# Watcher and variables

**URL:** <https://discuss.elastic.co/t/watcher-and-variables/33733>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [November 4, 2015, 11:34am UTC](https://discuss.elastic.co/t/watcher-and-variables/33733 "2015-11-04T11:34:57Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![SuperPringles](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/superpringles/32/5303_2.png) [@SuperPringles](https://discuss.elastic.co/u/SuperPringles)\
**Post date:** [November 4, 2015, 11:34am UTC](https://discuss.elastic.co/t/watcher-and-variables/33733/1 "2015-11-04T11:34:57Z")

</div>

Hi there!

I've been experimenting a little bit with watcher and I had a question.  
Let's start with the code.

```
status=yellow
echo $status

curl -XPUT 'http://localhost:9200/_watcher/watch/cluster_health_watch3' -d '{
  "trigger" : {
    "schedule" : { "interval" : "10s" }
  },
  "input" : {
    "http" : {
      "request" : {
       "host" : "localhost",
       "port" : 9200,
       "path" : "/_cluster/health"
      }
    }
  },
  "condition" : {
    "compare" : {
      "ctx.payload.status" : { "eq" : '$status' }
    }
  },
  "actions" : {
    "send_email" : {
      "email" : {
        "to" : "myemail@gmail.com",
        "subject" : "Cluster Status Warning",
        "body" : "Cluster status is YELLOW"
      }
    }
  }
}'

```

As you can see, its a plain old watcher setup for emails but with a bit a tweaking. I replaced the "yellow" at ctx.payload.status next to "eq" : with '$status'

My goal here is to be able to change the values of the watcher setup using variables. I placed a $status at the top which has the value yellow. When I process this it gives me the following error.

```
{"error":"WatcherException[failed to put watch [cluster_health_watch3]]; nested: WatcherException[could not parse watch [cluster_health_watch3]]; nested: JsonParseException[Unrecognized token 'red': was expecting ('true', 'false' or 'null')\n at [Source: [B@4996065a; line: 16, column: 43]]; ","status":500}

```

So what can I do about this? Is it even possible? Thanks 😃

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 30, 2015, 5:44am UTC](https://discuss.elastic.co/t/watcher-and-variables/33733/2 "2015-11-30T05:44:26Z")

</div>

Hey,

I think it might be a shell/escaping issue here, because you are misusing ticks and that results in broken JSON. Can you try without variables first to rule this out, and if it does, then check your shell for correct escaping.

--Alex

---

<div class="post-metadata">

**Author:** ![SuperPringles](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/superpringles/32/5303_2.png) [@SuperPringles](https://discuss.elastic.co/u/SuperPringles)\
**Post date:** [December 2, 2015, 2:28pm UTC](https://discuss.elastic.co/t/watcher-and-variables/33733/3 "2015-12-02T14:28:54Z")

</div>

@spinscale It has been a little while since I last worked on this problem (can still reproduce it) and I will get back to you asap with a proper response to your suggestion 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:48pm UTC](https://discuss.elastic.co/t/watcher-and-variables/33733/4 "2017-07-06T13:48:01Z")

</div>


