Alert rule with relative threshold

Watcher is a paid feature, I dont have a license, so dont know.

Alerts seems not include a generic "query and aggregate like this, look at that field in the response" support, that I can see. Happy to be corrected.

So one idea would be to use a transform, and stick the value of percent_inc in another index that you can then monitor.

However, I believe there are easier ways to achieve the same thing. This approach seems overly complex even to me. I hope someone else makes a better suggestion.