# Watcher email specific field of all hits from the results

**URL:** <https://discuss.elastic.co/t/watcher-email-specific-field-of-all-hits-from-the-results/186489>\
**Category:** Elasticsearch\
**Created:** [June 19, 2019, 2:20pm UTC](https://discuss.elastic.co/t/watcher-email-specific-field-of-all-hits-from-the-results/186489 "2019-06-19T14:20:25Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Arnav\_Sengupta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arnav_sengupta/32/24059_2.png) [@Arnav\_Sengupta](https://discuss.elastic.co/u/Arnav_Sengupta)\
**Post date:** [June 19, 2019, 2:20pm UTC](https://discuss.elastic.co/t/watcher-email-specific-field-of-all-hits-from-the-results/186489/1 "2019-06-19T14:20:26Z")

</div>

I have the following input for my watcher

```
"input": {
"search": {
  "request": {
    "search_type": "query_then_fetch",
    "indices": [
      "ccwhaproxy-*"
    ],
    "types": [],
    "body": {
      "query": {
        "bool": {
          "must": [
            {
              "term": {
                "status_code": "200"
              }
            },
            {
              "range": {
                "@timestamp": {
                  "gt": "now-10m/m",
                  "lte": "now"
                }
              }
            }
          ]
        }
      },
      "_source": "backend_name"
    }
  }
}

```

}

How do I print just the backend name of each hit in my actions in an email?

A single hit might be done by something like this

```
ctx.payload.hits.hits.<index>.fields.<fieldname>

```

But how to print each hit's field in a new line?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 19, 2019, 3:01pm UTC](https://discuss.elastic.co/t/watcher-email-specific-field-of-all-hits-from-the-results/186489/2 "2019-06-19T15:01:47Z")

</div>

hey,

the way to go here would be a [script transform](https://www.elastic.co/guide/en/elastic-stack-overview/7.1/transform-script.html) allowing you to change or add something to the existing payload. In this case you would probably have a list of maps, where each map contains the index/fieldname data of each document. Then you can walk through it easily in a mustache template.

--Alex

---

<div class="post-metadata">

**Author:** ![Arnav\_Sengupta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arnav_sengupta/32/24059_2.png) [@Arnav\_Sengupta](https://discuss.elastic.co/u/Arnav_Sengupta)\
**Post date:** [June 19, 2019, 3:20pm UTC](https://discuss.elastic.co/t/watcher-email-specific-field-of-all-hits-from-the-results/186489/3 "2019-06-19T15:20:26Z")

</div>

```
If I wish to do this on an aggregation, is it the same, script tranform?

I am trying to create an html table with each backend name and it's doc_count for my corresponding query

Here is the input

    
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "ccwhaproxy-*"
        ],
        "types": [],
        "body": {
          "query": {
            "bool": {
              "must": [
                {
                  "term": {
                    "status_code": "200"
                  }
                },
                {
                  "range": {
                    "@timestamp": {
                      "gt": "now-10m/m",
                      "lte": "now"
                    }
                  }
                }
              ]
            }
          },
          "_source": "backend_name",
          "aggs": {
            "unique": {
              "terms": {
                "field": "backend_name.keyword"
              }
            }
          }
        }
      }
    }
 
In my actions, I have an email, body as html

{
  "profile": "standard",
  "attachments": {
    "attached_data": {
      "data": {
        "format": "json"
      }
    }
  },
  "from": "noreply@xxx.com",
  "priority": "high",
  "to": [
    "xxx@xxx.com"
  ],
  "subject": "503 Service Unavailable Alert - CCWHaproxy",
  "body": {

` "html": "<head> <h1>503 Backend Counts</h1> </head><body> <table> <tr><th>Backend Name</th><th>Count</th></tr><tr><td>{{#ctx.payload.aggregations.unique.buckets}}{{key}}{{/ctx.payload.aggregations.unique.buckets}}</td><td>{{#ctx.payload.aggregations.unique.buckets}}{{doc_count}}{{/ctx.payload.aggregations.unique.buckets}}</td></tr></table></body>"`

}
}
 

But this is printing all the keys concatenated in one cell and all the values concatenated in another cell
```

---

<div class="post-metadata">

**Author:** ![Arnav\_Sengupta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arnav_sengupta/32/24059_2.png) [@Arnav\_Sengupta](https://discuss.elastic.co/u/Arnav_Sengupta)\
**Post date:** [June 19, 2019, 3:58pm UTC](https://discuss.elastic.co/t/watcher-email-specific-field-of-all-hits-from-the-results/186489/4 "2019-06-19T15:58:46Z")

</div>

Hi,

I was able to transform using the script. Here is what I get in the results now.

```
"transform": {
        "type": "script",
        "status": "success",
        "payload": {
          "_value": [
            {
              "/configesearch": 6618
            },
            {
              "/v1/listprice/listpriceservice": 1954
            },
            {
              "/v2/search/itemsearch": 1762
            },
            {
              "/gdrservice": 415
            },
            {
              "/proxystats": 342
            },
            {
              "/v1/ccw/price": 322
            },
            {
              "/v1/ac/accuprice": 149
            },
            {
              "/v1/LPCESUtility/lpcesutility": 56
            },
            {
              "/v1/catalog/lpcatalogservices": 19
            },
            {
              "/v1/ac/accnxtgen": 7
            }
          ]
        }
      }

```

Now how do I iterate over each element in this list of \_value and make a table row with two cells for each key and value?

I am new to Moustache and Scripting. Any help is much appreciated.

Thanks!

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 20, 2019, 10:52am UTC](https://discuss.elastic.co/t/watcher-email-specific-field-of-all-hits-from-the-results/186489/5 "2019-06-20T10:52:44Z")

</div>

hey

you should probably have a map as each element of the array like

```auto
"key":"/configesearch",
"value":6618

```

This way you could access all elements in mustache like this (on top of my head, not tested)

```auto
{{#ctx.payload._value}}{{key}} has value {{value}}{{/ctx.payload._value}}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 18, 2019, 10:52am UTC](https://discuss.elastic.co/t/watcher-email-specific-field-of-all-hits-from-the-results/186489/6 "2019-07-18T10:52:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
