# How to express Watcher condition on a field which has a numeric key (which has a decimal point in it)?

**URL:** <https://discuss.elastic.co/t/how-to-express-watcher-condition-on-a-field-which-has-a-numeric-key-which-has-a-decimal-point-in-it/37174>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [December 14, 2015, 10:08pm UTC](https://discuss.elastic.co/t/how-to-express-watcher-condition-on-a-field-which-has-a-numeric-key-which-has-a-decimal-point-in-it/37174 "2015-12-14T22:08:27Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![aliostad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aliostad/32/4046_2.png) [@aliostad](https://discuss.elastic.co/u/aliostad)\
**Post date:** [December 14, 2015, 10:08pm UTC](https://discuss.elastic.co/t/how-to-express-watcher-condition-on-a-field-which-has-a-numeric-key-which-has-a-decimal-point-in-it/37174/1 "2015-12-14T22:08:27Z")

</div>

Hi I am trying to set a condition for a watch that looks at a percentile of the response time of the API. The problem is that the field I need to look at in the tree has the value of "90.0" since this is how ES returns percentile values.

![](https://us1.discourse-cdn.com/elastic/original/2X/9/9fda5eeb9ffb85e8bb81c94872ee2dab694132fd.png)  
I have tried all combinations even using ['90.0'] to no avail. Problem is I cannot use something like this: [note I was able to change the agg name from "1" to "nth" but cannot do the same with the percentile]

![](https://us1.discourse-cdn.com/elastic/original/2X/b/bcd9faf34841770507521038eef1dff92b7d16e5.png)

How can I set this watch? I cannot find anyway, appreciate your help.

---

<div class="post-metadata">

**Author:** ![nellicus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nellicus/32/51566_2.png) [@nellicus](https://discuss.elastic.co/u/nellicus)\
**Post date:** [December 16, 2015, 8:47am UTC](https://discuss.elastic.co/t/how-to-express-watcher-condition-on-a-field-which-has-a-numeric-key-which-has-a-decimal-point-in-it/37174/2 "2015-12-16T08:47:36Z")

</div>

the below worked for me:

`"input": { "search": { "request": { "search_type": "query_then_fetch", "indices": ["logstash-syslog-*"], "types": [], "body": { "size": 0, "aggs": { "percentiles": { "percentiles": { "field": "my_numeric_field", "percents": [1, 5, 25, 50, 75, 95, 99] } } } } } } }, "condition": { "script": { "inline": "if (ctx.payload.aggregations.percentiles.values[\"99.0\"] > 0) return true;return false;" } }`

---

<div class="post-metadata">

**Author:** ![nellicus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nellicus/32/51566_2.png) [@nellicus](https://discuss.elastic.co/u/nellicus)\
**Post date:** [December 16, 2015, 9:30am UTC](https://discuss.elastic.co/t/how-to-express-watcher-condition-on-a-field-which-has-a-numeric-key-which-has-a-decimal-point-in-it/37174/3 "2015-12-16T09:30:18Z")

</div>

Ali, it appears that implementing the same check using watcher [compare](https://www.elastic.co/guide/en/watcher/current/condition.html#condition-compare) is not working, one of our developer found out and it is most likely a bug. using scripting for now is a valid workaround.

---

<div class="post-metadata">

**Author:** ![aliostad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aliostad/32/4046_2.png) [@aliostad](https://discuss.elastic.co/u/aliostad)\
**Post date:** [December 16, 2015, 4:16pm UTC](https://discuss.elastic.co/t/how-to-express-watcher-condition-on-a-field-which-has-a-numeric-key-which-has-a-decimal-point-in-it/37174/4 "2015-12-16T16:16:03Z")

</div>

Thank you!

Do I need to enable scripting? Because it is not enabled.

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [December 16, 2015, 4:44pm UTC](https://discuss.elastic.co/t/how-to-express-watcher-condition-on-a-field-which-has-a-numeric-key-which-has-a-decimal-point-in-it/37174/5 "2015-12-16T16:44:04Z")

</div>

Hi Aliostad,

For the example that Antonio shared, you do need to enable scripting.

However, it's easy to make the percentiles aggregation return it's results in a slightly different format that you can use with the compare condition. If you add `"keyed":true` to the percentiles aggregation, the results will come back in an array with keys and values, which are easy to parse.

In fact, I demonstrated doing this in a Webinar in July 🙂 You can skip to around 30:00 to see the example an how I used it:

[https://www.elastic.co/webinars/watcher-practical-alerting-for-elasticsearch](https://www.elastic.co/webinars/watcher-practical-alerting-for-elasticsearch)

Hope that helps!

Steve

---

<div class="post-metadata">

**Author:** ![aliostad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aliostad/32/4046_2.png) [@aliostad](https://discuss.elastic.co/u/aliostad)\
**Post date:** [December 16, 2015, 4:54pm UTC](https://discuss.elastic.co/t/how-to-express-watcher-condition-on-a-field-which-has-a-numeric-key-which-has-a-decimal-point-in-it/37174/6 "2015-12-16T16:54:06Z")

</div>

Awesome!! Thanks a lot.  
And I think you meant `"keyed":false` but I got it!

Cheers

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:47pm UTC](https://discuss.elastic.co/t/how-to-express-watcher-condition-on-a-field-which-has-a-numeric-key-which-has-a-decimal-point-in-it/37174/7 "2017-07-06T13:47:45Z")

</div>


