# Watcher results into new index

**URL:** <https://discuss.elastic.co/t/watcher-results-into-new-index/196051>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [August 21, 2019, 6:56am UTC](https://discuss.elastic.co/t/watcher-results-into-new-index/196051 "2019-08-21T06:56:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Denis.topa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/denis.topa/32/44993_2.png) [@Denis.topa](https://discuss.elastic.co/u/Denis.topa)\
**Post date:** [August 21, 2019, 6:56am UTC](https://discuss.elastic.co/t/watcher-results-into-new-index/196051/1 "2019-08-21T06:56:41Z")

</div>

Hello.  
Is there a way to copy the entire document from a index to another as an watcher action?  
Here is what I want to achieve:  
I have several watchers configured which currently are sending alerts to email, but I would like to have the same documents(for which watcher was triggered) into a separate index so I can build a visualization based on all watchers alerts.

Please note that the watcher index action doesn't fit my needs because it index the payload of the search query, instead I want to have all fields indexed as in the original index.

Or may be there is another way to do this?  
Thank you!

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 21, 2019, 2:06pm UTC](https://discuss.elastic.co/t/watcher-results-into-new-index/196051/2 "2019-08-21T14:06:46Z")

</div>

Hey,

I am not sure I understand the full requirement. If you want to index the same documents that a search returned, you need to pick the `_source` of each document index that using the index action - which supports multiple documents. One requirement of this is to convert this to the data you want to index using a `transform` before calling the `index` action.

This data is also already written in the `.watcher-history` indices. Maybe you can reuse those for you visualization without requiring to index that data a second time.

--Alex

---

<div class="post-metadata">

**Author:** ![Denis.topa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/denis.topa/32/44993_2.png) [@Denis.topa](https://discuss.elastic.co/u/Denis.topa)\
**Post date:** [August 22, 2019, 6:39am UTC](https://discuss.elastic.co/t/watcher-results-into-new-index/196051/3 "2019-08-22T06:39:06Z")

</div>

Thanks for your reply Alexander,  
I want to use watches results to be reviewed by a person, so I need only events generated by watchers.  
Something like a SIEM, it would be great if It was possible to watchers results as a Input in ELK Siem, but I don't know if this is possible.  
So I'm thinking of having watchers results as a separate index, where each event will be reviewed by a security person and in case of an incident will handle it with relevant team.  
Hope these details will make the task clear.

I'm relatively new to elasticsearch, so there is a lot of what I need to learn.  
Could you please bring me an example of " _you need to pick the `_source` of each document index that using the index action - which supports multiple documents. One requirement of this is to convert this to the data you want to index using a `transform` before calling the `index` action._"

Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 19, 2019, 6:39am UTC](https://discuss.elastic.co/t/watcher-results-into-new-index/196051/4 "2019-09-19T06:39:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
