# Compare condition for checking strings in watcher is not Working?

**URL:** <https://discuss.elastic.co/t/compare-condition-for-checking-strings-in-watcher-is-not-working/126882>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [April 5, 2018, 8:44am UTC](https://discuss.elastic.co/t/compare-condition-for-checking-strings-in-watcher-is-not-working/126882 "2018-04-05T08:44:16Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![naveen\_K.N](https://avatars.discourse-cdn.com/v4/letter/n/8e8cbc/32.png) [@naveen\_K.N](https://discuss.elastic.co/u/naveen_K.N)\
**Post date:** [April 5, 2018, 8:44am UTC](https://discuss.elastic.co/t/compare-condition-for-checking-strings-in-watcher-is-not-working/126882/1 "2018-04-05T08:44:16Z")

</div>

Hi Elastic Experts,

we have a compare condition as follows:

> "condition": {  
> "compare": {  
> "ctx.payload.hits.hits.0.\_source.syslog\_message": {  
> "gt": "lang.OutOfMemoryError:"  
> }  
> }  
> }

so here we want to check if syslog\_message contains " lang.outOfMemoryError" , but we are getting alerts even when there is no "lang.OutOfMemoryError" ?

any Help on this would be great help!!

thanks,  
Naveena K N

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 5, 2018, 9:22am UTC](https://discuss.elastic.co/t/compare-condition-for-checking-strings-in-watcher-is-not-working/126882/2 "2018-04-05T09:22:25Z")

</div>

The compare condition works only for numerics.

You need to use painless, like this

```auto
return ctx.payload.hits.hits.get(0)._source.syslog_message.contains('lang.OutOfMemoryError')

```

--Alex

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 5, 2018, 9:24am UTC](https://discuss.elastic.co/t/compare-condition-for-checking-strings-in-watcher-is-not-working/126882/3 "2018-04-05T09:24:28Z")

</div>

to clarify: strictly speaking, you can also use the condition for string comparison, but I think this is not what you are after, is it uses the java comparator logic

---

<div class="post-metadata">

**Author:** ![naveen\_K.N](https://avatars.discourse-cdn.com/v4/letter/n/8e8cbc/32.png) [@naveen\_K.N](https://discuss.elastic.co/u/naveen_K.N)\
**Post date:** [April 5, 2018, 11:30am UTC](https://discuss.elastic.co/t/compare-condition-for-checking-strings-in-watcher-is-not-working/126882/4 "2018-04-05T11:30:42Z")

</div>

> [@spinscale](#):
>
> return ctx.payload.hits.hits.get(0).\_source.syslog\_message.contains('lang.OutOfMemoryError')

so we can use above statement for our usecase,  
syslog\_message.contains(' some text') will work right??

Thanks  
Naveena K N

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 5, 2018, 11:54am UTC](https://discuss.elastic.co/t/compare-condition-for-checking-strings-in-watcher-is-not-working/126882/5 "2018-04-05T11:54:07Z")

</div>

I suppose. you have not exactly mentioned what you are expecting to check with your condition, but the above examples checks if the first hit contains the specified string.

I am not sure if checking only the first hit is enough, and I am also not sure, why you dont write a query that checks for the syslog message including out of memory error, so there may be ways to improve this query, if you share it.

---

<div class="post-metadata">

**Author:** ![naveen\_K.N](https://avatars.discourse-cdn.com/v4/letter/n/8e8cbc/32.png) [@naveen\_K.N](https://discuss.elastic.co/u/naveen_K.N)\
**Post date:** [April 6, 2018, 3:50am UTC](https://discuss.elastic.co/t/compare-condition-for-checking-strings-in-watcher-is-not-working/126882/6 "2018-04-06T03:50:44Z")

</div>

Hi @spinscale,

here is the watcher code to check Out of Memory Error in Server Logs running every 10seconds to check last 2 minute data:

```
{
  "trigger": {
    "schedule": {
      "interval": "10s"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "qa-mon-server-logs*"
        ],
        "types": [
          "doc"
        ],
        "body": {
          "query": {
            "range": {
              "logTimestamp": {
                "gte": "now-2m",
                "lt": "now"
              }
            }
          },
          "sort": [
            {
              "logTimestamp": {
                "order": "desc"
              }
            }
          ]
        }
      }
    }
  },
  "condition": {
    "script": {
      "source": "return ctx.payload.hits.hits.0._source.syslog_message.contains('OutOfMemoryError')",
      "lang": "painless"
    }
  },
  "actions": {
    "send_email": {
      "throttle_period_in_millis": 120000,
      "email": {
        "profile": "standard",
        "to": [
          "abc@gmail.com"
        ],
        "subject": "QA-mon-OutOfMemoryError",
        "body": {
          "text": "server path: {{ctx.payload.hits.hits.0._source.path}} Error message: {{ctx.payload.hits.hits.0._source.syslog_message}} "
        }
      }
    }
  }
}

```

we would to like to hear any suggestions on improving this query!!

Thanks,  
Naveena K N

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 6, 2018, 7:20am UTC](https://discuss.elastic.co/t/compare-condition-for-checking-strings-in-watcher-is-not-working/126882/7 "2018-04-06T07:20:33Z")

</div>

Thanks for sharing the watch.

This can potentially miss hits. You are sorting by time, so the latest document is the first, and you are only checking the first document. If the second newest document contains that error, this will not be found.

You need to put the search for your `OutOfMemoryError` into the query (maybe using a `match`) query, and then it should be sufficient to check for the hit count in the condition.

---

<div class="post-metadata">

**Author:** ![naveen\_K.N](https://avatars.discourse-cdn.com/v4/letter/n/8e8cbc/32.png) [@naveen\_K.N](https://discuss.elastic.co/u/naveen_K.N)\
**Post date:** [April 9, 2018, 3:58am UTC](https://discuss.elastic.co/t/compare-condition-for-checking-strings-in-watcher-is-not-working/126882/8 "2018-04-09T03:58:05Z")

</div>

Hi @spinscale,

can i Have something like below for checking all hits got in the context to check for "OutOfMemoryError"??

> [@naveen\_K.N](#):
>
> return ctx.payload.hits.hits.\*.\_source.syslog\_message.contains('OutOfMemoryError')

Thanks  
Naveena

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 9, 2018, 6:54am UTC](https://discuss.elastic.co/t/compare-condition-for-checking-strings-in-watcher-is-not-working/126882/9 "2018-04-09T06:54:30Z")

</div>

yes, you could, but again, you can solve this with a query, so why don't you go with that approach? It is easier and **much** faster.

--Alex

---

<div class="post-metadata">

**Author:** ![naveen\_K.N](https://avatars.discourse-cdn.com/v4/letter/n/8e8cbc/32.png) [@naveen\_K.N](https://discuss.elastic.co/u/naveen_K.N)\
**Post date:** [April 9, 2018, 7:30am UTC](https://discuss.elastic.co/t/compare-condition-for-checking-strings-in-watcher-is-not-working/126882/10 "2018-04-09T07:30:33Z")

</div>

Hi @spinscale

i have query to fetch field containing 'OutOfMemoryError' in data arrived last 150 minute so the query is

```
"body": {
          "query": {
            "query_string" : {
            "default_field" : "syslog_message",
            "query" : "*OutOfMemoryError"
        },
        "range": {
              "logTimestamp": {
                "gte": "now-150m",
                "lt": "now"
              }
            }
          },
          "sort": [
            {
              "logTimestamp": {
                "order": "desc"
              }
            }
          ]
        }

```

but im getting **parsing exception** due to **[query\_string] malformed query, expected [END\_OBJECT] but found [FIELD\_NAME]**

help me to modify this query to execute successfully!!

Thanks,  
Naveena

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 9, 2018, 7:48am UTC](https://discuss.elastic.co/t/compare-condition-for-checking-strings-in-watcher-is-not-working/126882/11 "2018-04-09T07:48:57Z")

</div>

you need to structure your queries differently. If you use a range and a query string query, you need to wrap it into a [bool query](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/query-dsl-bool-query.html), where the range query gets put into the `filter` clause and the query string query into the `must` clause.

Hope this helps!

--Alex

---

<div class="post-metadata">

**Author:** ![naveen\_K.N](https://avatars.discourse-cdn.com/v4/letter/n/8e8cbc/32.png) [@naveen\_K.N](https://discuss.elastic.co/u/naveen_K.N)\
**Post date:** [April 9, 2018, 8:06am UTC](https://discuss.elastic.co/t/compare-condition-for-checking-strings-in-watcher-is-not-working/126882/12 "2018-04-09T08:06:11Z")

</div>

i framed it like this:

```
GET prod-sl1a-server-logs*/_search
{
  "query": { 
    "bool": { 
      "must": [
        { "match": { "syslog_message": "java.lang.OutOfMemoryError" }}
      ],
      "filter": [
        { "range": { "logTimestamp": { "gte": "now-4d", "lt": "now"}}} 
      ]
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 7, 2018, 8:06am UTC](https://discuss.elastic.co/t/compare-condition-for-checking-strings-in-watcher-is-not-working/126882/13 "2018-05-07T08:06:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
