mustache script.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 5, 2020, 8:33am UTC](https://discuss.elastic.co/t/watcher-advanced-scripts/251197/5 "2020-11-05T08:33:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
