# Watcher Alert for Failed Snapshots How to loop the ctx.payload returned

**URL:** <https://discuss.elastic.co/t/watcher-alert-for-failed-snapshots-how-to-loop-the-ctx-payload-returned/122575>\
**Category:** Elasticsearch\
**Created:** [March 5, 2018, 7:01pm UTC](https://discuss.elastic.co/t/watcher-alert-for-failed-snapshots-how-to-loop-the-ctx-payload-returned/122575 "2018-03-05T19:01:57Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dmdm](https://avatars.discourse-cdn.com/v4/letter/d/858c86/32.png) [@dmdm](https://discuss.elastic.co/u/dmdm)\
**Post date:** [March 5, 2018, 7:01pm UTC](https://discuss.elastic.co/t/watcher-alert-for-failed-snapshots-how-to-loop-the-ctx-payload-returned/122575/1 "2018-03-05T19:01:57Z")

</div>

In the below example I query for the snapshots to see if there is a failed status on any of them. In this one I'm pulling the first record and the number of shards that failed in the snapshot. How would I edit this so that I could loop the array and display this for every record vs just the first one? I tried to do some searches for looping through a return to send to the log, or eventually a email alert, but couldn't find anything. Any help would be appreciated.

```auto
    "trigger": {
      "schedule": {
        "interval": "60s"
    }
  },
   "input": {
      "http": {
         "request": {
            "scheme": "http",
            "host": "localhost",
            "port": 9200,
            "method": "get",
            "path": "/_snapshot/s3_repository/_all",
            "params": {},
            "headers": {}
         }
      }
   },
  "condition": {
      "always": {}
  },
    "actions": {
        "logging": {
           "logging": {
            "text": "Shards failed in first returned record {{ctx.payload.snapshots.0.shards.failed}} "
          }
       }
    }
}

```

Here is an example of what it returns on the simulation, I removed the list of indices would make it too long(I get about 12 of those right now that I'm trying to loop through to log the results:

```auto
{
            "snapshot": "2018-02-23t03:15",
            "uuid": "nIOUXhIsQLSKONnFSFCNBQ",
            "version_id": 6020299,
            "version": "6.2.2",
            "indices": [
              .. indices were removed here ..
            ],
            "include_global_state": true,
            "state": "SUCCESS",
            "start_time": "2018-02-23T03:15:04.460Z",
            "start_time_in_millis": 1519355704460,
            "end_time": "2018-02-23T05:34:55.313Z",
            "end_time_in_millis": 1519364095313,
            "duration_in_millis": 8390853,
            "failures": [],
            "shards": {
              "total": 909,
              "failed": 0,
              "successful": 909
            }
          },

```

---

<div class="post-metadata">

**Author:** ![dmdm](https://avatars.discourse-cdn.com/v4/letter/d/858c86/32.png) [@dmdm](https://discuss.elastic.co/u/dmdm)\
**Post date:** [March 7, 2018, 3:22pm UTC](https://discuss.elastic.co/t/watcher-alert-for-failed-snapshots-how-to-loop-the-ctx-payload-returned/122575/2 "2018-03-07T15:22:45Z")

</div>

Ok I figured this out thanks to another example I dug up in the forums, so thanks to those in the forums. I changed from going after the failed shards to snapshot state. Posting this so other new guys like myself have an example of the loop.

```auto
	"actions": {
			"logging": {
				"logging": {
					"level": "info",
					"text": "Snapshot state: {{#ctx.payload.snapshots}}{{state}}{{/ctx.payload.snapshots}} "
				}
			}
		}

```

Is there anywhere that lists a bunch of watcher alert example? I now have a question on how to do the compare off of that loop, but will post it in another topic since it is a different question.

---

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [March 15, 2018, 8:23pm UTC](https://discuss.elastic.co/t/watcher-alert-for-failed-snapshots-how-to-loop-the-ctx-payload-returned/122575/3 "2018-03-15T20:23:12Z")

</div>

CC @spinscale

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 15, 2018, 8:36pm UTC](https://discuss.elastic.co/t/watcher-alert-for-failed-snapshots-how-to-loop-the-ctx-payload-returned/122575/4 "2018-03-15T20:36:30Z")

</div>

Hey,

you best source of examples is probably the examples repo at [https://github.com/elastic/examples/tree/master/Alerting](https://github.com/elastic/examples/tree/master/Alerting)

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 12, 2018, 8:36pm UTC](https://discuss.elastic.co/t/watcher-alert-for-failed-snapshots-how-to-loop-the-ctx-payload-returned/122575/5 "2018-04-12T20:36:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
