# Elasticsearch watcher syntax

**URL:** <https://discuss.elastic.co/t/elasticsearch-watcher-syntax/90922>\
**Category:** Elasticsearch\
**Created:** [June 27, 2017, 7:40am UTC](https://discuss.elastic.co/t/elasticsearch-watcher-syntax/90922 "2017-06-27T07:40:16Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Benjamin\_Peere](https://avatars.discourse-cdn.com/v4/letter/b/f04885/32.png) [@Benjamin\_Peere](https://discuss.elastic.co/u/Benjamin_Peere)\
**Post date:** [June 27, 2017, 7:40am UTC](https://discuss.elastic.co/t/elasticsearch-watcher-syntax/90922/1 "2017-06-27T07:40:16Z")

</div>

Hello everyone,

i have a problem with the elasticsearch watcher, i think the problem come from my syntax, but i don't know where,  
i have this informations :

 ![](https://us1.discourse-cdn.com/elastic/original/3X/e/b/eb35bcfd07fa03c57288cb66a7da210344639027.png)  
for the moment i would like to test if the temperature is greater than 0, so i made the following watcher :  
{  
"trigger": {  
"schedule": {  
"interval": "60s"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"monitoring"  
],  
"types": ,  
"body": {  
"query": {  
"match": {  
"\_type": "monitoring"Preformatted text  
}  
}  
}  
}  
}  
},  
"condition": {  
"compare": {  
"ctx.payload.hits.hits.temperature ": {  
"gt": 0  
}  
}  
},  
"actions": {  
"email\_admin": {  
"email": {  
"profile": "standard",  
"to": [  
"'Peere benjamin \< [benjaminpeere@gmail.com](mailto:benjaminpeere@gmail.com) \>'"  
],  
"subject": "{{ctx.watch\_id}} executed",  
"body": {  
"text": "{{ctx.watch\_id}} executed with {{ctx.payload.hits.total}} hits"  
}  
}  
}  
}  
}  
do you have any idea of what is wrong?  
thanks!

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [June 28, 2017, 12:06pm UTC](https://discuss.elastic.co/t/elasticsearch-watcher-syntax/90922/2 "2017-06-28T12:06:07Z")

</div>

Hi Benjamin,

The Alerting Examples Repo at [https://github.com/elastic/examples/tree/master/Alerting](https://github.com/elastic/examples/tree/master/Alerting) is a good reference to look at.

For example, look at this one: [https://github.com/elastic/examples/blob/master/Alerting/filesystem\_usage/watch.json](https://github.com/elastic/examples/blob/master/Alerting/filesystem_usage/watch.json)

Notice a few things that are different than what you are trying:

- There is a notion of time range in the query (query the index for documents in the last X minutes) and there's the threshold condition in the query using another range filter

```auto
          "query": {
            "bool": {
              "filter": [
                {
                  "range": {
                    "@timestamp": {
                      "gte": "now-{{ctx.metadata.window_period}}"
                    }
                  }
                },
                {
                  "range": {
                    "used_p": {
                      "gte": "{{ctx.metadata.threshold}}"
                    }
                  }
                }
              ]
            }
          }
        }

```

- The condition of the watch is counting the number of hits of the return of this query

```auto
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "gt": 0
      }
    }
  },

```

In other words, put all of the logic in the main query, then use the watch condition to see if your query matched or not.

Hope that helps!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 26, 2017, 12:06pm UTC](https://discuss.elastic.co/t/elasticsearch-watcher-syntax/90922/3 "2017-07-26T12:06:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
