# Watcher Configuration to print results in Email

**URL:** <https://discuss.elastic.co/t/watcher-configuration-to-print-results-in-email/136410>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [June 19, 2018, 4:55am UTC](https://discuss.elastic.co/t/watcher-configuration-to-print-results-in-email/136410 "2018-06-19T04:55:41Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![sanky186](https://avatars.discourse-cdn.com/v4/letter/s/7ea924/32.png) [@sanky186](https://discuss.elastic.co/u/sanky186)\
**Post date:** [June 19, 2018, 4:55am UTC](https://discuss.elastic.co/t/watcher-configuration-to-print-results-in-email/136410/1 "2018-06-19T04:55:41Z")

</div>

Guys,

I have looked all over the internet, and i cant seem to get a simple answer at all.  
So, we have an watcher configuration which triggers an email when a particular condition is satisfied.  
But, it prints only the hits.  
Now, can anyone please tell me in simple code, how to print the payload in the email action.

Here is my watcher configuration

{  
"trigger": {  
"schedule": {  
"interval": "30s"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"my-index-\*"  
],  
"types": [],  
"body": {  
"query": {  
"bool": {  
"must": [  
{  
"query\_string": {  
"query": "system.cpu.total.pct : [0.3 TO \*]"  
}  
},  
{  
"range": {  
"@timestamp": {  
"gte": "now-7d"  
}  
}  
}  
]  
}  
},  
"\_source": [  
"message"  
],  
"sort": [  
{  
"@timestamp": {  
"order": "desc"  
}  
}  
]  
}  
}  
}  
},  
"condition": {  
"compare": {  
"ctx.payload.hits.total": {  
"gte": 1  
}  
}  
},  
"actions": {  
"send\_email": {  
"email": {  
"profile": "standard",  
"to": [  
"myemail@mydomain.com"  
],  
"subject": "Warning: High CPU Utilization",  
"body": {  
"text": "{{ctx.payload.hits.total}} Times the CPU Utilization has crossed the threshold value {{#ctx.payload.\_value}}{{.}}:{{/ctx.payload.\_value}}"  
}  
}  
}  
},  
"throttle\_period\_in\_millis": 60000  
}  
sample\_cpu\_watcher.json  
Displaying sample\_cpu\_watcher.json.

---

<div class="post-metadata">

**Author:** ![\_Sergey](https://avatars.discourse-cdn.com/v4/letter/_/e68b1a/32.png) [@\_Sergey](https://discuss.elastic.co/u/_Sergey)\
**Post date:** [June 19, 2018, 11:57am UTC](https://discuss.elastic.co/t/watcher-configuration-to-print-results-in-email/136410/2 "2018-06-19T11:57:40Z")

</div>

Hey,

Here is useful link

[Email action](https://www.elastic.co/guide/en/watcher/current/actions.html#actions-email)

---

<div class="post-metadata">

**Author:** ![sanky186](https://avatars.discourse-cdn.com/v4/letter/s/7ea924/32.png) [@sanky186](https://discuss.elastic.co/u/sanky186)\
**Post date:** [June 19, 2018, 12:45pm UTC](https://discuss.elastic.co/t/watcher-configuration-to-print-results-in-email/136410/3 "2018-06-19T12:45:46Z")

</div>

Hi Sergey, Thanks for the reply.

I can see some data, but nothing in the link which helps me print a particular field in the Elastic index.

if had a field a in the response, how do i get that into the email body ?

ctx.payload.fieldname ?

---

<div class="post-metadata">

**Author:** ![elastock](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elastock/32/35672_2.png) [@elastock](https://discuss.elastic.co/u/elastock)\
**Post date:** [June 19, 2018, 2:58pm UTC](https://discuss.elastic.co/t/watcher-configuration-to-print-results-in-email/136410/4 "2018-06-19T14:58:27Z")

</div>

You have to understand that your payload may contain many hits and you can access the them just via the JSON array .  
So  
if you have X hits , you should do like this .

`{{#ctx.payload.hits.hits}}{{thefieldname}}{{/ctx.payload.hits.hits}}`

If you have only 1 hit in the payload .  
Value : `{{ctx.payload.hits.hits.0.thefieldname}}`

So in your case 🙂

`{{ctx.payload.hits.total}} Times the CPU Utilization has crossed the threshold value {{#ctx.payload.hits.hits}}{{value}}:{{/ctx.payload.hits.hits}}`

---

<div class="post-metadata">

**Author:** ![sanky186](https://avatars.discourse-cdn.com/v4/letter/s/7ea924/32.png) [@sanky186](https://discuss.elastic.co/u/sanky186)\
**Post date:** [June 19, 2018, 6:03pm UTC](https://discuss.elastic.co/t/watcher-configuration-to-print-results-in-email/136410/5 "2018-06-19T18:03:31Z")

</div>

Hi friend, thank you .. I tried and got this .... 1033 times the CPU Utilization has crossed the threshold value ::::::::::

Just dots ☹

---

<div class="post-metadata">

**Author:** ![sanky186](https://avatars.discourse-cdn.com/v4/letter/s/7ea924/32.png) [@sanky186](https://discuss.elastic.co/u/sanky186)\
**Post date:** [June 20, 2018, 12:39am UTC](https://discuss.elastic.co/t/watcher-configuration-to-print-results-in-email/136410/6 "2018-06-20T00:39:28Z")

</div>

@elastock @spinscale Any thoughts on my above reply ?

---

<div class="post-metadata">

**Author:** ![elastock](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elastock/32/35672_2.png) [@elastock](https://discuss.elastic.co/u/elastock)\
**Post date:** [June 20, 2018, 8:30am UTC](https://discuss.elastic.co/t/watcher-configuration-to-print-results-in-email/136410/7 "2018-06-20T08:30:15Z")

</div>

you have to replace {{value}} by the fieldname  
in your case i think it is .

> [@elastock](#):
>
> {{system.cpu.total.pct}}

but it may have a problem because of the dots in the fieldname .  
Lets try .

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [June 20, 2018, 10:31am UTC](https://discuss.elastic.co/t/watcher-configuration-to-print-results-in-email/136410/8 "2018-06-20T10:31:09Z")

</div>

I assume that you will eventually change this watch to:

a) be more "real-time" (i.e. be over the last X minutes, not over the last 7 days)  
b) set a more realistic threshold for CPU utilization  
c) print useful contextual information, as in, the name of the host that had the high CPU for example

If you have time, may I suggest reviewing some of our example watches in our public Github repo:

> **[elastic/examples](https://github.com/elastic/examples/tree/master/Alerting/Sample%20Watches)**
>
> Home for Elasticsearch examples available to everyone. It's a great way to get started.

They may give you additional ideas.

---

<div class="post-metadata">

**Author:** ![sanky186](https://avatars.discourse-cdn.com/v4/letter/s/7ea924/32.png) [@sanky186](https://discuss.elastic.co/u/sanky186)\
**Post date:** [June 20, 2018, 6:08pm UTC](https://discuss.elastic.co/t/watcher-configuration-to-print-results-in-email/136410/9 "2018-06-20T18:08:21Z")

</div>

I most certainly am going to go for more complex patterns, but i seem to be stonewalled by the basics.

See the watcher output below, i see no fields in the output, which would explain why i cant access any of them in my email body.  
How can i get the fields to flow in ? @elastock

---

<div class="post-metadata">

**Author:** ![sanky186](https://avatars.discourse-cdn.com/v4/letter/s/7ea924/32.png) [@sanky186](https://discuss.elastic.co/u/sanky186)\
**Post date:** [June 20, 2018, 6:08pm UTC](https://discuss.elastic.co/t/watcher-configuration-to-print-results-in-email/136410/10 "2018-06-20T18:08:27Z")

</div>

{  
"watch\_id": "serviceABC",  
"node": "xGdwQzxQTryzn1x9u-KFhw",  
"state": "executed",  
"status": {  
"state": {  
"active": true,  
"timestamp": "2018-06-20T04:28:XX.XX"  
},  
"last\_checked": "2018-06-20T04:29:49.120Z",  
"last\_met\_condition": "2018-06-20T04:29:49.120Z",  
"actions": {  
"send\_email": {  
"ack": {  
"timestamp": "2018-06-20T04:29:16.567Z",  
"state": "ackable"  
},  
"last\_execution": {  
"timestamp": "2018-06-20T04:29:49.120Z",  
"successful": true  
},  
"last\_successful\_execution": {  
"timestamp": "2018-06-20T04:29:49.120Z",  
"successful": true  
}  
}  
},  
"execution\_state": "executed",  
"version": -1  
},  
"trigger\_event": {  
"type": "schedule",  
"triggered\_time": "2018-06-20T04:29:49.120Z",  
"schedule": {  
"scheduled\_time": "2018-06-20T04:29:48.758Z"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"index\_name-\*"  
],  
"types": [],  
"body": {  
"query": {  
"bool": {  
"must": [  
{  
"query\_string": {  
"query": "my\_fieldname: [0.2 TO _]"  
}  
},  
{  
"range": {  
"@timestamp": {  
"gte": "now-7d"  
}  
}  
}  
]  
}  
},  
"\_source": [  
"message"  
],  
"sort": [  
{  
"@timestamp": {  
"order": "desc"  
}  
}  
]  
}  
}  
}  
},  
"condition": {  
"compare": {  
"ctx.payload.hits.total": {  
"gte": 1  
}  
}  
},  
"metadata": {  
"name": "CPU util. check",  
"xpack": {  
"type": "json"  
}  
},  
"result": {  
"execution\_time": "2018-06-20T04:29:XX.XX",  
"execution\_duration": 598,  
"input": {  
"type": "search",  
"status": "success",  
"payload": {  
"\_shards": {  
"total": 22,  
"failed": 0,  
"successful": 22,  
"skipped": 0  
},  
"hits": {  
"hits": [  
{  
"\_index": "my\_index-2018.06.20",  
"\_type": "doc",  
"\_source": {},  
"\_id": "gM5xG2QBlZxOw2VhYARB",  
"sort": [  
1529468771416  
],  
"\_score": null  
},  
{  
"\_index": "my\_index-2018.06.20",  
"\_type": "doc",  
"\_source": {},  
"\_id": "Js5xG2QBlZxOw2VhVQSi",  
"sort": [  
1529468768641  
],  
"\_score": null  
},  
{  
"\_index": "my\_index-2018.06.20",  
"\_type": "doc",  
"\_source": {},  
"\_id": "xxxx",  
"sort": [  
1529468406117  
],  
"\_score": null  
},  
{  
"\_index": "my\_index-2018.06.20",  
"\_type": "doc",  
"\_source": {},  
"\_id": "xxxx",  
"sort": [  
1529468165110  
],  
"\_score": null  
},  
{  
"\_index": "my\_index-2018.06.20",  
"\_type": "doc",  
"\_source": {},  
"\_id": "xxxx",  
"sort": [  
1529468046117  
],  
"\_score": null  
},  
{  
"\_index": "my\_index-2018.06.20",  
"\_type": "doc",  
"\_source": {},  
"\_id": "xxxx",  
"sort": [  
1529468036117  
],  
"\_score": null  
},  
{  
"\_index": "my\_index-2018.06.20",  
"\_type": "doc",  
"\_source": {},  
"\_id": "xxxx",  
"sort": [  
1529467871416  
],  
"\_score": null  
},  
{  
"\_index": "my\_index-2018.06.20",  
"\_type": "doc",  
"\_source": {},  
"\_id": "xxxx",  
"sort": [  
1529467868641  
],  
"\_score": null  
},  
{  
"\_index": "my\_index-2018.06.20",  
"\_type": "doc",  
"\_source": {},  
"\_id": "xxxx",  
"sort": [  
1529467718641  
],  
"\_score": null  
},  
{  
"\_index": "my\_index-2018.06.20",  
"\_type": "doc",  
"\_source": {},  
"\_id": "xxxx",  
"sort": [  
1529467708641  
],  
"\_score": null  
}  
],  
"total": 6715,  
"max\_score": null  
},  
"took": 86,  
"timed\_out": false  
},  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"my\_index-_"  
],  
"types": [],  
"body": {  
"query": {  
"bool": {  
"must": [  
{  
"query\_string": {  
"query": "my\_field : [0.2 TO \*]"  
}  
},  
{  
"range": {  
"@timestamp": {  
"gte": "now-7d"  
}  
}  
}  
]  
}  
},  
"\_source": [  
"message"  
],  
"sort": [  
{  
"@timestamp": {  
"order": "desc"  
}  
}  
]  
}  
}  
}  
},  
"condition": {  
"type": "compare",  
"status": "success",  
"met": true,  
"compare": {  
"resolved\_values": {  
"ctx.payload.hits.total": 6715  
}  
}  
},  
"actions": [  
{  
"id": "send\_email",  
"type": "email",  
"status": "success",  
"email": {  
"account": "smtp\_account",  
"message": {  
"id": "watcher\_ID\_xxxxx-2018-06-20T04:29:49.120Z",  
"from": "xyzemail@abc.com",  
"sent\_date": "2018-06-20T04:29:49.xx.xx",  
"to": [  
"myemail@abc.com"  
],  
"subject": "High CPU Utilization in past 7 days",  
"body": {  
"text": " "  
}  
}  
}  
}  
]  
},  
"messages": []  
}

---

<div class="post-metadata">

**Author:** ![elastock](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elastock/32/35672_2.png) [@elastock](https://discuss.elastic.co/u/elastock)\
**Post date:** [June 21, 2018, 7:03am UTC](https://discuss.elastic.co/t/watcher-configuration-to-print-results-in-email/136410/11 "2018-06-21T07:03:32Z")

</div>

i'm not really sure , but you can try this

```
                             {
                                    "query_string": {
                                        "query": "my_field : [0.2 TO *]",
                                        "analyze_wildcard": true
                                    }
                                },

```

and delete

```
                        "_source": [
                        "message"
                    ],
```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 22, 2018, 1:57pm UTC](https://discuss.elastic.co/t/watcher-configuration-to-print-results-in-email/136410/12 "2018-06-22T13:57:54Z")

</div>

Hey,

I just saw this snippet in your execute watch API output. I do not think that `_value` has been populated, as `ctx.payload.hits.total` is set. Maybe you want to use `{{#ctx.payload.hits.hits}}` and loop through the result set?

> [@sanky186](#):
>
> {{#ctx.payload.\_value}}{{.}}:{{/ctx.payload.\_value}}"

Also, please format your code snippets properly, thisi s nearly impossible to read. You can use markdown in this forum. Thank you!

--Alex

---

<div class="post-metadata">

**Author:** ![iamthealex](https://avatars.discourse-cdn.com/v4/letter/i/e9c0ed/32.png) [@iamthealex](https://discuss.elastic.co/u/iamthealex)\
**Post date:** [June 27, 2018, 3:33pm UTC](https://discuss.elastic.co/t/watcher-configuration-to-print-results-in-email/136410/13 "2018-06-27T15:33:51Z")

</div>

You might find this page helpful:

[https://www.vodori.com/helpful-mustache-template-tips/](https://www.vodori.com/helpful-mustache-template-tips/)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 25, 2018, 3:33pm UTC](https://discuss.elastic.co/t/watcher-configuration-to-print-results-in-email/136410/14 "2018-07-25T15:33:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
