# Any way of specifying a tag within a watch?

**URL:** <https://discuss.elastic.co/t/any-way-of-specifying-a-tag-within-a-watch/182101>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [May 21, 2019, 11:31pm UTC](https://discuss.elastic.co/t/any-way-of-specifying-a-tag-within-a-watch/182101 "2019-05-21T23:31:50Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![drivera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/drivera/32/39900_2.png) [@drivera](https://discuss.elastic.co/u/drivera)\
**Post date:** [May 21, 2019, 11:31pm UTC](https://discuss.elastic.co/t/any-way-of-specifying-a-tag-within-a-watch/182101/1 "2019-05-21T23:31:50Z")

</div>

ES 5.6 with x-pack  
I'm trying to extract a field that matches a specific tag in my watch. My watch looks like this:

```
PUT _xpack/watcher/watch/error_logs
{
  "trigger" : {
    "schedule" : { "interval" : "20s" } 
  },
  "input" : {
    "search" : {
      "request" : {
        "indices" : ["<logstash-{now/d}>"],
        "body" : {
          "query" : {
            "match" : { "error_message": "Not able to find userId" }
          }
        }
      }
    }
  },
  "condition" : {
    "compare" : { "ctx.payload.hits.total" : { "gt" : 0 }} 
  },
  "actions" : {
    "send_email" : {
      "email" : {
        "to" : "email@email.com",
        "subject" : "Encountered {{ctx.payload.hits.total}} Errors",
        "body" : "Too many errors found",
        "attachments" : {
          "attached_data" : {
            "data" : {
              "format" : "json"
            }
          }
        }
 
     }
   }
  }
}

```

The output of my watch looks like this:

```
"ctx" : {
    "metadata" : null,
    "watch_id" : "error_logs",
    "payload" : {
      "_shards" : {
        "total" : 5,
        "failed" : 0,
        "successful" : 5,
        "skipped" : 0
      },
      "hits" : {
        "hits" : [
          {
            "_index" : "logstash-2019.05.21",
            "_type" : "linux-logs",
            "_source" : {
              "severity" : "*WARN*",
              "error_message" : "Not able to find user for userId",
              "offset" : 68548,
              "method" : "GET",
              "ip" : "10.x.x.x",
              "prospector" : {
                "type" : "log"
              },
              "source" : "/var/log/aem/error.log",
              "message" : "21.05.2019 00:00:28.126 *WARN* [10.43.32.119 [1558396828123] GET /content/regent.html HTTP/1.1] com.adobe.fd.core.security.internal.CurrentUserServiceImpl Not able to find user for userId [anonymous]",
              "type" : "linux-logs",
              "version" : "HTTP/1.1",
              "tags" : [
                "aemlogs",
                "aemlogs",
                "fglam",
                "beats_input_codec_plain_applied",
                "_grokparsefailure",
                "_fglamparsefailure"
              ],
              "input" : {
                "type" : "log"
              },
              "@timestamp" : "2019-05-21T00:00:29.984Z",

```

Any ideas? Thanks.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [May 22, 2019, 8:05am UTC](https://discuss.elastic.co/t/any-way-of-specifying-a-tag-within-a-watch/182101/2 "2019-05-22T08:05:19Z")

</div>

Can you be more specific with your question? What field are you exactly trying to extract? If you want to access the field of the search first hit, you would go with something like `ctx.payload.hits.hits.0._source.MY_FIELD`

hope that helps.

--Alex

---

<div class="post-metadata">

**Author:** ![drivera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/drivera/32/39900_2.png) [@drivera](https://discuss.elastic.co/u/drivera)\
**Post date:** [May 22, 2019, 5:21pm UTC](https://discuss.elastic.co/t/any-way-of-specifying-a-tag-within-a-watch/182101/3 "2019-05-22T17:21:09Z")

</div>

I'm trying to limit my search to events that have the tag "aemlogs". In many cases I have the same error\_message from multiple pipelines but I only need those tagged as "aemlogs". Thanks

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [May 23, 2019, 1:02pm UTC](https://discuss.elastic.co/t/any-way-of-specifying-a-tag-within-a-watch/182101/4 "2019-05-23T13:02:30Z")

</div>

this means you need to use a `bool` query with two `must` clauses. One the match query from above and one a match query for the tags (there are other ways to solve this, but I think this is the easiest one).

See [https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-bool-query.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-bool-query.html)

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 20, 2019, 1:02pm UTC](https://discuss.elastic.co/t/any-way-of-specifying-a-tag-within-a-watch/182101/5 "2019-06-20T13:02:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
