# Watcher error when executing the watch

**URL:** <https://discuss.elastic.co/t/watcher-error-when-executing-the-watch/119536>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [February 12, 2018, 7:17pm UTC](https://discuss.elastic.co/t/watcher-error-when-executing-the-watch/119536 "2018-02-12T19:17:44Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Maxime\_Poirier-Journ](https://avatars.discourse-cdn.com/v4/letter/m/a8b319/32.png) [@Maxime\_Poirier-Journ](https://discuss.elastic.co/u/Maxime_Poirier-Journ)\
**Post date:** [February 12, 2018, 7:17pm UTC](https://discuss.elastic.co/t/watcher-error-when-executing-the-watch/119536/1 "2018-02-12T19:17:44Z")

</div>

Hi,

Im pretty new to watcher and painless. I'm getting this error and I have no clue why. Can you guys help me out for this one?

What i need to do is retrieve the value of "SAM Account Name: " in the ES item called "message" ( see screenshot below). So after trial and error scripting i came up with that script. It looks good but a little something seems to be missing. I'm getting this error: StringIndexOutOfBoundsException[String index out of range: -1] as soon as I execute the watch.

> {  
> "trigger": {  
> "schedule": {  
> "hourly": {  
> "minute": [  
> 0  
> ]  
> }  
> }  
> },  
> "input": {  
> "search": {  
> "request": {  
> "search\_type": "query\_then\_fetch",  
> "indices": [  
> "v7-\*"  
> ],  
> "types": ,  
> "body": {  
> "query": {  
> "bool": {  
> "must": [  
> {  
> "query\_string": {  
> "query": "A user account was created",  
> "analyze\_wildcard": true  
> }  
> },  
> {  
> "range": {  
> "@timestamp": {  
> "gte": "now-60m"  
> }  
> }  
> }  
> ]  
> }  
> }  
> }  
> },  
> "timeout\_in\_millis": 60000  
> }  
> },  
> "condition": {  
> "compare": {  
> "ctx.payload.hits.total": {  
> "gt": 0  
> }  
> }  
> },  
> "actions": {  
> "Create\_zendesk\_ticket": {  
> "transform": {  
> "script": {  
> "inline": "def items = ctx.payload.hits.hits.collect(item -\> ['cluster': item.\_source.cluster, 'message': item.\_source.message]);def users = ;def start\_i=0;def end\_i=0;for (item in items){start\_i = item['message'].lastIndexOf('SAM Account Name:');end\_i = item['message'].lastIndexOf('Display Name');users.add(item['cluster'].substring(start\_i,end\_i));}HashSet hashusers = new HashSet(users); return ['ticket': ['body': items,'requester': ['name': 'Ops Internal', 'email': '%emailhere%'], 'subject': 'An account was created on the following clusters', 'comment': String.join('\n',hashusers), 'priority': 'normal', 'tags': ['reccurent', 'ops', 'internal']]];",  
> "lang": "painless"  
> }  
> },  
> "webhook": {  
> "scheme": "https",  
> "host": "hosthere",  
> "port": 443,  
> "method": "post",  
> "path": "/apipathgoeshere/",  
> "params": {},  
> "headers": {  
> "Content-Type": "application/json"  
> },  
> "auth": {  
> "basic": {  
> "username": "usernamehere",  
> "password": "passwordhere"  
> }  
> },  
> "body": "{{#toJson}}ctx.payload{{/toJson}}"  
> }  
> }  
> }  
> }

---

<div class="post-metadata">

**Author:** ![Maxime\_Poirier-Journ](https://avatars.discourse-cdn.com/v4/letter/m/a8b319/32.png) [@Maxime\_Poirier-Journ](https://discuss.elastic.co/u/Maxime_Poirier-Journ)\
**Post date:** [February 12, 2018, 7:20pm UTC](https://discuss.elastic.co/t/watcher-error-when-executing-the-watch/119536/2 "2018-02-12T19:20:09Z")

</div>

![chrome_2018-02-12_14-14-09](https://us1.discourse-cdn.com/elastic/original/3X/f/6/f657716ac612ff4fc64eec59046cd7f6c5e09001.png)

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 13, 2018, 9:46am UTC](https://discuss.elastic.co/t/watcher-error-when-executing-the-watch/119536/3 "2018-02-13T09:46:05Z")

</div>

can you use the [Execute Watch API](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/watcher-api-execute-watch.html) and paste the output here? Otherwise it is super hard to help without having further information.

My current guess is that one of your lastIndexOf or substring calls uses a wrong offset.

---

<div class="post-metadata">

**Author:** ![Maxime\_Poirier-Journ](https://avatars.discourse-cdn.com/v4/letter/m/a8b319/32.png) [@Maxime\_Poirier-Journ](https://discuss.elastic.co/u/Maxime_Poirier-Journ)\
**Post date:** [February 15, 2018, 5:59pm UTC](https://discuss.elastic.co/t/watcher-error-when-executing-the-watch/119536/4 "2018-02-15T17:59:16Z")

</div>

The output cant really be pasted here. That beeing said

hits.total : 283861 this look suspicious 🤔

```
"condition": {
    "type": "compare",
    "status": "success",
    "met": true,
    "compare": {
      "resolved_values": {
        "ctx.payload.hits.total": 283861
      }
    }
  },
  "actions": [
    {
      "id": "Create_zendesk_ticket",
      "type": "webhook",
      "status": "failure",
      "transform": {
        "type": "script",
        "status": "failure",
        "reason": "ScriptException[runtime error]; nested: StringIndexOutOfBoundsException[String index out of range: -1]; "
      },
      "reason": "Failed to transform payload"
    }
  ]
},
"messages": []

```

}  
}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 16, 2018, 8:12am UTC](https://discuss.elastic.co/t/watcher-error-when-executing-the-watch/119536/5 "2018-02-16T08:12:32Z")

</div>

Please use something like gist or pastebin or paste the full watch.

Also, please try to run the search query first in isolation to see if matches your expections. In this example you seem to run `OR` combined queries in the `query_string` query which could explain that many results.

When pasting the execute watch API response others can see the search response, making it easier to see why your script failed.

---

<div class="post-metadata">

**Author:** ![Maxime\_Poirier-Journ](https://avatars.discourse-cdn.com/v4/letter/m/a8b319/32.png) [@Maxime\_Poirier-Journ](https://discuss.elastic.co/u/Maxime_Poirier-Journ)\
**Post date:** [February 20, 2018, 7:14pm UTC](https://discuss.elastic.co/t/watcher-error-when-executing-the-watch/119536/6 "2018-02-20T19:14:41Z")

</div>

Here is a pastebin:

[https://pastebin.com/2C2LqyHg](https://pastebin.com/2C2LqyHg)

---

<div class="post-metadata">

**Author:** ![Maxime\_Poirier-Journ](https://avatars.discourse-cdn.com/v4/letter/m/a8b319/32.png) [@Maxime\_Poirier-Journ](https://discuss.elastic.co/u/Maxime_Poirier-Journ)\
**Post date:** [February 20, 2018, 8:18pm UTC](https://discuss.elastic.co/t/watcher-error-when-executing-the-watch/119536/7 "2018-02-20T20:18:23Z")

</div>

I reworked my watch. Now I'm getting the expected number of results. That beeing said i'm still getting

`"reason": "ScriptException[runtime error]; nested: StringIndexOutOfBoundsException[String index out of range: -1]; "`

You can see the \_execute result above in the pastebin link ☹

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 21, 2018, 8:15am UTC](https://discuss.elastic.co/t/watcher-error-when-executing-the-watch/119536/8 "2018-02-21T08:15:59Z")

</div>

your field is named `Message` while you referred to it in the script you provided as `message`. Field names are case sensitive.

The out of bounds exception could result from a couple of calls, as you dont do any checking on length or content before using `substring`, `lastIndexOf`, which are the most likely candidates.

The transform does not properly bubble show our awesome painless exceptions. If you put the script for testing into the condition, you should be able to see a more proper stack trace, where exactly the script failed.

--Alex

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 21, 2018, 8:37am UTC](https://discuss.elastic.co/t/watcher-error-when-executing-the-watch/119536/9 "2018-02-21T08:37:54Z")

</div>

out of curiosity: What ES version are you running on?

---

<div class="post-metadata">

**Author:** ![Maxime\_Poirier-Journ](https://avatars.discourse-cdn.com/v4/letter/m/a8b319/32.png) [@Maxime\_Poirier-Journ](https://discuss.elastic.co/u/Maxime_Poirier-Journ)\
**Post date:** [February 21, 2018, 2:03pm UTC](https://discuss.elastic.co/t/watcher-error-when-executing-the-watch/119536/10 "2018-02-21T14:03:08Z")

</div>

Hi Alexander,

We're running 5.3. in prod. We're migrating to 6.1.1 tonight 😊 That being said if you look at the pastebin again there is 2 fields named "message". 1 is lower case and the other one is Upper case. The information i'm looking for is in the lower case one 😃

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 22, 2018, 8:25am UTC](https://discuss.elastic.co/t/watcher-error-when-executing-the-watch/119536/11 "2018-02-22T08:25:43Z")

</div>

hope everything went well. The reason for my ask is, that starting from ES 6.1 we will have proper exceptions with scripting issues, so that it should be super simple to find the offending code snippet, when you call the execute watch API.

--Alex

---

<div class="post-metadata">

**Author:** ![Maxime\_Poirier-Journ](https://avatars.discourse-cdn.com/v4/letter/m/a8b319/32.png) [@Maxime\_Poirier-Journ](https://discuss.elastic.co/u/Maxime_Poirier-Journ)\
**Post date:** [February 22, 2018, 9:25pm UTC](https://discuss.elastic.co/t/watcher-error-when-executing-the-watch/119536/13 "2018-02-22T21:25:01Z")

</div>

I managed to finally figured it out... i removed the unnecessary .substring

```
users.add(item['cluster'].substring(start_i,end_i))

```

for

```
users.add(item['cluster'])

```

Working as expected now 🤩

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2018, 9:25pm UTC](https://discuss.elastic.co/t/watcher-error-when-executing-the-watch/119536/14 "2018-03-22T21:25:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
