# Error while adding condition to APM Error Watcher

**URL:** <https://discuss.elastic.co/t/error-while-adding-condition-to-apm-error-watcher/256008>\
**Category:** Elastic Observability\
**Tags:** elastic-stack-alerting\
**Created:** [November 19, 2020, 3:00pm UTC](https://discuss.elastic.co/t/error-while-adding-condition-to-apm-error-watcher/256008 "2020-11-19T15:00:22Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![akosanovic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akosanovic/32/58345_2.png) [@akosanovic](https://discuss.elastic.co/u/akosanovic)\
**Post date:** [November 19, 2020, 3:00pm UTC](https://discuss.elastic.co/t/error-while-adding-condition-to-apm-error-watcher/256008/1 "2020-11-19T15:00:22Z")

</div>

**Kibana version** : v 7.1.1

**Elasticsearch version** : v 7.1.1

**APM Server version** :

**APM Agent language and version** :

**Original install method (e.g. download page, yum, deb, from source, etc.) and version**: Elastic Cloud 7.1.1

**Is there anything special in your setup?** No

**Description of the problem including expected versus actual behavior. Please include screenshots (if relevant)**:

I want to filter out some 3rd party error messages that are spamming our slack channel but when I add condition to filter out those errors I'm getting an error.

How do we filter out some errors from the watcher?

```auto
 "condition": {
     "never": {
         "term": {
               "error.exception.message": "Http failure response for (unknown url): 0 Unknown Error"
           }
      }
   }

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/5/f5e67af797cc128bf37eb2ca7890a08609429c9e.png)

**Provide logs and/or server output (if relevant)**:

```auto
{
  "trigger": {
    "schedule": {
      "interval": "10m"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "apm-*"
        ],
        "rest_total_hits_as_int": true,
        "body": {
          "size": 0,
          "query": {
            "bool": {
              "filter": [
                {
                  "term": {
                    "service.name": "{{ctx.metadata.serviceName}}"
                  }
                },
                {
                  "term": {
                    "processor.event": "error"
                  }
                },
                {
                  "range": {
                    "@timestamp": {
                      "gte": "now-{{ctx.metadata.timeRangeValue}}{{ctx.metadata.timeRangeUnit}}"
                    }
                  }
                }
              ]
            }
          },
          "aggs": {
            "error_groups": {
              "terms": {
                "min_doc_count": "{{ctx.metadata.threshold}}",
                "field": "error.grouping_key",
                "size": 10,
                "order": {
                  "_count": "desc"
                },
               "condition": {
                  "never": {
                    "term": {
                      "error.exception.message": "Http failure response for (unknown url): 0 Unknown Error"
                    }
                  }
                }
              },
              "aggs": {
                "sample": {
                  "top_hits": {
                    "_source": [
                      "error.log.message",
                      "error.exception.message",
                      "error.exception.handled",
                      "error.culprit",
                      "error.grouping_key",
                      "@timestamp"
                    ],
                    "sort": [
                      {
                        "@timestamp": "desc"
                      }
                    ],
                    "size": 1
                  }
                }
              }
            }
          }
        }
      }
    }
  },
  "condition": {
    "script": {
      "source": "return ctx.payload.aggregations.error_groups.buckets.length > 0",
      "lang": "painless"
    }
  },
  "actions": {
    "log_error": {
      "logging": {
        "level": "info",
        "text": "Your service \"{{ctx.metadata.serviceName}}\" has error groups which exceeds {{ctx.metadata.threshold}} occurrences within \"{{ctx.metadata.timeRangeValue}}{{ctx.metadata.timeRangeUnit}}\"<br/><br/>{{#ctx.payload.aggregations.error_groups.buckets}}<br/><strong>{{sample.hits.hits.0._source.error.log.message}}{{^sample.hits.hits.0._source.error.log.message}}{{sample.hits.hits.0._source.error.exception.0.message}}{{/sample.hits.hits.0._source.error.log.message}}</strong><br/>{{sample.hits.hits.0._source.error.culprit}}{{^sample.hits.hits.0._source.error.culprit}}N/A{{/sample.hits.hits.0._source.error.culprit}}<br/>{{doc_count}} occurrences<br/>{{/ctx.payload.aggregations.error_groups.buckets}}"
      }
    },
    "slack_webhook": {
      "webhook": {
        "scheme": "https",
        "host": "hooks.slack.com",
        "port": 443,
        "method": "post",
        "path": "{{ctx.metadata.slackUrlPath}}",
        "params": {},
        "headers": {
          "Content-Type": "application/json"
        },
        "body": " __json__ ::{\"text\":\"Your service \\\"{{ctx.metadata.serviceName}}\\\" has error groups which exceeds {{ctx.metadata.threshold}} occurrences within \\\"{{ctx.metadata.timeRangeValue}}{{ctx.metadata.timeRangeUnit}}\\\"\\n{{#ctx.payload.aggregations.error_groups.buckets}}\\n>*{{sample.hits.hits.0._source.error.log.message}}{{^sample.hits.hits.0._source.error.log.message}}{{sample.hits.hits.0._source.error.exception.0.message}}{{/sample.hits.hits.0._source.error.log.message}}*\\n>{{#sample.hits.hits.0._source.error.culprit}}`{{sample.hits.hits.0._source.error.culprit}}`{{/sample.hits.hits.0._source.error.culprit}}{{^sample.hits.hits.0._source.error.culprit}}N/A{{/sample.hits.hits.0._source.error.culprit}}\\n>{{doc_count}} occurrences\\n{{/ctx.payload.aggregations.error_groups.buckets}}\"}"
      }
    }
  },
  "metadata": {
    "emails": [],
    "timeRangeValue": 5,
    "slackUrlPath": "/services/T03DVALCR/B012V7JUQ3V/OLepGUbDtxV6cVoBJFSsrJPi",
    "threshold": 5,
    "trigger": "This value must be changed in trigger section",
    "serviceName": "startwizard-5",
    "timeRangeUnit": "m"
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 10, 2020, 11:00am UTC](https://discuss.elastic.co/t/error-while-adding-condition-to-apm-error-watcher/256008/2 "2020-12-10T11:00:27Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
