# Watcher http input : What is the expected response?

**URL:** <https://discuss.elastic.co/t/watcher-http-input-what-is-the-expected-response/323608>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [January 20, 2023, 3:37pm UTC](https://discuss.elastic.co/t/watcher-http-input-what-is-the-expected-response/323608 "2023-01-20T15:37:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Javier\_Molina\_Sanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/javier_molina_sanz/32/116213_2.png) [@Javier\_Molina\_Sanz](https://discuss.elastic.co/u/Javier_Molina_Sanz)\
**Post date:** [January 20, 2023, 3:37pm UTC](https://discuss.elastic.co/t/watcher-http-input-what-is-the-expected-response/323608/1 "2023-01-20T15:37:47Z")

</div>

Hi team,

I am trying to build a watcher that calls an external web service to build the query and then fire an action.

```auto
 "input": {
    "http": {
      "request": {
        "scheme": "https",
        "host": "myhost",
        "port": 443,
        "method": "get",
        "path": "/es",
        "params": {},
        "headers": {}
      }
    }
  },

```

The problem is that I don't understand from [the docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/input-http.html) what the response looks like. I'd like to send a query so that it gets executed on Elastic search, but I don't know what response the HTTP input is expecting.

This is the response I am trying at the moment, but it does not seem to work as it does not return any results, and there are results. I've replaced my query and my script with ${myquery} and ${myscript}

```auto
request: {
      indices: ['logstash-*'],
      rest_total_hits_as_int: true,
      body: {
        size: 0,
        query: {
          query_string: {
            query:
              ${myquery}
          },
        },
        aggs: {
          account_to_number: {
            terms: {
              script:
              ${myscript}
              min_doc_count: 100,
              size: 500,
            },
          },
        },
      },
    },
  });

```

Am I missing anything?

Thanks in advance

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [January 23, 2023, 4:20pm UTC](https://discuss.elastic.co/t/watcher-http-input-what-is-the-expected-response/323608/2 "2023-01-23T16:20:17Z")

</div>

First, use the `_execute` endpoint in DevTools console to "test" the Watch (without fully saving it) and see the response in the right hand pane.

Second, use this example to see how one can extract information from the response to the webhook call: [compare\_shard\_primary\_and\_replica · GitHub](https://gist.github.com/richcollier/5643e649a2816ed317d0caf3917263b8)

Third, you will need to use chained inputs where you can take the info from one input type (here a webhook call) and pass that information onto a subsequent input type (in your case a query to Elasticsearch). See an example of chained inputs here: [insight\_watch.json · GitHub](https://gist.github.com/richcollier/7e5603c366b9fcece6f1a8b1b3cf4d3f)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 20, 2023, 4:20pm UTC](https://discuss.elastic.co/t/watcher-http-input-what-is-the-expected-response/323608/3 "2023-02-20T16:20:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
