# Cloud elastic Alerting not working as expected

**URL:** <https://discuss.elastic.co/t/cloud-elastic-alerting-not-working-as-expected/148111>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [September 11, 2018, 11:09am UTC](https://discuss.elastic.co/t/cloud-elastic-alerting-not-working-as-expected/148111 "2018-09-11T11:09:44Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hitesh\_Baldaniya](https://avatars.discourse-cdn.com/v4/letter/h/439d5e/32.png) [@Hitesh\_Baldaniya](https://discuss.elastic.co/u/Hitesh_Baldaniya)\
**Post date:** [September 11, 2018, 11:09am UTC](https://discuss.elastic.co/t/cloud-elastic-alerting-not-working-as-expected/148111/1 "2018-09-11T11:09:44Z")

</div>

Hi Team,

We have setup watcher on our monitoring elasticsearch server. We are monitoring on ".monitoring-es-\*" indices with following mentioned watcher definition, but it always getting triggered so I believe compare stage is not working properly.

```
"trigger": {
"schedule": {
  "interval": "10s"
}
},
"input": {
"search": {
  "request": {
    "search_type": "query_then_fetch",
    "indices": [
      ".monitoring-es*"
    ],
    "types": ["doc"],
    "body": {
      "query": {
        "match": {
          "type": "cluster_stats"
        }
      },
      "sort": [
        {
          "timestamp": {
            "order": "desc"
          }
        }
      ],
      "_source": [
        "cluster_stats"
      ],
      "size": 1
    }
  }
}
},
"condition": {
"compare": {
  "ctx.payload.hits.hits.0._source.cluster_stats.indices.store.size_in_bytes": {
    "gt": 1000000000
  }
}
},
"actions": {
"send_email": {
  "email": {
    "profile": "standard",
    "to": [
      "XXXXXXXXX"
    ],
    "subject": "[Disk Usage Watcher]Elastic cloud Watcher Notification",
    "body": {
      "text": "You Elastic cloud cluster disk usage is more than 10GB 
 {{ctx.payload.hits.hits.0._source.cluster_stats.indices.store.size_in_bytes}}"
    }
   }
  }
},
"throttle_period_in_millis": 2160000
```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 11, 2018, 11:55am UTC](https://discuss.elastic.co/t/cloud-elastic-alerting-not-working-as-expected/148111/2 "2018-09-11T11:55:14Z")

</div>

can you share the output of the execute watch API in a gist, please?

---

<div class="post-metadata">

**Author:** ![Hitesh\_Baldaniya](https://avatars.discourse-cdn.com/v4/letter/h/439d5e/32.png) [@Hitesh\_Baldaniya](https://discuss.elastic.co/u/Hitesh_Baldaniya)\
**Post date:** [September 11, 2018, 12:04pm UTC](https://discuss.elastic.co/t/cloud-elastic-alerting-not-working-as-expected/148111/3 "2018-09-11T12:04:27Z")

</div>

Hi Alexander,

I tried simulate but at that time I see `"status":"success"` and `"met": false`due to which action email is not getting triggered.

> <https://gist.github.com/hiteshbal91/4093d3c734a5b5cc676c03e59fc765c1>

But once I set it got trigger it sends email even if the condition of 10GB is not satisfied.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 11, 2018, 12:06pm UTC](https://discuss.elastic.co/t/cloud-elastic-alerting-not-working-as-expected/148111/4 "2018-09-11T12:06:47Z")

</div>

can you also paste one of the entries from the watcher history index for this watch, then we can check if the condition was triggered or not.

---

<div class="post-metadata">

**Author:** ![Hitesh\_Baldaniya](https://avatars.discourse-cdn.com/v4/letter/h/439d5e/32.png) [@Hitesh\_Baldaniya](https://discuss.elastic.co/u/Hitesh_Baldaniya)\
**Post date:** [September 11, 2018, 12:29pm UTC](https://discuss.elastic.co/t/cloud-elastic-alerting-not-working-as-expected/148111/5 "2018-09-11T12:29:28Z")

</div>

I am seeing conditions where not met and triggering was not done for few. I am checking one of my other cluster where actually I am getting false trigger emails.

I will be able to share in sometime.

But mean while I also checked that I could not actually query fields which are added in compare section of watchers. Is there are specific reasons for them?

---

<div class="post-metadata">

**Author:** ![Hitesh\_Baldaniya](https://avatars.discourse-cdn.com/v4/letter/h/439d5e/32.png) [@Hitesh\_Baldaniya](https://discuss.elastic.co/u/Hitesh_Baldaniya)\
**Post date:** [September 11, 2018, 1:43pm UTC](https://discuss.elastic.co/t/cloud-elastic-alerting-not-working-as-expected/148111/6 "2018-09-11T13:43:59Z")

</div>

Hi,

Here is the link for the event where we are getting false trigger.

> <https://gist.github.com/hiteshbal91/97dc7188bcf343869e03d5ca748f6d7e>

One thing which I noted is that condition which matches is in string while we have created watcher with integer value.

---

<div class="post-metadata">

**Author:** ![Hitesh\_Baldaniya](https://avatars.discourse-cdn.com/v4/letter/h/439d5e/32.png) [@Hitesh\_Baldaniya](https://discuss.elastic.co/u/Hitesh_Baldaniya)\
**Post date:** [September 12, 2018, 4:57am UTC](https://discuss.elastic.co/t/cloud-elastic-alerting-not-working-as-expected/148111/7 "2018-09-12T04:57:29Z")

</div>

Hi Alexander,

Let me know your inputs for above issue.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 14, 2018, 2:15pm UTC](https://discuss.elastic.co/t/cloud-elastic-alerting-not-working-as-expected/148111/8 "2018-09-14T14:15:46Z")

</div>

Hey,

can you replace your condition with

```auto
    "condition": {
      "script": {
        "source": "return ctx.payload.foo > 150000000000L"
      }
    },

```

and report back if that works? You might have hit a bug in the compare condition.

--Alex

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 14, 2018, 2:19pm UTC](https://discuss.elastic.co/t/cloud-elastic-alerting-not-working-as-expected/148111/9 "2018-09-14T14:19:45Z")

</div>

I think your last example fails because you put the number into ticks, making it a string and thus doing a string based comparison, not a number based one

```auto
"gt": "150000000000"

```

---

<div class="post-metadata">

**Author:** ![Hitesh\_Baldaniya](https://avatars.discourse-cdn.com/v4/letter/h/439d5e/32.png) [@Hitesh\_Baldaniya](https://discuss.elastic.co/u/Hitesh_Baldaniya)\
**Post date:** [September 17, 2018, 4:31am UTC](https://discuss.elastic.co/t/cloud-elastic-alerting-not-working-as-expected/148111/10 "2018-09-17T04:31:21Z")

</div>

> [@spinscale](#):
>
> "source": "return ctx.payload.foo \> 150000000000L"

Thanks Alexander for your inputs issue has been resolved after removing quotes.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 1, 2018, 4:31am UTC](https://discuss.elastic.co/t/cloud-elastic-alerting-not-working-as-expected/148111/11 "2018-10-01T04:31:33Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
