# Watcher Sending Slack dynamic Attachments

**URL:** <https://discuss.elastic.co/t/watcher-sending-slack-dynamic-attachments/120786>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [February 21, 2018, 8:25am UTC](https://discuss.elastic.co/t/watcher-sending-slack-dynamic-attachments/120786 "2018-02-21T08:25:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vaidabhishek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vaidabhishek/32/22766_2.png) [@vaidabhishek](https://discuss.elastic.co/u/vaidabhishek)\
**Post date:** [February 21, 2018, 8:25am UTC](https://discuss.elastic.co/t/watcher-sending-slack-dynamic-attachments/120786/1 "2018-02-21T08:25:41Z")

</div>

- I'm setting a watcher on ELK 6.2 to send dynamic attachments. I just want to extract string in the key `message` of all the hits. Below is the actions defined on my watcher. It's not working. The text is coming fine in the Alert, but not the attachment. The query returns hits, where `_source` only has one field `message`.

```auto
"actions": {
    "notify_slack": {
      "throttle_period_in_millis": 300,
      "slack": {
        "message": {
          "to": [
            "#seo-alerts"
          ],
          "text": "[SEO NGiNX Alert] [/getSeoPages] ({{ctx.payload.hits.total}} Errors)",
          "dynamic_attachments": {
            "list_path": "ctx.payload.hits.hits",
            "attachment_template": {
              "color": "danger",
              "title": "{{message}}",
              "text": "{{message}}"
            }
          }
        }
      }
    }
  }

```

This is what I get in my slack:

 ![15%20PM](https://us1.discourse-cdn.com/elastic/original/3X/7/5/75187757b03210139749508335c224b305abc9c9.png)

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 21, 2018, 8:35am UTC](https://discuss.elastic.co/t/watcher-sending-slack-dynamic-attachments/120786/2 "2018-02-21T08:35:13Z")

</div>

you are inside of a hits array, this means you should try to use `{{_source.message}}` to access the proper field, I assume your fields are just empty with your setup.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 21, 2018, 8:35am UTC](https://discuss.elastic.co/t/watcher-sending-slack-dynamic-attachments/120786/3 "2018-03-21T08:35:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
