# Xpack watcher payload

**URL:** <https://discuss.elastic.co/t/xpack-watcher-payload/169496>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [February 21, 2019, 10:27pm UTC](https://discuss.elastic.co/t/xpack-watcher-payload/169496 "2019-02-21T22:27:07Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jodiaz](https://avatars.discourse-cdn.com/v4/letter/j/eb8c5e/32.png) [@jodiaz](https://discuss.elastic.co/u/jodiaz)\
**Post date:** [February 21, 2019, 10:27pm UTC](https://discuss.elastic.co/t/xpack-watcher-payload/169496/1 "2019-02-21T22:27:07Z")

</div>

Hello,

I was hoping someone was familiar with some of the capabilities of watchers. I have a regex that queries my index and returns a big set of numbers. I now want to run a different regex on the data loaded in the payload instead of it running against my index. I believe this would be a transform however, I am not sure if I'm doing it right. Any help is appreciated.

"transform": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"types": ,  
"body": {  
"query": {  
"bool": {  
"must": [  
{  
"query\_string": {  
"query": "/4[0-9]{14,16}/"  
}  
}  
]  
}  
}  
}  
},

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [February 22, 2019, 11:54am UTC](https://discuss.elastic.co/t/xpack-watcher-payload/169496/2 "2019-02-22T11:54:47Z")

</div>

@spinscale Can you help here, please?

---

<div class="post-metadata">

**Author:** ![andres-perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andres-perez/32/136461_2.png) [@andres-perez](https://discuss.elastic.co/u/andres-perez)\
**Post date:** [March 6, 2019, 6:55pm UTC](https://discuss.elastic.co/t/xpack-watcher-payload/169496/3 "2019-03-06T18:55:55Z")

</div>

> [@jodiaz](#):
>
> I now want to run a different regex on the data loaded in the payload instead of it running against my index.

What you are using, a `search transform`, is meant to run against the index.  
You will need to use a [script transform](https://www.elastic.co/guide/en/elastic-stack-overview/current/transform-script.html) instead and do some programing in painless script to process the payload with the additional regex.

If the regex is only used to check matches (so can evaluate to true or false) and fire an action, then a [script condition](https://www.elastic.co/guide/en/elastic-stack-overview/current/condition-script.html) with the painless script code could be set inside the action.

By the way, if this question is an additional explanation for your other topic [Xpack Watcher -- Credit card in logs](https://discuss.elastic.co/t/xpack-watcher-credit-card-in-logs/164374) , both of them should be merged to avoid having partial context spread in different threads for the same problem.

---

<div class="post-metadata">

**Author:** ![jodiaz](https://avatars.discourse-cdn.com/v4/letter/j/eb8c5e/32.png) [@jodiaz](https://discuss.elastic.co/u/jodiaz)\
**Post date:** [March 7, 2019, 5:38pm UTC](https://discuss.elastic.co/t/xpack-watcher-payload/169496/4 "2019-03-07T17:38:59Z")

</div>

Thank you for the reply. Yes, this is all in regards to the same topic. Not sure how I would merge these. Kinda new to online communities.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 4, 2019, 5:39pm UTC](https://discuss.elastic.co/t/xpack-watcher-payload/169496/5 "2019-04-04T17:39:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
