# Watcher: transform

**URL:** <https://discuss.elastic.co/t/watcher-transform/112185>\
**Category:** Elasticsearch\
**Created:** [December 18, 2017, 9:18am UTC](https://discuss.elastic.co/t/watcher-transform/112185 "2017-12-18T09:18:23Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![mruthyu](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Post date:** [December 18, 2017, 9:18am UTC](https://discuss.elastic.co/t/watcher-transform/112185/1 "2017-12-18T09:18:24Z")

</div>

I want to use the transform section in watcher before action and wanted additional field to be added to the current payload. When I use the following painless script before the action I am getting only the epochtime in action and the original payload being lost. How to append the following epochtime to the ctx.payload so that I can access both.

"transform": {  
"script": {  
"inline": "return ['epochtime' : ctx.execution\_time.getMillis()]",  
"lang": "painless"  
}  
},

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [December 18, 2017, 10:04am UTC](https://discuss.elastic.co/t/watcher-transform/112185/2 "2017-12-18T10:04:02Z")

</div>

the returned data is replaced by the payload, which means you need to include the existing payload, something like this (untested, on top of my head)

```auto
def payload = ctx.payload; payload.epochtime = ... ; return payload;

```

--Alex

---

<div class="post-metadata">

**Author:** ![mruthyu](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Post date:** [December 18, 2017, 11:41am UTC](https://discuss.elastic.co/t/watcher-transform/112185/3 "2017-12-18T11:41:43Z")

</div>

Great. I will check this out.

---

<div class="post-metadata">

**Author:** ![mruthyu](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Post date:** [January 8, 2018, 10:33am UTC](https://discuss.elastic.co/t/watcher-transform/112185/4 "2018-01-08T10:33:20Z")

</div>

It works. Thanks. But when I add some more code (replaceAll()). I am not able to save the watcher. I see the following error.

**Watcher: An internal server error occurred**

"transform": {  
"script": {  
"inline": "def payload = ctx.payload; def newpayload = /[aeiou]/.matcher(ctx.payload).replaceAll(''); payload.epochtime = ctx.execution\_time.getMillis() ; return payload;",  
"lang": "painless"  
}  
},

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [January 8, 2018, 11:18am UTC](https://discuss.elastic.co/t/watcher-transform/112185/5 "2018-01-08T11:18:50Z")

</div>

please provide the exception as well and not just your snippet or again the full output of the execute watch API.

--Alex

---

<div class="post-metadata">

**Author:** ![mruthyu](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Post date:** [January 8, 2018, 11:26am UTC](https://discuss.elastic.co/t/watcher-transform/112185/6 "2018-01-08T11:26:10Z")

</div>

Hi Alex,

Thaks for looking into this. If I take out the statement def newpayload = /[aeiou]/.matcher(ctx.payload).replaceAll(''); from the script I am able to save the watcher.  
Otherwise it gives the above mentioned error in the Wather Edit page in Kibana.

Looks like it is related to enabling the **script.painless.regex.enabled** as the statement I am using is having the regex. Just I am wondering by default the **script.painless.regex.enabled** is not set may be it is throwing this error.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [January 8, 2018, 11:28am UTC](https://discuss.elastic.co/t/watcher-transform/112185/7 "2018-01-08T11:28:24Z")

</div>

can you try to store the watch in the console and see if an error gets returned that you can paste here?

And yes, you need to have that setting enabled in order to make it work, otherwise an exception will be thrown.

---

<div class="post-metadata">

**Author:** ![mruthyu](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Post date:** [January 8, 2018, 11:28am UTC](https://discuss.elastic.co/t/watcher-transform/112185/8 "2018-01-08T11:28:30Z")

</div>

Let me know what you think. I don't want to add script.painless.regex.enabled: true in elasticsearch.yml and restart the master nodes. Wanted to know whether I can set this parameter dynamically.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [January 8, 2018, 11:30am UTC](https://discuss.elastic.co/t/watcher-transform/112185/9 "2018-01-08T11:30:09Z")

</div>

this is not a dynamic parameter, for a very good reason, as it opens up a security issue, if someone can write complex long processing regular expressions.

Also, just checking for vowels is something you do not need a regex for, maybe you can work around that, i.e. by using `String.indexOf` is you just have such simple checks?

---

<div class="post-metadata">

**Author:** ![mruthyu](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Post date:** [January 8, 2018, 11:34am UTC](https://discuss.elastic.co/t/watcher-transform/112185/10 "2018-01-08T11:34:15Z")

</div>

Yes Sure. I want to replace some special characters like : " etc from the context.payload as these are disturbing the JSON structure in webhook.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 5, 2018, 11:34am UTC](https://discuss.elastic.co/t/watcher-transform/112185/11 "2018-02-05T11:34:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
