# Watcher: How to extract @timestamp using transform map?

**URL:** <https://discuss.elastic.co/t/watcher-how-to-extract-timestamp-using-transform-map/253662>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [October 29, 2020, 9:20am UTC](https://discuss.elastic.co/t/watcher-how-to-extract-timestamp-using-transform-map/253662 "2020-10-29T09:20:00Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![kelk](https://avatars.discourse-cdn.com/v4/letter/k/13edae/32.png) [@kelk](https://discuss.elastic.co/u/kelk)\
**Post date:** [October 29, 2020, 9:20am UTC](https://discuss.elastic.co/t/watcher-how-to-extract-timestamp-using-transform-map/253662/1 "2020-10-29T09:20:00Z")

</div>

In Watcher, i'm trying to extract the `@timestamp` field from payload

```auto
        return [
            'my_group_array': ctx.payload.hits.hits,
            'my_group_fields': ctx.payload.hits.hits.stream()
            .map(t-> {return ['timestamp': t._source.@timestamp, 'eventSource': t._source.eventSource, 'eventName': t._source.eventName, 'recipientAccountId': t._source.recipientAccountId, 'userIdentity': t._source.userIdentity.principalId]})
            .collect(Collectors.toList())
        ]

```

the `@` symbol causes the problem as the above works if I replace a similar eventtime field. Any idea how to extract variable which has `@` in it within a watcher transform? I've tried enclosing with double quotes, but still fails

Error in case if anyone have seen this before

```auto
[script_exception] compile error, with { script_stack={ 0="... ['timestamp': t._source.@timestamp, 'eventSourc ..." & 1=" ^---- HERE" } & script="\r\n return [\r\n 'my_group_array': ctx.payload.hits.hits,\r\n 'my_group_fields': ctx.payload.hits.hits.stream()\r\n .map(t-> {return ['timestamp': t._source.\"@timestamp\",

```

Incoming data is

```auto
            {
              "_index": "myindex",
              "_type": "_doc",
              "_source": {
                "@timestamp": "2020-10-28T16:02:19.676Z",
                "eventSource": "kms.amazonaws.com",
                "eventName": "blahal",
                "recipientAccountId": "12345",
                "userIdentity": {
                  "principalId": "xxxxxxxxxyyyyyyyy"
                }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 26, 2020, 9:20am UTC](https://discuss.elastic.co/t/watcher-how-to-extract-timestamp-using-transform-map/253662/2 "2020-11-26T09:20:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
