# Watcher parse an array

**URL:** <https://discuss.elastic.co/t/watcher-parse-an-array/220777>\
**Category:** Elasticsearch\
**Created:** [February 25, 2020, 6:27am UTC](https://discuss.elastic.co/t/watcher-parse-an-array/220777 "2020-02-25T06:27:21Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![cmiscloni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cmiscloni/32/63250_2.png) [@cmiscloni](https://discuss.elastic.co/u/cmiscloni)\
**Post date:** [February 25, 2020, 6:27am UTC](https://discuss.elastic.co/t/watcher-parse-an-array/220777/1 "2020-02-25T06:27:21Z")

</div>

Hi all,

I try to monitor some events with watcher but I can't find the solution to parse the hits of the array below

{  
"watch\_id": "_inlined_",  
"node": "\*\*\*\*\*\*\*\*\*\*\*\*\*_",  
"state": "executed",  
"status": {  
"state": {  
"active": true,  
"timestamp": "2020-02-25T06:20:38.759Z"  
},  
"last\_checked": "2020-02-25T06:20:38.760Z",  
"last\_met\_condition": "2020-02-25T06:20:38.760Z",  
"actions": {  
"email\_admin": {  
"ack": {  
"timestamp": "2020-02-25T06:20:38.759Z",  
"state": "awaits\_successful\_execution"  
},  
"last\_execution": {  
"timestamp": "2020-02-25T06:20:38.760Z",  
"successful": false,  
"reason": ""  
}  
}  
},  
"execution\_state": "executed",  
"version": -1  
},  
"trigger\_event": {  
"type": "manual",  
"triggered\_time": "2020-02-25T06:20:38.760Z",  
"manual": {  
"schedule": {  
"scheduled\_time": "2020-02-25T06:20:38.760Z"  
}  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
""  
],  
"rest\_total\_hits\_as\_int": true,  
"body": {  
"size": 0,  
"query": {  
"bool": {  
"filter": [  
{  
"range": {  
"@timestamp": {  
"gte": "now-120m",  
"lte": "now"  
}  
}  
},  
{  
"terms": {  
"event.code": [  
"4728",  
"4729"  
]  
}  
}  
]  
}  
}  
}  
}  
}  
},  
"condition": {  
"compare": {  
"ctx.payload.hits.total": {  
"gt": 0  
}  
}  
},  
"metadata": {  
"name": "Security Group",  
"xpack": {  
"type": "json"  
}  
},  
"result": {  
"execution\_time": "2020-02-25T06:20:38.760Z",  
"execution\_duration": 690,  
"input": {  
"type": "search",  
"status": "success",  
"payload": {  
"\_shards": {  
"total": 7,  
"failed": 0,  
"successful": 7,  
"skipped": 0  
},  
"hits": {  
"hits": [],  
"total": 2,  
"max\_score": null  
},  
"took": 686,  
"timed\_out": false  
},  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"_"  
],  
"rest\_total\_hits\_as\_int": true,  
"body": {  
"size": 0,  
"query": {  
"bool": {  
"filter": [  
{  
"range": {  
"@timestamp": {  
"gte": "now-120m",  
"lte": "now"  
}  
}  
},  
{  
"terms": {  
"event.code": [  
"4728",  
"4729"  
]  
}  
}  
]  
}  
}  
}  
}  
}  
},  
"condition": {  
"type": "compare",  
"status": "success",  
"met": true,  
"compare": {  
"resolved\_values": {  
**"ctx.payload.hits.total": 2**  
}  
}  
},  
"actions": [  
{  
"id": "email\_admin",  
"type": "email",  
"status": "failure",  
"error": {  
"root\_cause": [  
{  
"type": "exception",  
"reason": "foreach object [ctx.payload.hits.hits] **was an empty list, could not run any action**"  
}  
],  
"type": "exception",  
"reason": "foreach object [ctx.payload.hits.hits] was an empty list, could not run any action"  
}  
}  
]  
},  
"messages":   
}

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [February 25, 2020, 8:47am UTC](https://discuss.elastic.co/t/watcher-parse-an-array/220777/2 "2020-02-25T08:47:09Z")

</div>

Could you please use markdown to make your code easier to read, also could you provide full watcher query ?

I'm using it like "foreach": "ctx.payload.hits.hits"

---

<div class="post-metadata">

**Author:** ![cmiscloni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cmiscloni/32/63250_2.png) [@cmiscloni](https://discuss.elastic.co/u/cmiscloni)\
**Post date:** [February 25, 2020, 8:58am UTC](https://discuss.elastic.co/t/watcher-parse-an-array/220777/3 "2020-02-25T08:58:59Z")

</div>

Yes, see below

```
{
  "trigger": {
"schedule": {
  "interval": "240m"
}
  },
  "input": {
"search": {
  "request": {
    "search_type": "query_then_fetch",
    "indices": [
      "xxxx-*"
    ],
    "rest_total_hits_as_int": true,
    "body": {
      "size": 0,
      "query": {
        "bool": {
          "filter": [
            {
              "range": {
                "@timestamp": {
                  "gte": "now-240m",
                  "lte": "now"
                }
              }
            },
            {
              "terms": {
                "event.action.keyword": [
                  "added-group-account-to",
                  "deleted-group-account-from"
                ]
              }
            }
          ]
        }
      }
    }
  }
}
  },
  "condition": {
"compare": {
  "ctx.payload.hits.total": {
    "gt": 0
  }
}
  },
  "actions": {
"email_admin": {
  "throttle_period_in_millis": 50000,
  "foreach" : "ctx.payload.hits.hits",
  "email": {
    "profile": "standard",
    "to": [
      "xxxxxxxx"
    ],
    "subject": "Warning: User Added to Security Enabled Group",
    "body": {
      "text": "The user {{ctx.payload._source.user.name}} was added to a security enabled group !"
    }
  }
}
  }
}
```

---

<div class="post-metadata">

**Author:** ![cmiscloni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cmiscloni/32/63250_2.png) [@cmiscloni](https://discuss.elastic.co/u/cmiscloni)\
**Post date:** [February 25, 2020, 9:20am UTC](https://discuss.elastic.co/t/watcher-parse-an-array/220777/4 "2020-02-25T09:20:30Z")

</div>

The result of this watcher execution

> ```
> "ctx.payload.hits.total": 2
> foreach object [ctx.payload.hits.hits] was an empty list, could not run any action
> 
> ```

---

<div class="post-metadata">

**Author:** ![cmiscloni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cmiscloni/32/63250_2.png) [@cmiscloni](https://discuss.elastic.co/u/cmiscloni)\
**Post date:** [February 25, 2020, 9:44am UTC](https://discuss.elastic.co/t/watcher-parse-an-array/220777/5 "2020-02-25T09:44:42Z")

</div>

I setted the body to "0", this was the problem.  
Thanks

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [February 25, 2020, 9:57am UTC](https://discuss.elastic.co/t/watcher-parse-an-array/220777/6 "2020-02-25T09:57:25Z")

</div>

Including "ctx.payload.\_source.user.name" in the mail body was causing an error ?

because you can iterate over with ctx.payload.hits.hits.0.\_source.user.name with a transform action

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 24, 2020, 9:57am UTC](https://discuss.elastic.co/t/watcher-parse-an-array/220777/7 "2020-03-24T09:57:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
