# X-pack Watcher email alert with full information stripped from JSON file

**URL:** <https://discuss.elastic.co/t/x-pack-watcher-email-alert-with-full-information-stripped-from-json-file/119667>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [February 13, 2018, 3:31pm UTC](https://discuss.elastic.co/t/x-pack-watcher-email-alert-with-full-information-stripped-from-json-file/119667 "2018-02-13T15:31:14Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jay.Dhillon](https://avatars.discourse-cdn.com/v4/letter/j/c67d28/32.png) [@Jay.Dhillon](https://discuss.elastic.co/u/Jay.Dhillon)\
**Post date:** [February 13, 2018, 3:31pm UTC](https://discuss.elastic.co/t/x-pack-watcher-email-alert-with-full-information-stripped-from-json-file/119667/1 "2018-02-13T15:31:14Z")

</div>

How can define Watcher watches script to detect a keyword from JSON files? and How to include more information from JSON file(From Azure EventHUB)? Currently using below Advanced JSON watch but seems like not working.

{  
"trigger": {  
"schedule": {  
"interval": "1m"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"eventhub"  
],  
"types": [],  
"body": {  
"query": {  
"bool": {  
"must": [  
{  
"query\_string": {  
"query": "Microsoft.Authorization/roleAssignments"  
}  
},  
{  
"range": {  
"@timestamp": {  
"gte": "now-1m"  
}  
}  
}  
]  
}  
},  
"\_source": [  
"message"  
],  
"sort": [  
{  
"@timestamp": {  
"order": "desc"  
}  
}  
]  
}  
}  
}  
},  
"condition": {  
"compare": {  
"ctx.payload.hits.total": {  
"gt": 0  
}  
}  
},  
"actions": {  
"email\_me": {  
"throttle\_period\_in\_millis": 600000,  
"email": {  
"profile": "standard",  
"to": [  
""  
],  
"subject": "ELK Watcher: AzureRoleAssignmentsChangesDetected",  
"body": {  
"html": "Watcher detected {{ctx.payload.hits.total}} AzureRoleAssignmentsChanges"  
}  
}  
}  
},  
"throttle\_period\_in\_millis": 900000  
}

---

<div class="post-metadata">

**Author:** ![Jay.Dhillon](https://avatars.discourse-cdn.com/v4/letter/j/c67d28/32.png) [@Jay.Dhillon](https://discuss.elastic.co/u/Jay.Dhillon)\
**Post date:** [February 14, 2018, 12:15am UTC](https://discuss.elastic.co/t/x-pack-watcher-email-alert-with-full-information-stripped-from-json-file/119667/2 "2018-02-14T00:15:41Z")

</div>

I was able to attach JSON file with the each trap but it's including full list of traps/log received by elastic. Is there a filter only to include only log of current time?

"LogEncounter": {  
"data": {  
"format": "json"  
}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 14, 2018, 7:25am UTC](https://discuss.elastic.co/t/x-pack-watcher-email-alert-with-full-information-stripped-from-json-file/119667/3 "2018-02-14T07:25:35Z")

</div>

Hey,

first, it would be great, if you could properly format code/watcher snippets. As this forum supports github markdown, it should be pretty easy and makes reading watches inifnitely simpler.

Second, you could use the [extract directive from the search input](https://www.elastic.co/guide/en/x-pack/6.2/input-search.html#_extracting_specific_fields) to reduce the size of your payload. Alternatively you could use a transform in your action.

--Alex

---

<div class="post-metadata">

**Author:** ![Jay.Dhillon](https://avatars.discourse-cdn.com/v4/letter/j/c67d28/32.png) [@Jay.Dhillon](https://discuss.elastic.co/u/Jay.Dhillon)\
**Post date:** [February 16, 2018, 3:27pm UTC](https://discuss.elastic.co/t/x-pack-watcher-email-alert-with-full-information-stripped-from-json-file/119667/4 "2018-02-16T15:27:53Z")

</div>

It seems like it's not working still? Is this correct format? search seems like not valid parameter for action.

"actions": {  
"email\_me": {  
"throttle\_period\_in\_millis": 600000,  
"email": {  
"profile": "standard",  
"priority": "high",  
"to": [  
"email"  
],  
"subject": "Detected {{ctx.payload.hits.total}} Azure Role Assignments Changes",  
"body": {  
"text": "Check Attached for more details"  
},  
"attachments": {  
"pdf.pdf": {  
"reporting": {  
"url": "\*\*\*\*",  
"retries":6,  
"interval":"1s",  
"auth": {  
"basic": {  
"username": "elastic",  
"password": ""  
}  
}  
}  
},  
"Raw Data": {  
"data": {  
"format": "json"  
}  
}  
}  
}  
},  
"transform": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"_eventhub_"  
],  
"types": [],  
"body": {  
"query": {  
"match": {  
"field": "_string_"  
},  
"range": {  
"@timestamp": {  
"gte": "now-2m"  
}  
}  
}  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![Jay.Dhillon](https://avatars.discourse-cdn.com/v4/letter/j/c67d28/32.png) [@Jay.Dhillon](https://discuss.elastic.co/u/Jay.Dhillon)\
**Post date:** [February 16, 2018, 3:37pm UTC](https://discuss.elastic.co/t/x-pack-watcher-email-alert-with-full-information-stripped-from-json-file/119667/5 "2018-02-16T15:37:10Z")

</div>

I have specified range inside input but data field inside action still doesn't attach matched events Raw Data. Need to attach JSON(RAW) file with every event trapped.

"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"_eventhub_"  
],  
"types": [],  
"body": {  
"size": 0,  
"query": {  
"bool": {  
"must": [  
{  
"match": {  
"field": "string"  
}  
},  
{  
"range": {  
"@timestamp": {  
"gte": "now-2m"  
}  
}  
}  
]  
}  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 19, 2018, 8:17am UTC](https://discuss.elastic.co/t/x-pack-watcher-email-alert-with-full-information-stripped-from-json-file/119667/6 "2018-02-19T08:17:20Z")

</div>

if you use a transform, you might want to use a `script` transform and decide manually which data to keep and which to remove. A `search` transform just uses the search result as new input, so I dont think you will gain anything from that.

I have not looked any closer at the snippets, because they are nearly impossible to read without formatting...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 19, 2018, 8:17am UTC](https://discuss.elastic.co/t/x-pack-watcher-email-alert-with-full-information-stripped-from-json-file/119667/7 "2018-03-19T08:17:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
