# How to create a watcher script to match one field with other field in same document

**URL:** <https://discuss.elastic.co/t/how-to-create-a-watcher-script-to-match-one-field-with-other-field-in-same-document/260424>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [January 7, 2021, 9:13am UTC](https://discuss.elastic.co/t/how-to-create-a-watcher-script-to-match-one-field-with-other-field-in-same-document/260424 "2021-01-07T09:13:47Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![sangatamilan](https://avatars.discourse-cdn.com/v4/letter/s/cab0a1/32.png) [@sangatamilan](https://discuss.elastic.co/u/sangatamilan)\
**Post date:** [January 7, 2021, 9:13am UTC](https://discuss.elastic.co/t/how-to-create-a-watcher-script-to-match-one-field-with-other-field-in-same-document/260424/1 "2021-01-07T09:13:48Z")

</div>

Hi ,

Can anyone please help me on this scenario to create an alert  
I am having a log events like the following

\<#\> 20200806 17:04:23.261 280018000 EV.WRN [MVINB-LSL2.T1G1\_WEBSVR1 main.main TSP1.T1G1\_WEBSVR1] Failed to load TermRecord for TermID=f6y4jkm

\<#\> 20200806 17:04:23.261 280018000 EV.WRN [MVINB-LSL2.T1G1\_WEBSVR1 main.main TSP1.T1G1\_WEBSVR1] Failed to load TermRecord for TermID=f6y4jkm

\<#\> 20200806 17:04:23.261 280018000 EV.INF [MVINB-LSL2.T1G1\_WEBSVR1 main.main TSP1.T1G1\_WEBSVR1] Failed to load TermRecord for TermID=7yhe73v

\<#\> 20200806 17:04:23.261 280018000 EV.FNE [MVINB-LSL2.T1G1\_WEBSVR1 main.main TSP1.T1G1\_WEBSVR1] Failed to load TermRecord for TermID=j6ljudn

here EV.WRN is the "event\_type" and "Failed to load TermRecord for TermID=f6y4jkm" is the log\_message.

i want to create an alert if get the the same "event\_type" with the same "log\_message"  
with the same term id. Is there a way to generate and alert based upon this scenario. the following is my current watcher script.

{  
"trigger": {  
"schedule": {  
"interval": "10s"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"testingalert\*"  
],  
"rest\_total\_hits\_as\_int": true,  
"body": {  
"size": 0,  
"query": {  
"bool": {  
"must": {  
"query\_string": {  
"query": "Failed to load TermRecord for TermID=/a-zA-Z0-9\_.-/"  
}  
},  
"filter": {  
"range": {  
"@timestamp": {  
"gte": "{{ctx.trigger.scheduled\_time}}||-5m",  
"lte": "{{ctx.trigger.scheduled\_time}}",  
"format": "strict\_date\_optional\_time||epoch\_millis"  
}  
}  
}  
}  
},  
"aggs": {  
"log\_message": {  
"terms": {  
"field": "log\_message.keyword",  
"size": 10  
},  
"aggs": {  
"id": {  
"terms": {  
"field": "term\_id.keyword",  
"size": 10  
}  
}  
}  
}  
}  
}  
}  
}  
},  
"condition": {  
"script": {  
"source": "ArrayList arr = ctx.payload.aggregations.log\_message.buckets; for (int i = 0; i \< arr.length; i++) { if (arr[i].doc\_count \> params.threshold) { return true; } } return false;",  
"lang": "painless",  
"params": {  
"threshold": 2  
}  
}  
},  
"actions": {  
"send\_email": {  
"email": {  
"profile": "standard",  
"to": [  
"[anonymousbeendetected@gmail.com](mailto:anonymousbeendetected@gmail.com)"  
],  
"subject": "Watcher Notification",  
"body": {  
"text": "Watch [{{ctx.metadata.name}}] The 'Terminal ID' alert has occured more than 5 times in 5 minutes interval of time"  
}  
}  
}  
},  
"transform": {  
"script": {  
"source": "HashMap result = new HashMap(); ArrayList arr = ctx.payload.aggregations.log\_message.buckets; ArrayList filteredHits = new ArrayList(); for (int i = 0; i \< arr.length; i++) { HashMap filteredHit = new HashMap(); filteredHit.key = arr[i].key; filteredHit.value = arr[i].doc\_count; if (filteredHit.value \> params.threshold) { filteredHits.add(filteredHit); } } result.results = filteredHits; return result;",  
"lang": "painless",  
"params": {  
"threshold": 2  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 4, 2021, 9:13am UTC](https://discuss.elastic.co/t/how-to-create-a-watcher-script-to-match-one-field-with-other-field-in-same-document/260424/2 "2021-02-04T09:13:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
