# Watcher using metadata array in input terms

**URL:** <https://discuss.elastic.co/t/watcher-using-metadata-array-in-input-terms/271273>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [April 26, 2021, 3:06pm UTC](https://discuss.elastic.co/t/watcher-using-metadata-array-in-input-terms/271273 "2021-04-26T15:06:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Destan](https://avatars.discourse-cdn.com/v4/letter/d/50afbb/32.png) [@Destan](https://discuss.elastic.co/u/Destan)\
**Post date:** [April 26, 2021, 3:06pm UTC](https://discuss.elastic.co/t/watcher-using-metadata-array-in-input-terms/271273/1 "2021-04-26T15:06:52Z")

</div>

Hello guys, I would like to know if it's possible to use metadata as an array like this:

```auto
"metadata": {
    "MyList": [
        "1",
        "2",
        "3",
        "4"
      ],
   "from": "60m"
 }

```

and use it as a parameters for my input:

```auto
 "input": {
     "search": {
       "request": {
         "search_type": "query_then_fetch",
         "indices": [
           "*test*"
         ],
         "rest_total_hits_as_int": true,
         "body": {
           "size": 0,
           "query": {
             "bool": {
               "must": [
                 {
                   "range": {
                     "@timestamp": {
                       "from": "now-{{ctx.metadata.from}}",
                       "to": "now"
                     }
                   }
                 },
                 {
                   "terms": {
                     **"id": "{{ctx.metadata.MyList}}"**
                   }
                 }
               ]
             }
           },
           "aggs": {
             "entite": {
               "terms": {
                 "field": "id.keyword"
               }
             }
           }
         }
       }
     }
   }

```

I would like that to act the same as:

```auto
{
"terms": {
    "id": [
        "1",
        "2",
        "3",
        "4"
   ],
}

```

But when i'm trying it, my terms is transformed to:

```auto
"terms": {
   "id": "{0=1, 1=2, 2=3, 3=4}"
 }

```

Do you have any idea, if it's possible? I would like to avoid to duplicate MyList inside a condition and inside the input.  
Thanks in advance

---

<div class="post-metadata">

**Author:** ![Destan](https://avatars.discourse-cdn.com/v4/letter/d/50afbb/32.png) [@Destan](https://discuss.elastic.co/u/Destan)\
**Post date:** [May 3, 2021, 11:57am UTC](https://discuss.elastic.co/t/watcher-using-metadata-array-in-input-terms/271273/2 "2021-05-03T11:57:10Z")

</div>

up! 😭

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [May 3, 2021, 2:47pm UTC](https://discuss.elastic.co/t/watcher-using-metadata-array-in-input-terms/271273/3 "2021-05-03T14:47:45Z")

</div>

The [ids query](https://www.elastic.co/guide/en/elasticsearch/reference/7.12/query-dsl-ids-query.html) requires you to create an array, which is not possible using mustache templating.

How about using another query like this:

```auto
GET test/_search
{
  "query": {
    "query_string": {
      "default_field": "_id",
      "query": "1 OR 2 OR 3"
    }
  }
}

```

this way, you could use the [join function](https://www.elastic.co/guide/en/elasticsearch/reference/7.12/search-template.html#search-template-concatenate-array)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2021, 2:48pm UTC](https://discuss.elastic.co/t/watcher-using-metadata-array-in-input-terms/271273/4 "2021-05-31T14:48:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
