# How to using scripted field value in watcher?

**URL:** <https://discuss.elastic.co/t/how-to-using-scripted-field-value-in-watcher/184001>\
**Category:** Elasticsearch\
**Created:** [June 3, 2019, 2:54pm UTC](https://discuss.elastic.co/t/how-to-using-scripted-field-value-in-watcher/184001 "2019-06-03T14:54:25Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![yagami23](https://avatars.discourse-cdn.com/v4/letter/y/e19adc/32.png) [@yagami23](https://discuss.elastic.co/u/yagami23)\
**Post date:** [June 3, 2019, 2:54pm UTC](https://discuss.elastic.co/t/how-to-using-scripted-field-value-in-watcher/184001/1 "2019-06-03T14:54:25Z")

</div>

Hi ,  
i have created a scripted field called "duration" which will return in number. and i confirm this scripted field value is showing in Kibana when query.

If i want to show this scripted field value by using watcher, how do do that because i tried many method below, the field value still showing null when send in email:

\_source.duration  
\_all.duration  
doc[duration].value  
doc.duration

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 7, 2019, 11:55am UTC](https://discuss.elastic.co/t/how-to-using-scripted-field-value-in-watcher/184001/2 "2019-06-07T11:55:20Z")

</div>

Hey

if it is a scripted field, then the query you are executing in watcher also needs to create such a scripted field. Can you share the query you are running in your watch and if it is querying for such a scripted field as well?

---

<div class="post-metadata">

**Author:** ![yagami23](https://avatars.discourse-cdn.com/v4/letter/y/e19adc/32.png) [@yagami23](https://discuss.elastic.co/u/yagami23)\
**Post date:** [June 7, 2019, 2:28pm UTC](https://discuss.elastic.co/t/how-to-using-scripted-field-value-in-watcher/184001/3 "2019-06-07T14:28:41Z")

</div>

Hi Alex,  
below is my scripted field name with "value":  
doc['A'].value - doc['B'].value

and below is my watcher, i would like to compare if **ctx.payload.hits.total \> value** then trigger to send email, how i can put this scripted field "value" in watcher .. ?

```
{
  "trigger": {
    "schedule": {
      "interval": "1h"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "websys-wcs*"
        ],
        "types": [],
        "body": {
          "query": {
            "bool": {
              "must": [
                {
                  "match_phrase": {
                    "message": "E"
                  }
                },
                {
                  "match": {
                    "fields.env": "prod"
                  }
                },
                {
                  "wildcard": {
                    "source.keyword": "/opt/apps/IBM/WebSphere/AppServer/profiles/wccommp/logs/commerceServer*/SystemOut.log"
                  }
                }
              ],
              "filter": [
                {
                  "range": {
                    "@timestamp": {
                      "gte": "now-5m"
                    }
                  }
                }
              ]
            }
          },
          "sort": [
            {
              "@timestamp": {
                "order": "desc",
                "unmapped_type": "boolean"
              }
            }
          ]
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "gt": value
      }
    }
  },
  "actions": {
    "send_email": {
      "email": {
        "profile": "standard",
        "to": [
          abc@abc.com"
        ],
        "subject": "testing",
        "body": {
          "text": "The alert condition for testing was triggered:\n\n{{#ctx.payload.hits.hits}}\n\nHostname:{{_source.hostname}}\nSource:{{_source.source}}\nTags:{{_source.tags}}\n{{_source.message}}\n\n{{/ctx.payload.hits.hits}}"
        }
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 7, 2019, 2:50pm UTC](https://discuss.elastic.co/t/how-to-using-scripted-field-value-in-watcher/184001/4 "2019-06-07T14:50:59Z")

</div>

See the docs how to add a script field in kibana: [https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-script-fields.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-script-fields.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2019, 2:51pm UTC](https://discuss.elastic.co/t/how-to-using-scripted-field-value-in-watcher/184001/5 "2019-07-05T14:51:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
