# Cannot Run Scripted\_mertic in elastic watcher input part

**URL:** <https://discuss.elastic.co/t/cannot-run-scripted-mertic-in-elastic-watcher-input-part/335834>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [June 13, 2023, 8:08am UTC](https://discuss.elastic.co/t/cannot-run-scripted-mertic-in-elastic-watcher-input-part/335834 "2023-06-13T08:08:57Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![JasonREC](https://avatars.discourse-cdn.com/v4/letter/j/858c86/32.png) [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Post date:** [June 13, 2023, 8:08am UTC](https://discuss.elastic.co/t/cannot-run-scripted-mertic-in-elastic-watcher-input-part/335834/1 "2023-06-13T08:08:57Z")

</div>

Hi, I am trying to set up a watcher and iterate throught my index. I have a search query which return buckets(region) inside another buckets(pa\_key). The inside bucket (region) has a value called ac\_count and av\_count. And I want to see if they are over 50, if either value is over 50, I am going to store that related pa\_key, region and ac\_count and av\_count into the state list, and eventually send this list via email to me

The is the pure query response without adding scripted metric:

 ![query_response](https://us1.discourse-cdn.com/elastic/original/3X/8/2/82463c4453bde0b914c72d90fd88fc8d60fa027d.png)

This is the query script after adding scripted metric:

 ![script_mertics](https://us1.discourse-cdn.com/elastic/original/3X/5/5/5563c1ad4e179c759c5c86a8e44ffc1aac1b0c54.png)

this is the response from mock watcher, and it return failed message

 ![watcher_response](https://us1.discourse-cdn.com/elastic/original/3X/9/e/9ea376d58911782764bbdad53b4111926daef46b.png)

Could anyone help me out?

Thank you

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [June 14, 2023, 4:37pm UTC](https://discuss.elastic.co/t/cannot-run-scripted-mertic-in-elastic-watcher-input-part/335834/2 "2023-06-14T16:37:47Z")

</div>

I would either:

a) Use a `bucket_selector` aggregation ([link](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-pipeline-bucket-selector-aggregation.html)) to only return the buckets that meet your threshold.

b) Set the threshold in the `condition` section, like [this watch](https://gist.github.com/richcollier/eeb6d6f98599ac77fea69a684debe647)

---

<div class="post-metadata">

**Author:** ![JasonREC](https://avatars.discourse-cdn.com/v4/letter/j/858c86/32.png) [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Post date:** [June 15, 2023, 8:55am UTC](https://discuss.elastic.co/t/cannot-run-scripted-mertic-in-elastic-watcher-input-part/335834/4 "2023-06-15T08:55:04Z")

</div>

Hi, @richcollier

Both way are very helpful and easy to understand. I went for the (b) approach and and it does satisfy my need. In that example, it shows to use log action to do a final script transform( use if condition to filter out the bucket I don't need) before return the result to the user. I wonder if I can even further send that result via email to myself. it would be like trigger 2 action in order. First, log action -\> Second email action.

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [June 15, 2023, 3:19pm UTC](https://discuss.elastic.co/t/cannot-run-scripted-mertic-in-elastic-watcher-input-part/335834/5 "2023-06-15T15:19:24Z")

</div>

In the examples that I usually publish, I always pick the log action because I'm not doing the examples to show the notification capabilities of Watcher, but rather am focusing on the query, aggregation, and formatting of the results via the `transform` block.

So, feel free to replace the logging action with an email one. An email action can have its own [action-level `transform`](https://www.elastic.co/guide/en/elasticsearch/reference/current/transform.html) block for formatting the data

---

<div class="post-metadata">

**Author:** ![JasonREC](https://avatars.discourse-cdn.com/v4/letter/j/858c86/32.png) [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Post date:** [June 16, 2023, 2:32am UTC](https://discuss.elastic.co/t/cannot-run-scripted-mertic-in-elastic-watcher-input-part/335834/6 "2023-06-16T02:32:39Z")

</div>

Hi @richcollier ,

Thanks for helping! now everything works as expected !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 14, 2023, 2:33am UTC](https://discuss.elastic.co/t/cannot-run-scripted-mertic-in-elastic-watcher-input-part/335834/7 "2023-07-14T02:33:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
