# Xpack watcher payload

**URL:** <https://discuss.elastic.co/t/xpack-watcher-payload/169496>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [February 21, 2019, 10:27pm UTC](https://discuss.elastic.co/t/xpack-watcher-payload/169496 "2019-02-21T22:27:07Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![andres-perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andres-perez/32/136461_2.png) [@andres-perez](https://discuss.elastic.co/u/andres-perez)\
**Post date:** [March 6, 2019, 6:55pm UTC](https://discuss.elastic.co/t/xpack-watcher-payload/169496/3 "2019-03-06T18:55:55Z")

</div>

> [@jodiaz](#):
>
> I now want to run a different regex on the data loaded in the payload instead of it running against my index.

What you are using, a `search transform`, is meant to run against the index.  
You will need to use a [script transform](https://www.elastic.co/guide/en/elastic-stack-overview/current/transform-script.html) instead and do some programing in painless script to process the payload with the additional regex.

If the regex is only used to check matches (so can evaluate to true or false) and fire an action, then a [script condition](https://www.elastic.co/guide/en/elastic-stack-overview/current/condition-script.html) with the painless script code could be set inside the action.

By the way, if this question is an additional explanation for your other topic [Xpack Watcher -- Credit card in logs](https://discuss.elastic.co/t/xpack-watcher-credit-card-in-logs/164374) , both of them should be merged to avoid having partial context spread in different threads for the same problem.

---

_[View the full topic](https://discuss.elastic.co/t/xpack-watcher-payload/169496)._
