# Watcher - how to call values out of the aggregation that triggers an alert into xml for a webhook action

**URL:** <https://discuss.elastic.co/t/watcher-how-to-call-values-out-of-the-aggregation-that-triggers-an-alert-into-xml-for-a-webhook-action/67549>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [November 29, 2016, 9:20pm UTC](https://discuss.elastic.co/t/watcher-how-to-call-values-out-of-the-aggregation-that-triggers-an-alert-into-xml-for-a-webhook-action/67549 "2016-11-29T21:20:06Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![casieowen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/casieowen/32/8734_2.png) [@casieowen](https://discuss.elastic.co/u/casieowen)\
**Post date:** [November 29, 2016, 9:20pm UTC](https://discuss.elastic.co/t/watcher-how-to-call-values-out-of-the-aggregation-that-triggers-an-alert-into-xml-for-a-webhook-action/67549/1 "2016-11-29T21:20:07Z")

</div>

Hi elastic community!

We have watcher alerts now hooked up to an internal alerting/ticketing system using webhook with an xml body. That is all working. I'm wondering how I can call values from the aggregations that trigger the alerts in the xml so that the alert titles/details have meaningful info. For example, if I look at watch history, here is a bucket. I'd want to format the xml to include the value and the key. For example:

Java heap usage is %value% on %key%

```
                                         "doc_count": 3,
                                         "memory": {
                                            "value": 72
                                         },
                                         "key": "node7"

```

That same data is available in the index we're creating with the index payload action of the watch. But I assume there is a way to grab the values that are triggering the webhook action at the time and insert them into the call them within the xml body?

Can you help with this? I'm including the watch definition below. (yes, the threshold is 0, but that's just for testing. :))

Thanks,  
Casie

PUT \_watcher/watch/watch\_jvmheapusedpercenttoxaptest  
{  
"trigger": {  
"schedule": {  
"interval": "1m"  
}  
},  
"input": {  
"search": {  
"request": {  
"indices": [  
".marvel-\*"  
],  
"search\_type": "count",  
"body": {  
"query": {  
"filtered": {  
"filter": {  
"range": {  
"@timestamp": {  
"gte": "now-2m",  
"lte": "now"  
}  
}  
}  
}  
},  
"aggs": {  
"minutes": {  
"date\_histogram": {  
"field": "@timestamp",  
"interval": "minute"  
},  
"aggs": {  
"nodes": {  
"terms": {  
"field": "node.name.raw",  
"size": 10,  
"order": {  
"memory": "desc"  
}  
},  
"aggs": {  
"memory": {  
"avg": {  
"field": "jvm.mem.heap\_used\_percent"  
}  
}  
}  
}  
}  
}  
}  
}  
}  
}  
},  
"throttle\_period": "30m",  
"condition": {  
"script": "if (ctx.payload.aggregations.minutes.buckets.size() == 0) return false; def latest = ctx.payload.aggregations.minutes.buckets[-1]; def node = latest.nodes.buckets[0]; return node && node.memory && node.memory.value \>= 0;"  
},  
"actions": {  
"index\_payload": {  
"index": {  
"index": "watch\_jvmheapusedpercent",  
"doc\_type": "watch\_record"  
}  
},  
"xap\_webhook": {  
"webhook": {  
"method": "POST",  
"host": "[www.example.com](http://www.example.com)",  
"port": 443,  
"scheme": "https",  
"headers": {  
"Content-Type": "application/xml",  
"accept": "text/xml"  
},  
"path": "/xap",  
"body": bunch of xml  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [December 1, 2016, 9:50am UTC](https://discuss.elastic.co/t/watcher-how-to-call-values-out-of-the-aggregation-that-triggers-an-alert-into-xml-for-a-webhook-action/67549/2 "2016-12-01T09:50:14Z")

</div>

Hey Casie,

so the index action is just using `ctx.payload` as the document and indexes it into the `watch_jvmheapusedpercent` index. You can refer to that in the body by using `"body" : "{{ctx.payload.path.to.value.you.want.to.refer}}"`.

Is that what you want, or did I misread your question?

--Alex

---

<div class="post-metadata">

**Author:** ![casieowen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/casieowen/32/8734_2.png) [@casieowen](https://discuss.elastic.co/u/casieowen)\
**Post date:** [December 2, 2016, 9:08pm UTC](https://discuss.elastic.co/t/watcher-how-to-call-values-out-of-the-aggregation-that-triggers-an-alert-into-xml-for-a-webhook-action/67549/3 "2016-12-02T21:08:28Z")

</div>

Yeah, that's what we ended up doing. Thanks for the response,

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 30, 2016, 9:08pm UTC](https://discuss.elastic.co/t/watcher-how-to-call-values-out-of-the-aggregation-that-triggers-an-alert-into-xml-for-a-webhook-action/67549/4 "2016-12-30T21:08:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
