# Watcher index action not able to save

**URL:** <https://discuss.elastic.co/t/watcher-index-action-not-able-to-save/170844>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [March 5, 2019, 8:50am UTC](https://discuss.elastic.co/t/watcher-index-action-not-able-to-save/170844 "2019-03-05T08:50:35Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tallakh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tallakh/32/8860_2.png) [@tallakh](https://discuss.elastic.co/u/tallakh)\
**Post date:** [March 5, 2019, 8:50am UTC](https://discuss.elastic.co/t/watcher-index-action-not-able-to-save/170844/1 "2019-03-05T08:50:36Z")

</div>

We are using elastic cloud and elasticsearch and kibana 6.6.1. When I try to create an advanced watcher with an index action, it is not possible to save. There is an error in the browser console:

```
Error: Attempted to create unknown action type index.
    at JsonWatch.createAction (kibana.bundle.js:2)
    at kibana.bundle.js:2
    at Array.forEach (<anonymous>)
    at JsonWatchEditController.createActionsForWatch (kibana.bundle.js:2)
    at WatchEditTitleBarController.JsonWatchEditController._this.onWatchSave (kibana.bundle.js:2)
    at fn (eval at compile (vendors.bundle.dll.js:434), <anonymous>:4:212)
    at callback (vendors.bundle.dll.js:434)
    at Scope.$eval (vendors.bundle.dll.js:434)
    at Scope.$apply (vendors.bundle.dll.js:434)
    at HTMLButtonElement.<anonymous> (vendors.bundle.dll.js:434)
    at HTMLButtonElement.dispatch (vendors.bundle.dll.js:149)
    at HTMLButtonElement.elemData.handle (vendors.bundle.dll.js:149)

```

The action should be according to documentation:

```
"index_payload": {
  "transform": {
    "script": "return ['inAlert' : ctx.vars.fails_check]"
  },
  "index": {
    "index": "{{ctx.metadata.alertindex}}",
    "doc_type": "{{ctx.metadata.alerttype}}",
    "doc_id": "{{ctx.metadata.alertid}}"
  }
}

```

Any ideas what I'm doing wrong?

---

<div class="post-metadata">

**Author:** ![tallakh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tallakh/32/8860_2.png) [@tallakh](https://discuss.elastic.co/u/tallakh)\
**Post date:** [March 5, 2019, 8:55am UTC](https://discuss.elastic.co/t/watcher-index-action-not-able-to-save/170844/2 "2019-03-05T08:55:25Z")

</div>

And this is the entire watcher definition:

```json
{
  "trigger": {
    "schedule": {
      "interval": "1m"
    }
  },
  "input": {
    "chain": {
      "inputs": [
        {
          "alert": {
            "search": {
              "request": {
                "search_type": "query_then_fetch",
                "indices": ["watcheralerts"],
                "types": [],
                "body": {
                  "query": {
                    "bool": {
                      "must": [
                        {
                          "term": {
                            "_id": "{{ctx.metadata.alertid}}"
                          }
                        },
                        {
                          "term": {
                            "inAlert": true
                          }
                        }
                      ]
                    }
                  }
                }
              }
            }
          }
        },
        {
          "check": {
            "search": {
              "request": {
                "search_type": "query_then_fetch",
                "indices": ["heartbeat-*"],
                "types": [],
                "body": {
                  "query": {
                    "bool": {
                      "filter": [
                        {
                          "term": {
                            "monitor.status": {
                              "value": "down"
                            }
                          }
                        },
                        {
                          "range": {
                            "@timestamp": {
                              "gte": "now-1m"
                            }
                          }
                        },
                        {
                          "term": {
                            "monitor.name": "{{ctx.metadata.heartbeatname}}"
                          }
                        }
                      ]
                    }
                  },
                  "sort": "@timestamp"
                }
              }
            }
          }
        }
      ]
    }
  },
  "condition": {
    "script": {
      "source": "ctx.vars.fails_check = ctx.payload.check.hits.total != 0 && ctx.payload.check.hits.hits[0]._source.monitor.status != 'up'; ctx.vars.not_resolved = ctx.payload.alert.hits.total == 1;if (ctx.vars.fails_check && ctx.vars.not_resolved){return false;} else {return ctx.vars.fails_check || ctx.vars.not_resolved;}",
      "lang": "painless"
    }
  },
  "actions": {
    "log": {
      "transform": {
        "script": {
          "source": "return ['status': ctx.vars.fails_check ? 'down' : 'up']",
          "lang": "painless"
        }
      },
      "logging": {
        "level": "info",
        "text": "{{ctx.metadata.heartbeatname}} is {{ctx.payload.status}}"
      }
    },
    "slack_1": {
      "transform": {
        "script": {
          "source": "return ['status': ctx.vars.fails_check ? 'down' : 'up']",
          "lang": "painless"
        }
      },
      "slack": {
        "message": {
          "to": ["#web-api-notifications"],
          "text": "{{ctx.metadata.heartbeatname}} is {{ctx.payload.status}}"
        }
      }
    },
    "index_payload": {
      "transform": {
        "script": "return ['inAlert' : ctx.vars.fails_check]"
      },
      "index": {
        "index": "{{ctx.metadata.alertindex}}",
        "doc_type": "{{ctx.metadata.alerttype}}",
        "doc_id": "{{ctx.metadata.alertid}}"
      }
    }
  },
  "metadata": {
    "heartbeatname": "[CRM] GET /index.html",
    "heartbeatindex": "heartbeat-*",
    "alertid": "crm_get_index.html",
    "alertindex": ".watcheralerts",
    "alerttype": "doc",
    "tz": "Europe/Oslo"
  }
}

```

---

<div class="post-metadata">

**Author:** ![Bill\_McConaghy](https://avatars.discourse-cdn.com/v4/letter/b/ed655f/32.png) [@Bill\_McConaghy](https://discuss.elastic.co/u/Bill_McConaghy)\
**Post date:** [March 5, 2019, 7:59pm UTC](https://discuss.elastic.co/t/watcher-index-action-not-able-to-save/170844/3 "2019-03-05T19:59:58Z")

</div>

This is a bug. Could you please file an issue in the Kibana Github repo? [https://github.com/elastic/kibana/issues](https://github.com/elastic/kibana/issues)

---

<div class="post-metadata">

**Author:** ![tallakh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tallakh/32/8860_2.png) [@tallakh](https://discuss.elastic.co/u/tallakh)\
**Post date:** [March 5, 2019, 9:11pm UTC](https://discuss.elastic.co/t/watcher-index-action-not-able-to-save/170844/4 "2019-03-05T21:11:50Z")

</div>

Ok, added the issue here [https://github.com/elastic/kibana/issues/32517](https://github.com/elastic/kibana/issues/32517)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 2, 2019, 9:11pm UTC](https://discuss.elastic.co/t/watcher-index-action-not-able-to-save/170844/5 "2019-04-02T21:11:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
