# Watcher trigger playload

**URL:** <https://discuss.elastic.co/t/watcher-trigger-playload/206920>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [November 7, 2019, 7:54am UTC](https://discuss.elastic.co/t/watcher-trigger-playload/206920 "2019-11-07T07:54:07Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Karrie\_Koo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karrie_koo/32/52576_2.png) [@Karrie\_Koo](https://discuss.elastic.co/u/Karrie_Koo)\
**Post date:** [November 7, 2019, 7:54am UTC](https://discuss.elastic.co/t/watcher-trigger-playload/206920/1 "2019-11-07T07:54:08Z")

</div>

If I want to change the category watcher.logging.bppm.(Minor), based on different log Meassage ID, how can I do?

"actions": {  
"log\_error": {  
"logging": {  
"category": "watcher.logging.bppm.Minor",  
"level": "info",  
"text": "Found {{ctx.payload.hits.total}} stuck thread in the logs (EAP)\n{{#ctx.payload.hits.hits}}[MINOR] {{\_source.wlstimestamp}} {{\_source.hostname}} {{\_source.wlsdomain}} {{\_source.wlsname}} {{\_source.msgId}}\n{{/ctx.payload.hits.hits}}"  
}

It means when ctx.results[0].\_source.msgId == BEA-310003, then the category becomes watcher.logging.bppm.Critical.

Many thanks if you can help

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 7, 2019, 8:58am UTC](https://discuss.elastic.co/t/watcher-trigger-playload/206920/2 "2019-11-07T08:58:05Z")

</div>

the category is a static text at the moment and thus can only be set when the watch is created.

However, a potential workaround could be the use of conditional actions, where you have two logger actions with different categories and only based on the condition one of those actions is called.

See [https://www.elastic.co/guide/en/elasticsearch/reference/7.4/action-conditions.html](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/action-conditions.html) on how to add conditions to actions.

---

<div class="post-metadata">

**Author:** ![Karrie\_Koo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karrie_koo/32/52576_2.png) [@Karrie\_Koo](https://discuss.elastic.co/u/Karrie_Koo)\
**Post date:** [November 7, 2019, 9:25am UTC](https://discuss.elastic.co/t/watcher-trigger-playload/206920/3 "2019-11-07T09:25:44Z")

</div>

{  
"trigger": {  
"schedule": {  
"interval": "20s"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"eap\_wls\_server\*",  
"_:eap\_wls\_server_"  
],  
"types": ,  
"body": {  
"size": 100,  
"query": {  
"bool": {  
"must": [  
{  
"range": {  
"@timestamp": {  
"gte": "now-15m/m",  
"lte": "now"  
}  
}  
},  
{  
"simple\_query\_string": {  
"query": "(OutOfMemoryError) | (000112) | (310006) | (090078) | (040028) | (040507) | (281016) | (280061)",  
"fields": [  
"logMessage",  
"msgId"  
]  
}  
}  
]  
}  
},  
"sort": [  
{  
"@timestamp": {  
"order": "desc"  
}  
}  
]  
}  
}  
}  
},  
"condition": { "script": {  
"source": "def Serverity = ['Critical', 'Major', 'Minor']; if (BEA-310003) {Severity = Critical;} else if (BEA-000112) { Serverity = Major;} else if (BEA-310006) {Severity = Critical;} else if (ctx.results[0].\_source.msgId == BEA-090078) {Severity = Critical;} else if (ctx.results[0].\_source.msgId == BEA-040028) {Severity = Critical;} else if (ctx.results[0].\_source.msgId == BEA-040507) {Serverity = Major;} else if (ctx.results[0].\_source.msgId == BEA-281016) {Severity = Critical;} else if (ctx.results[0].\_source.msgId == BEA-280061) {Severity = Critical;}}",  
"lang": "painless"  
},  
"compare": {  
"ctx.payload.hits.total": {  
"gt": 0  
}  
}  
},  
"actions": {  
"log\_error": {  
"transform": {  
"script": {  
"source": "return [ctx.playload.Severity]",  
"lang": "painless"  
}  
},  
"logging": {  
"category": "watcher.logging.bppm.{{ctx.playload.Severity}}",  
"level": "info",  
"text": "Found {{ctx.payload.hits.total}} stuck thread in the logs (EAP)\n{{#ctx.payload.hits.hits}}[ctx.playload.Severity {{\_source.wlstimestamp}} {{\_source.hostname}} {{\_source.wlsdomain}} {{\_source.wlsname}} {{\_source.msgId}}\n{{/ctx.payload.hits.hits}}"  
}  
},  
"email\_alert": {  
"email": {  
"profile": "standard",  
"to": [  
"'Karrie KOO [kks629@ha.org.hk](mailto:kks629@ha.org.hk)'"  
],  
"subject": "{{ctx.payload.hits.hits.0.\_source.hostname}} {{ctx.payload.hits.hits.0.\_source.wlstimestamp}} {{ctx.payload.hits.hits.0.\_source.wlsdomain}} {{ctx.payload.hits.hits.0.\_source.wlsname}} {{ctx.payload.hits.hits.0.\_source.msgId}} [No. of Matched Pattern: {{ctx.payload.hits.total}}]",  
"body": {  
"html": "

1. {{#ctx.payload.hits.hits}} **Host** : {{\_source.hostname}}  
  
 **Date** : {{\_source.wlstimestamp}}  
  
 **Domain** : {{\_source.wlsdomain}}  
  
 **Managed Server** : {{\_source.wlsname}}  
  
 **Monitoring Pattern** : {{\_source.msgId}}  
  
 **Log Message** : {{\_source.logMessage}}
* * *
 {{/ctx.payload.hits.hits}}
"  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![Karrie\_Koo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karrie_koo/32/52576_2.png) [@Karrie\_Koo](https://discuss.elastic.co/u/Karrie_Koo)\
**Post date:** [November 7, 2019, 9:26am UTC](https://discuss.elastic.co/t/watcher-trigger-playload/206920/4 "2019-11-07T09:26:29Z")

</div>

Thanks so much

This is my script and it results with an internal error.  
How can I fix it/\_\

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 7, 2019, 9:30am UTC](https://discuss.elastic.co/t/watcher-trigger-playload/206920/5 "2019-11-07T09:30:28Z")

</div>

as I wrote in my previous reply, you cannot use mustache in the logger category, and this is why you need to use a conditional action.

---

<div class="post-metadata">

**Author:** ![Karrie\_Koo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karrie_koo/32/52576_2.png) [@Karrie\_Koo](https://discuss.elastic.co/u/Karrie_Koo)\
**Post date:** [November 8, 2019, 1:52am UTC](https://discuss.elastic.co/t/watcher-trigger-playload/206920/6 "2019-11-08T01:52:33Z")

</div>

```
      "transform" : {
      "script" : {
        "source" : "def vars = ctx.vars ; ctx.vars.severity = ['Critical', 'Major', 'Minor'];if (BEA-310003) {ctx.vars.severity = Critical}",
      "lang": "painless"
      }
    },

```

"actions": {  
"log\_error": {   
"logging": {  
"category": "watcher.logging.bppm.{{ctx.vars.Severity}}",  
"level": "info",  
"text": "Found {{ctx.payload.hits.total}} stuck thread in the logs (EAP)\n{{#ctx.payload.hits.hits}}[MINOR] {{\_source.wlstimestamp}} {{\_source.hostname}} {{\_source.wlsdomain}} {{\_source.wlsname}} {{\_source.msgId}}\n{{/ctx.payload.hits.hits}}"  
}  
},

I have tried use conditional action, but it is still not working

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 8, 2019, 9:00am UTC](https://discuss.elastic.co/t/watcher-trigger-playload/206920/7 "2019-11-08T09:00:42Z")

</div>

I do not see a condition in your last code sample, please always provide the full watch. Thanks!

---

<div class="post-metadata">

**Author:** ![Karrie\_Koo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karrie_koo/32/52576_2.png) [@Karrie\_Koo](https://discuss.elastic.co/u/Karrie_Koo)\
**Post date:** [November 8, 2019, 9:12am UTC](https://discuss.elastic.co/t/watcher-trigger-playload/206920/8 "2019-11-08T09:12:12Z")

</div>

{  
"trigger": {  
"schedule": {  
"interval": "20s"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"eap\_wls\_server\*",  
"_:eap\_wls\_server_"  
],  
"types": ,  
"body": {  
"size": 100,  
"query": {  
"bool": {  
"must": [  
{  
"range": {  
"@timestamp": {  
"gte": "now-15m/m",  
"lte": "now"  
}  
}  
},  
{  
"simple\_query\_string": {  
"query": "(OutOfMemoryError) | (000112) | (310006) | (090078) | (040028) | (040507) | (281016) | (280061)",  
"fields": [  
"logMessage",  
"msgId"  
]  
}  
}  
]  
}  
},  
"sort": [  
{  
"@timestamp": {  
"order": "desc"  
}  
}  
]  
}  
}  
}  
},  
"condition": {  
"compare": {  
"ctx.payload.hits.total": {  
"gt": 0  
}  
}  
},  
"transform" : {  
"script" : {  
"source" : {  
"playload": "Severity: ['Critical', 'Major', 'Minor']",  
"lang": "painless"  
}  
}  
},  
"actions": {  
"log\_error": {   
"condition": {  
"script" : "if (BEA-310003) {ctx.playload.Severity = Critical;} else if (BEA-000112) { ctx.playload.Severity = Major;} else if (BEA-310006) {ctx.playload.Severity = Critical;} else if (BEA-090078) {ctx.playload.Severity = Critical;} else if (BEA-040028) {ctx.playload.Severity = Critical;} else if (BEA-040507) {ctx.playload.Severity = Major;} else if (BEA-281016) {ctx.playload.Severity = Critical;} else if (BEA-280061) {ctx.playload.Severity = Critical;}}"  
},  
"logging": {  
"category": "watcher.logging.bppm.NONE",  
"level": "info",  
"text": "Found {{ctx.payload.hits.total}} stuck thread in the logs (EAP)\n{{#ctx.payload.hits.hits}}[{{ctx.playload.Severity}}] {{\_source.wlstimestamp}} {{\_source.hostname}} {{\_source.wlsdomain}} {{\_source.wlsname}} {{\_source.msgId}}\n{{/ctx.payload.hits.hits}}"  
}  
},  
"email\_alert": {  
"email": {  
"profile": "standard",  
"to": [  
"'Karrie KOO [kks629@ha.org.hk](mailto:kks629@ha.org.hk)'"  
],  
"subject": "{{ctx.payload.hits.hits.0.\_source.hostname}} {{ctx.payload.hits.hits.0.\_source.wlstimestamp}} {{ctx.payload.hits.hits.0.\_source.wlsdomain}} {{ctx.payload.hits.hits.0.\_source.wlsname}} {{ctx.payload.hits.hits.0.\_source.msgId}} [No. of Matched Pattern: {{ctx.payload.hits.total}}]",  
"body": {  
"html": "

1. {{#ctx.payload.hits.hits}} **Host** : {{\_source.hostname}}  
  
 **Date** : {{\_source.wlstimestamp}}  
  
 **Domain** : {{\_source.wlsdomain}}  
  
 **Managed Server** : {{\_source.wlsname}}  
  
 **Monitoring Pattern** : {{\_source.msgId}}  
  
 **Log Message** : {{\_source.logMessage}}
* * *
 {{/ctx.payload.hits.hits}}
"  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 8, 2019, 9:48am UTC](https://discuss.elastic.co/t/watcher-trigger-playload/206920/9 "2019-11-08T09:48:13Z")

</div>

please take the time to properly format your message. This is super hard to read.

A condition in an action needs to return true or false. Setting anything in the payload will not have any effect.

```auto
"actions" : {
  "logging_cat_foo" : {
    "condition" : {
     "script" "return ctx.payload.foo == 'foo'"
    }
    "logging" : {
      "category" : "foo",
      "text" : "This is foo"
    }
  },
  "logging_cat_bar" : {
    "condition" : {
     "script" "return ctx.payload.foo != 'foo'"
    }
    "logging" : {
      "category" : "bar",
      "text" : "This is bar"
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 6, 2019, 9:48am UTC](https://discuss.elastic.co/t/watcher-trigger-playload/206920/10 "2019-12-06T09:48:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
