# Indexing Rate Watch

**URL:** <https://discuss.elastic.co/t/indexing-rate-watch/110544>\
**Category:** Elasticsearch\
**Created:** [December 6, 2017, 4:57pm UTC](https://discuss.elastic.co/t/indexing-rate-watch/110544 "2017-12-06T16:57:27Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![acchaulk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/acchaulk/32/24345_2.png) [@acchaulk](https://discuss.elastic.co/u/acchaulk)\
**Post date:** [December 6, 2017, 4:57pm UTC](https://discuss.elastic.co/t/indexing-rate-watch/110544/1 "2017-12-06T16:57:27Z")

</div>

I would like to create a Watch for when the indexing rate for a specific index is 0 /s. How does the default monitoring dashboard Indexing Rate graph pull the data in? I am having trouble finding an API to call in the watch, as the index stats api does not seem to show timeseries data. Thanks!

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [December 6, 2017, 5:30pm UTC](https://discuss.elastic.co/t/indexing-rate-watch/110544/2 "2017-12-06T17:30:15Z")

</div>

hey,

you could reuse the monitoring indices that are being created by monitoring to do this. By using `GET _cat/indices` you should see the monitoring indices.

--Alex

---

<div class="post-metadata">

**Author:** ![acchaulk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/acchaulk/32/24345_2.png) [@acchaulk](https://discuss.elastic.co/u/acchaulk)\
**Post date:** [December 6, 2017, 9:07pm UTC](https://discuss.elastic.co/t/indexing-rate-watch/110544/3 "2017-12-06T21:07:35Z")

</div>

Alex,

Does the monitoring index poll index stats?

Thanks

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [December 7, 2017, 8:11am UTC](https://discuss.elastic.co/t/indexing-rate-watch/110544/4 "2017-12-07T08:11:08Z")

</div>

I was wrong here, it only contains stats about all indices.

So what about creating one watch, that gathers the stats via HTTP input, and queries a local index for the last entry and uses an index action to store in that local index, all you need is basically a timestamp and the docs count

```auto
GET .monitoring-es-*/_stats?filter_path=_all.primaries.docs

```

if you have deletes you might want to check for the sum of count and deleted

---

<div class="post-metadata">

**Author:** ![acchaulk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/acchaulk/32/24345_2.png) [@acchaulk](https://discuss.elastic.co/u/acchaulk)\
**Post date:** [December 7, 2017, 2:33pm UTC](https://discuss.elastic.co/t/indexing-rate-watch/110544/5 "2017-12-07T14:33:57Z")

</div>

Ah, good idea. So I could collect stats for my index like that. How would you recommend calculating the rate/alerting? I found [this](https://www.elastic.co/blog/implementing-a-statistical-anomaly-detector-part-1) blog post about anomaly detection. My desired alert is to tell me when my indexing rate is 0 docs / second for X units.

---

<div class="post-metadata">

**Author:** ![acchaulk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/acchaulk/32/24345_2.png) [@acchaulk](https://discuss.elastic.co/u/acchaulk)\
**Post date:** [December 7, 2017, 7:25pm UTC](https://discuss.elastic.co/t/indexing-rate-watch/110544/6 "2017-12-07T19:25:40Z")

</div>

I think I got it.. I have one watch to poll the index \_stats api that puts that data in another index. Then I have another watch that queries that index and does a serial\_diff to see compare the document count between time windows. Not the prettiest, but it works

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [December 8, 2017, 9:44am UTC](https://discuss.elastic.co/t/indexing-rate-watch/110544/7 "2017-12-08T09:44:20Z")

</div>

Hey Adam,

you could potentially do all of this in one watch, but for the sake of getting started and not suffering from the complexity, going with two watches and that approach sounds like a good idea!

--Alex

---

<div class="post-metadata">

**Author:** ![pickypg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pickypg/32/62409_2.png) [@pickypg](https://discuss.elastic.co/u/pickypg)\
**Post date:** [December 21, 2017, 6:03pm UTC](https://discuss.elastic.co/t/indexing-rate-watch/110544/8 "2017-12-21T18:03:45Z")

</div>

The Monitoring data _does_ poll `_stats` for all indices.

```auto
GET /.monitoring-es-6-*/_search
{
  "query": {
    "bool": {
      "filter": [
        {
          "term": {
            "index_stats.index": "my-index123"
          }
        }
      ]
    }
  }
}

```

This will give you the last-fetched index stats for the index `my-index123`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 18, 2018, 6:04pm UTC](https://discuss.elastic.co/t/indexing-rate-watch/110544/9 "2018-01-18T18:04:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
