# Webhook not sending json format

**URL:** <https://discuss.elastic.co/t/webhook-not-sending-json-format/54580>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [July 2, 2016, 3:49pm UTC](https://discuss.elastic.co/t/webhook-not-sending-json-format/54580 "2016-07-02T15:49:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![elasticbharat](https://avatars.discourse-cdn.com/v4/letter/e/ba8739/32.png) [@elasticbharat](https://discuss.elastic.co/u/elasticbharat)\
**Post date:** [July 2, 2016, 3:49pm UTC](https://discuss.elastic.co/t/webhook-not-sending-json-format/54580/1 "2016-07-02T15:49:14Z")

</div>

Hi,

I want to send watcher data in json format. Here is my json string of watcher query

```auto
{
          "trigger" : { "schedule" : { "interval" : "10s" } }, 
          "input" : { 
            "search" : {
              "request" : {
                "indices" : ["k8s*"],
                "body" : {
                    "query": {
                       "match":{"reason" : "FailedSync"}
                    }
                }
              }
            }
          },
          "condition" : {
            "compare" : { "ctx.payload.hits.total" : { "gt" : 0 }}
          },
        "actions" : {
          "my_webhook" : {
            "webhook" : {
              "method" : "PUT",
              "host" : "tcmonitor",
              "port" : 5080,
              "headers" : {
                  "Content-Type": "application/json"
              },
              "path": "/rules/results", 
              "body" : "{\"results\":\"{{ctx.payload.hits.hits.1}}\"}"
            }
          }
        }
    }

```

I get the webhook request to python flask framework at /rules/results. Python flask thrwoing error saying the string not in json format.

I used tcpdump to capture packet in ASCII format. I see the packet does not have quote around it. Here is the packet capture. As you can see below there is no quote around \_type, Pod...

```auto
{"results":{ {_type=Pod, _source={message=Error syncing pod, skipp
ing: [failed to "StartContainer" for "openrg" with ImagePullBackOff: "Back-off p
ulling image \"engci-docker.cisco.com:5933/vcpe-openrg:5\""
, failed to "StartContainer" for "sidecar" with ImagePullBackOff: "Back-off pull
ing image \"engci-docker.cisco.com:5933/tccp-hyperagent\""
], reason=FailedSync, severity=Warning, impacted_object={id=d3c154ca-3f63-11e6-9
7db-fa163eeb6065, name=ed405aa43dd5441c9787b97-cpe-zzpot, type=Pod}}, _id=AVWrzU
g_hu_4kJYUMyFr, _index=k8s, _score=2.3613377} }}?

```

```auto
{
    "message": "Failed to decode JSON object: Expecting property name enclosed i
n double quotes: line 1 column 14 (char 13)"
}

```

But when I look in watch records, I see quote inside elastic search watch records

```auto
{
                  "_type" : "Pod",
                  "_source" : {
                    "message" : "Error syncing pod, skipping: [failed to \"StartContainer\" for \"openrg\" with ImagePullBackOff: \"Back-off pulling image \\\"engci-docker.cisco.com:5933/vcpe-openrg:5\\\"\"\n, failed to \"StartContainer\" for \"sidecar\" with ImagePullBackOff: \"Back-off pulling image \\\"engci-docker.cisco.com:5933/tccp-hyperagent\\\"\"\n]",
                    "reason" : "FailedSync",
                    "severity" : "Warning",
                    "impacted_object" : {
                      "id" : "d3c154ca-3f63-11e6-97db-fa163eeb6065",
                      "name" : "ed405aa43dd5441c9787b97-cpe-zzpot",
                      "type" : "Pod"
                    }

```

How to get data in json format in webhook?

Thanks  
Bharat

---

<div class="post-metadata">

**Author:** ![elasticbharat](https://avatars.discourse-cdn.com/v4/letter/e/ba8739/32.png) [@elasticbharat](https://discuss.elastic.co/u/elasticbharat)\
**Post date:** [July 3, 2016, 4:29pm UTC](https://discuss.elastic.co/t/webhook-not-sending-json-format/54580/2 "2016-07-03T16:29:03Z")

</div>

Can anybody share your thoughts/exeperience? Can I open bug for this?

Thanks  
Bharat

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [July 4, 2016, 7:17am UTC](https://discuss.elastic.co/t/webhook-not-sending-json-format/54580/3 "2016-07-04T07:17:37Z")

</div>

Hey,

You can use the [Execute Watch API](https://www.elastic.co/guide/en/watcher/current/api-rest.html#api-rest-execute-watch) to check, what the request body looks like. In the `actions` part at the end of the output, you will find the `body`, which should show what is sent to the server.

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:44pm UTC](https://discuss.elastic.co/t/webhook-not-sending-json-format/54580/4 "2017-07-06T13:44:36Z")

</div>


