# Watcher webhook action with bulk request

**URL:** <https://discuss.elastic.co/t/watcher-webhook-action-with-bulk-request/72333>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [January 20, 2017, 8:31pm UTC](https://discuss.elastic.co/t/watcher-webhook-action-with-bulk-request/72333 "2017-01-20T20:31:10Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![diopib](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/diopib/32/12334_2.png) [@diopib](https://discuss.elastic.co/u/diopib)\
**Post date:** [January 20, 2017, 8:31pm UTC](https://discuss.elastic.co/t/watcher-webhook-action-with-bulk-request/72333/1 "2017-01-20T20:31:10Z")

</div>

Hello there,

We would like to use watcher's webhook with a bulk request.  
For some reasons, we can't use the same data format indicated in the documentation [here](https://www.elastic.co/guide/en/elasticsearch/reference/2.4/docs-bulk.html) -- we get a 400 error.

Do you know if it's actually possible to call a bulk request from a webhook action or is there any alternative solution?

Thanks.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [January 23, 2017, 8:58am UTC](https://discuss.elastic.co/t/watcher-webhook-action-with-bulk-request/72333/2 "2017-01-23T08:58:36Z")

</div>

Hey,

the [index action](https://www.elastic.co/guide/en/x-pack/5.1/actions-index.html) has support for bulk requests. Would that suit your use-case? If not, please tell us, what is missing.

--Alex

---

<div class="post-metadata">

**Author:** ![diopib](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/diopib/32/12334_2.png) [@diopib](https://discuss.elastic.co/u/diopib)\
**Post date:** [January 23, 2017, 1:18pm UTC](https://discuss.elastic.co/t/watcher-webhook-action-with-bulk-request/72333/3 "2017-01-23T13:18:08Z")

</div>

Thanks for your reply,  
Yes, we indexed many documents at the time in other scenarios but this time  
we would like to partially update documents in bulk. I did not think this  
was possible with the index action. Is it?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [January 24, 2017, 8:07am UTC](https://discuss.elastic.co/t/watcher-webhook-action-with-bulk-request/72333/4 "2017-01-24T08:07:38Z")

</div>

Hey,

indeed, that `index` action does not support partial updates.

--Alex

---

<div class="post-metadata">

**Author:** ![diopib](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/diopib/32/12334_2.png) [@diopib](https://discuss.elastic.co/u/diopib)\
**Post date:** [January 24, 2017, 2:27pm UTC](https://discuss.elastic.co/t/watcher-webhook-action-with-bulk-request/72333/5 "2017-01-24T14:27:54Z")

</div>

Is there any other way from a watch perspective? Is it possible with a  
webhook ? My interrogation is particularly concerning the payload format  
expected in bulk requests...

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [January 25, 2017, 5:13pm UTC](https://discuss.elastic.co/t/watcher-webhook-action-with-bulk-request/72333/6 "2017-01-25T17:13:12Z")

</div>

Hey,

creating the bulk JSON payload in a script `transform` might be worth a try, however this also sounds somewhat tedious. You can maybe share what you already tried.

Alternatively have you thought about writing the data to logstash via a webhook and then use the logstash http input to read the data, process it via logstash and write it to ES?

--Alex

---

<div class="post-metadata">

**Author:** ![diopib](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/diopib/32/12334_2.png) [@diopib](https://discuss.elastic.co/u/diopib)\
**Post date:** [January 26, 2017, 7:41pm UTC](https://discuss.elastic.co/t/watcher-webhook-action-with-bulk-request/72333/7 "2017-01-26T19:41:48Z")

</div>

Thanks Alexander.  
I thought of the transform option but yeah it seemed quite tedious.  
I ended up doing something similar to the logstash idea. What I did is sending the data to a webserver, process the data and sending back the data to ES. This seemed like our best alternative.  
Thanks again  
-Ibrahim

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 23, 2017, 7:42pm UTC](https://discuss.elastic.co/t/watcher-webhook-action-with-bulk-request/72333/8 "2017-02-23T19:42:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
