# Elasticsearch Watcher Capabilities

**URL:** <https://discuss.elastic.co/t/elasticsearch-watcher-capabilities/329167>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [April 3, 2023, 7:12am UTC](https://discuss.elastic.co/t/elasticsearch-watcher-capabilities/329167 "2023-04-03T07:12:32Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![umityayla](https://avatars.discourse-cdn.com/v4/letter/u/13edae/32.png) [@umityayla](https://discuss.elastic.co/u/umityayla)\
**Post date:** [April 3, 2023, 7:12am UTC](https://discuss.elastic.co/t/elasticsearch-watcher-capabilities/329167/1 "2023-04-03T07:12:32Z")

</div>

Hello,

We plan to implement such a watcher that will regex a field in the documents that are found and pass it to the clients. What I mean is;

Let's assume there are 2 documents like below;

```auto
{
  "_type": "_doc",
  "_id": "VbnxRYcBbONNOA7tHnlq",
  "_version": 1,
  "_score": 1,
  "_ignored": [
    "Message.keyword"
  ],
  "_source": {
    "Message": "Result is: true, data is: qqq",
    "LogType": "Info",
    "LogDate": "2023-04-03T07:07:22.5906183Z"
  },
  "fields": {
    "Message": [
      "Result is: true, data is: qqq"
    ],
    "LogType": [
      "Info"
    ],
    "LogDate": [
      "2023-04-03T07:07:22.590Z"
    ]
  }
}

```

```auto
{
  "_type": "_doc",
  "_id": "VbnxRYcBbONNOA7tHnlq",
  "_version": 1,
  "_score": 1,
  "_ignored": [
    "Message.keyword"
  ],
  "_source": {
    "Message": "Result is: true, data is: qqq",
    "LogType": "Info",
    "LogDate": "2023-04-03T07:07:22.5906183Z"
  },
  "fields": {
    "Message": [
      "Result is: false, data is: qqq"
    ],
    "LogType": [
      "Info"
    ],
    "LogDate": [
      "2023-04-03T07:07:22.590Z"
    ]
  }
}

```

We want to use the result/data fields in the document. We'll go for separate fields as a last resort.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 1, 2023, 7:12am UTC](https://discuss.elastic.co/t/elasticsearch-watcher-capabilities/329167/2 "2023-05-01T07:12:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
