# Kibana watcher sending alert cpu utilisation more than 90%

**URL:** <https://discuss.elastic.co/t/kibana-watcher-sending-alert-cpu-utilisation-more-than-90/303824>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-monitoring, elastic-stack-alerting\
**Created:** [May 3, 2022, 11:57am UTC](https://discuss.elastic.co/t/kibana-watcher-sending-alert-cpu-utilisation-more-than-90/303824 "2022-05-03T11:57:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sanjaychahar](https://avatars.discourse-cdn.com/v4/letter/s/aeb1de/32.png) [@sanjaychahar](https://discuss.elastic.co/u/sanjaychahar)\
**Post date:** [May 3, 2022, 11:57am UTC](https://discuss.elastic.co/t/kibana-watcher-sending-alert-cpu-utilisation-more-than-90/303824/1 "2022-05-03T11:57:49Z")

</div>

Hi  
I have configured Kibana watcher to monitor cpu utilisation and its sending alert to out monitoring team stating cpu utilisation ec2 instance(Worker node) more than 90% but when I have checked in AWS CloudWatch cpu utilisation not showing more than 50%.  
We are using filebeat, metricbeat and heartbeat and I am using Elasticsearch v 7.16.3

Can you please tell me  
Is there any discrepancy in cpu utilisation in Kibana and CloudWatch ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 5, 2022, 2:22am UTC](https://discuss.elastic.co/t/kibana-watcher-sending-alert-cpu-utilisation-more-than-90/303824/2 "2022-05-05T02:22:20Z")

</div>

Welcome to our community! 😃

Can you share a few images of the stack Monitoring graphs and the cloudwatch ones showing the discrepency?

---

<div class="post-metadata">

**Author:** ![sanjaychahar](https://avatars.discourse-cdn.com/v4/letter/s/aeb1de/32.png) [@sanjaychahar](https://discuss.elastic.co/u/sanjaychahar)\
**Post date:** [May 5, 2022, 1:24pm UTC](https://discuss.elastic.co/t/kibana-watcher-sending-alert-cpu-utilisation-more-than-90/303824/3 "2022-05-05T13:24:27Z")

</div>

Thanks for your qucik response warkolam

We are using kibana watcher to monitor cpu and please find kibana watcher and AWS CloudWatch screen shot

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/f/9f6371601066b809dc5aa992988411244053b54f.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/d/bdf5021182ad33e47bf75858d4558e39262d305b.jpeg)

CPU Monitoring watcher jason file

```auto
{
  "trigger": {
    "schedule": {
      "interval": "5m"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "metricbeat-*"
        ],
        "rest_total_hits_as_int": true,
        "body": {
          "size": 0,
          "query": {
            "bool": {
              "filter": {
                "range": {
                  "@timestamp": {
                    "gte": "{{ctx.trigger.scheduled_time}}||-5m",
                    "lte": "{{ctx.trigger.scheduled_time}}",
                    "format": "strict_date_optional_time||epoch_millis"
                  }
                }
              }
            }
          },
          "aggs": {
            "bucketAgg": {
              "terms": {
                "field": "kubernetes.node.name",
                "size": "40",
                "order": {
                  "metricAgg": "asc"
                }
              },
              "aggs": {
                "metricAgg": {
                  "max": {
                    "field": "kubernetes.node.cpu.usage.nanocores"
                  }
                }
              }
            }
          }
        }
      }
    }
  },
  "condition": {
    "script": {
      "source": "ArrayList arr = xx.xx.aggregations.bucketAgg.buckets; for (int i = 0; i < arr.length; i++) { if (arr[i]['metricAgg'].value >= params.threshold) { return true; } } return false;",
      "lang": "painless",
      "params": {
        "threshold": 7200000000
      }
    }
  },
  "actions": {
    "alert_webhook": {
      "webhook": {
        "scheme": "http",
        "host": "xxxxxxxx.monitoring-xxxx-alert-proxy.svc.cluster.local",
        "port": 80,
        "method": "post",
        "path": "/api/alert",
        "params": {},
        "headers": {},
        "body": "\"Watcher id: {{ctx.watch_id}}\n\nWatcher entity_id: {{ctx.id}}\n\nTriggered_time: {{ctx.trigger.triggered_time}}\n\nEvent: {{ctx.watch_id}}: alert for error: \n\n{{ctx.payload.results}}"
      }
    }
  },
  "throttle_period_in_millis": 28800000
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 2, 2022, 1:24pm UTC](https://discuss.elastic.co/t/kibana-watcher-sending-alert-cpu-utilisation-more-than-90/303824/4 "2022-06-02T13:24:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
