# Kibana watcher returns correct data for ID but wrong data for name

**URL:** <https://discuss.elastic.co/t/kibana-watcher-returns-correct-data-for-id-but-wrong-data-for-name/180740>\
**Category:** Kibana\
**Created:** [May 13, 2019, 6:31am UTC](https://discuss.elastic.co/t/kibana-watcher-returns-correct-data-for-id-but-wrong-data-for-name/180740 "2019-05-13T06:31:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Indiresh\_Ds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/indiresh_ds/32/23382_2.png) [@Indiresh\_Ds](https://discuss.elastic.co/u/Indiresh_Ds)\
**Post date:** [May 13, 2019, 6:31am UTC](https://discuss.elastic.co/t/kibana-watcher-returns-correct-data-for-id-but-wrong-data-for-name/180740/1 "2019-05-13T06:31:18Z")

</div>

Hello there,

We have a bunch of docker containers running on our application servers and each container is dedicated to a specific service of the application.

We have also setup Kibana monitoring for all these services.

Each of these containers has a container ID which is being logged in the Kibana payload under the field **HOSTNAME**  
And the same service is also represented with the help of another identifier which is the name of the service (for ex: login-app-service). This service name is logged in the Kibana payload under the field **app.name** and also under another field called **application**

I am writing a watcher script to retrieve all the ERRORS occurring in the login-service once every hour. However, if I try to identify the logs based on the name of the service i.e., as shown below, then the watcher returns false data that belongs to a completely different service of the application (ex: navigate-service).

{  
"match":  
{  
"app.name": "login-service"  
}  
}

This is returning all the errors being logged under _navigate-service_ instead of _login-service_

But if I use the container ID as the identifier as follows, I get the correct output:

{  
"match":  
{  
"HOSTNAME": "abcde123fgh2"  
}  
}

However, this will introduce a dependency of having to go back to Kibana and change this filter manually everytime a new image of the container is deployed.

Any idea if I can refactor my watcher scripts such that it can still return the expected output using the app.name itself as the filter?

Screenshot depicting the fields in my payload is attached. Also mentioned below is the watcher script that I have written for this purpose.

 ![Kibana%20payload](https://us1.discourse-cdn.com/elastic/original/3X/f/f/fff613f602e6d3c6a8b7c97d6b0eb8edb558b5ea.png)

{  
"trigger": {  
"schedule": {  
"interval": "1h"  
}  
},  
"input": {  
"chain": {  
"inputs": [  
{  
"first": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"-_"  
],  
"types": [],  
"body": {  
"query": {  
"constant\_score": {  
"filter": {  
"bool": {  
"filter": [  
{  
"range": {  
"@timestamp": {  
"gte": "now-1h"  
}  
}  
}  
],  
"must": [  
{  
"match": {  
"level": "ERROR"  
}  
},  
{  
"bool": {  
"must": [  
{  
"match": {  
"host": ""  
}  
},  
{  
"match": {  
"HOSTNAME": "abcdef1234gh"  
}  
}  
]  
}  
}  
]  
}  
}  
}  
},  
"\_source": [  
"req.requestURI",  
"message",  
"application",  
"@timestamp"  
]  
}  
}  
}  
}  
},  
{  
"second": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"-_"  
],  
"types": ,  
"body": {  
"query": {  
"constant\_score": {  
"filter": {  
"bool": {  
"filter": [  
{  
"range": {  
"@timestamp": {  
"gte": "now-1h"  
}  
}  
}  
],  
"must": [  
{  
"match": {  
"level": "ERROR"  
}  
},  
{  
"bool": {  
"must": [  
{  
"match": {  
"host": ""  
}  
},  
{  
"match": {  
"HOSTNAME": "dfsrt1234oit"  
}  
}  
]  
}  
}  
]  
}  
}  
}  
},  
"\_source": [  
"req.requestURI",  
"message",  
"application",  
"@timestamp"  
]  
}  
}  
}  
}  
}  
]  
}  
},  
"condition": {  
"compare": {  
"ctx.payload.first.hits.total": {  
"gt": 0  
}  
}  
},  
"actions": {  
"send\_email": {  
"email": {  
"profile": "standard",  
"to": [  
"myemailaddress@domain.com"  
],  
"subject": "ERRORS in my application - login service over the past 1 hour",  
"body": {  
"text": "{{ctx.payload.first.hits.total}} errors have occurred in login service of \<server 1\> in the past 1 hour \n\n The error messages that have been logged over the past 1 hour can be found below:\n\n {{#ctx.payload.first.hits.hits}}{{\_source}}:\n{{/ctx.payload.first.hits.hits}}\n\n\n\n{{ctx.payload.second.hits.total}} errors have occurred in login service of \<server 2\> in the past 1 hour \n\n The error messages that have been logged over the past 1 hour can be found below:\n\n {{#ctx.payload.second.hits.hits}}{{\_source}}:\n{{/ctx.payload.second.hits.hits}}"  
}  
}  
},

"throttle\_period\_in\_millis": 3600000  
}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [May 22, 2019, 8:06am UTC](https://discuss.elastic.co/t/kibana-watcher-returns-correct-data-for-id-but-wrong-data-for-name/180740/2 "2019-05-22T08:06:30Z")

</div>

try `app.name.keyword` for an exact match, otherwise a search for `login OR service` is exeucted.

---

<div class="post-metadata">

**Author:** ![Indiresh\_Ds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/indiresh_ds/32/23382_2.png) [@Indiresh\_Ds](https://discuss.elastic.co/u/Indiresh_Ds)\
**Post date:** [May 26, 2019, 12:32pm UTC](https://discuss.elastic.co/t/kibana-watcher-returns-correct-data-for-id-but-wrong-data-for-name/180740/3 "2019-05-26T12:32:11Z")

</div>

Hello @spinscale

It worked like a charm! 🙂

Thank you so much! 🙂

The only change I made was replacing the below block as follows:

_Block that was present earlier:_

_{  
"match": {  
"HOSTNAME": "xxxxxxx"  
}  
}_

_Replaced this with:_

_{  
"match": {  
"app.name.keyword": "login-service"  
}  
}_

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 23, 2019, 12:32pm UTC](https://discuss.elastic.co/t/kibana-watcher-returns-correct-data-for-id-but-wrong-data-for-name/180740/4 "2019-06-23T12:32:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
