# X-Pack Watcher Webhook malformed json with backslashes

**URL:** <https://discuss.elastic.co/t/x-pack-watcher-webhook-malformed-json-with-backslashes/107194>\
**Category:** Elasticsearch\
**Created:** [November 10, 2017, 1:53pm UTC](https://discuss.elastic.co/t/x-pack-watcher-webhook-malformed-json-with-backslashes/107194 "2017-11-10T13:53:29Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![lctrcl](https://avatars.discourse-cdn.com/v4/letter/l/97f17d/32.png) [@lctrcl](https://discuss.elastic.co/u/lctrcl)\
**Post date:** [November 10, 2017, 1:53pm UTC](https://discuss.elastic.co/t/x-pack-watcher-webhook-malformed-json-with-backslashes/107194/1 "2017-11-10T13:53:29Z")

</div>

legend:

As part of payload, I'm grabbing one field, which contains backslashes  
"C:\Windows\System32\wbem\WmiPrvSE.exe"

But when I'm trying to send it to webhook in json, it doesn't escape it properly, so in the end I'm getting malformed json.

I'm trying to use painless transform to "doubleescape" these backslashes, but can't figure out the right usage.

action script:

```auto
   "actions": {
    "logstash_hook": {
      "webhook": {
        "scheme": "http",
        "host": "x.x.x.x",
        "port": 9000,
        "method": "post",
        "path": "/api/alert",
        "params": {},
        "headers": {
          "Authorization": "Bearer xxxxxx"
        },
        "body": {
          "source": {
            "title": "{{ctx.metadata.name}}",
            "description": "xxxxxxx",
            "type": "external",
            "severity": 3,
            "tlp": 3,
            "artifacts": [
              {
                "dataType": "fqdn",
                "data": "{{ctx.payload.hostname}}",
                "tags": [
                  "hostname"
                ]
              },
              {
                "dataType": "other",
                "data": "{{ctx.payload.user}}",
                "tags": [
                  "src-user"
                ]
              },
              {
                "dataType": "other",
                "data": "{{ctx.payload.process_name}}",
                "tags": [
                  "process_name"
                ]
              }
            ],
            "source": "xpack",
            "sourceRef": "{{ctx.payload.alertid}}"
          },
          "lang": "mustache",
          "options": {
            "content_type": "application/json; charset=UTF-8"
          }
        }
      }
    }
  },

```

results:

```auto
{
... 

    "transform": {
      "type": "script",
      "status": "success",
      "payload": {
        "hostname": "windows-2012-r2.demo.local",
        "@timestamp": "2017-11-10T12:17:47.500Z",
        "process_name": "C:\\Windows\\System32\\wbem\\WmiPrvSE.exe",
        "alertid": "AV-aEH8d9J44Pmhi7J2h",
        "user": "WINDOWS-2012-R2$"
      }
    },
      "actions": [
      {
        "id": "logstash_hook",
        "type": "webhook",
        "status": "simulated",
        "webhook": {
          "request": {
            "host": "x.x.x.x",
            "port": 9000,
            "scheme": "http",
            "method": "post",
            "path": "/api/alert",
            "headers": {
              "Authorization": "Bearer xxxxxxxxx",
              "Content-Type": "application/json; charset=UTF-8"
            },
            "body": "{\"title\":\"\",\"description\":\"xxxxxxxxx\",\"type\":\"external\",\"severity\":3,\"tlp\":3,\"artifacts\":[{\"dataType\":\"fqdn\",\"data\":\"windows-2012-r2.demo.local\",\"tags\":[\"hostname\"]},{\"dataType\":\"other\",\"data\":\"WINDOWS-2012-R2$\",\"tags\":[\"src-user\"]},{\"dataType\":\"other\",\"data\":\"C:\\Windows\\System32\\wbem\\WmiPrvSE.exe\",\"tags\":[\"process_name\"]}],\"source\":\"xpack\",\"sourceRef\":\"AV-aEH8d9J44Pmhi7J2h\"}"
          }
        }
...

```

transform script:

```auto
  "transform": {
    "script": {
      "source": "String pname = /\\\\/.matcher(ctx.payload.hits.hits.0._source.ProcessName).replaceAll('\\\\\\\\'); return ['@timestamp':ctx.trigger.triggered_time,'process_name': pname, 'hostname': ctx.payload.hits.hits.0._source.Hostname, 'user': ctx.payload.hits.hits.0._source.user, 'alertid': ctx.payload.hits.hits.0._id]",
      "lang": "painless"
    }
  },

```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 13, 2017, 8:59am UTC](https://discuss.elastic.co/t/x-pack-watcher-webhook-malformed-json-with-backslashes/107194/2 "2017-11-13T08:59:01Z")

</div>

can you provide the full watch and even more important, the full output of running the [Execute Watch API](https://www.elastic.co/guide/en/elasticsearch/reference/5.6/watcher-api-execute-watch.html)

Thank you!

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 11, 2017, 8:59am UTC](https://discuss.elastic.co/t/x-pack-watcher-webhook-malformed-json-with-backslashes/107194/3 "2017-12-11T08:59:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
