# Elasticsearch Watcher Rate function query

**URL:** <https://discuss.elastic.co/t/elasticsearch-watcher-rate-function-query/231570>\
**Category:** Elasticsearch\
**Created:** [May 7, 2020, 3:04pm UTC](https://discuss.elastic.co/t/elasticsearch-watcher-rate-function-query/231570 "2020-05-07T15:04:14Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![rj23495](https://avatars.discourse-cdn.com/v4/letter/r/7ba0ec/32.png) [@rj23495](https://discuss.elastic.co/u/rj23495)\
**Post date:** [May 7, 2020, 3:04pm UTC](https://discuss.elastic.co/t/elasticsearch-watcher-rate-function-query/231570/1 "2020-05-07T15:04:15Z")

</div>

Hi All,  
I wish to create a watch in elasticsearch based on rate function of logstash emitted events as seen in monitoring overview of logstash.  
How should i go about in creating a watch for the purpose as in if rate of events emitted goes below a threshold, then trigger an alarm?

 ![Screenshot 2020-05-07 at 8.31.58 PM](https://us1.discourse-cdn.com/elastic/original/3X/9/9/990b0b094b7a642270dc1c35fadb76428a86f476.png)

---

<div class="post-metadata">

**Author:** ![Brigance](https://avatars.discourse-cdn.com/v4/letter/b/838e76/32.png) [@Brigance](https://discuss.elastic.co/u/Brigance)\
**Post date:** [May 7, 2020, 3:54pm UTC](https://discuss.elastic.co/t/elasticsearch-watcher-rate-function-query/231570/2 "2020-05-07T15:54:28Z")

</div>

A single-value metrics aggregation that sums up numeric values that are extracted from the aggregated documents. These values can be extracted either from specific numeric fields in the documents, or be generated by a provided script.

---

<div class="post-metadata">

**Author:** ![rj23495](https://avatars.discourse-cdn.com/v4/letter/r/7ba0ec/32.png) [@rj23495](https://discuss.elastic.co/u/rj23495)\
**Post date:** [May 8, 2020, 4:39am UTC](https://discuss.elastic.co/t/elasticsearch-watcher-rate-function-query/231570/3 "2020-05-08T04:39:02Z")

</div>

@Brigance The metrics that i am seeing in the overview dashboard seem to aggregated using some metric name. I am actually unable to formulate a script/query for the metric to create a watcher alarm.

---

<div class="post-metadata">

**Author:** ![Brigance](https://avatars.discourse-cdn.com/v4/letter/b/838e76/32.png) [@Brigance](https://discuss.elastic.co/u/Brigance)\
**Post date:** [May 9, 2020, 3:30pm UTC](https://discuss.elastic.co/t/elasticsearch-watcher-rate-function-query/231570/4 "2020-05-09T15:30:53Z")

</div>

> [@Brigance](#):
>
> These values can be extracted either [gophone login](https://www.paygonline.vip/) from specific numeric fields in the documents, or be generated by a provided script.

These values can be extracted either from specific numeric fields in the documents, or be generated by a provided script.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 6, 2020, 3:31pm UTC](https://discuss.elastic.co/t/elasticsearch-watcher-rate-function-query/231570/5 "2020-06-06T15:31:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
