# Math in watcher condition part

**URL:** <https://discuss.elastic.co/t/math-in-watcher-condition-part/104663>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [October 20, 2017, 7:40am UTC](https://discuss.elastic.co/t/math-in-watcher-condition-part/104663 "2017-10-20T07:40:56Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Izek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/izek/32/37113_2.png) [@Izek](https://discuss.elastic.co/u/Izek)\
**Post date:** [October 20, 2017, 7:40am UTC](https://discuss.elastic.co/t/math-in-watcher-condition-part/104663/1 "2017-10-20T07:40:56Z")

</div>

I am try to do the calculate of the condition part in watcher.  
But I have no idea how to do it .

For logstash monitoring index, there have a doc.logstash\_stats.events.in and doc.logstash\_stats.events.out.  
How could I do subtraction between this to value and that is the value is less than 1000 or something, then return true?

---

<div class="post-metadata">

**Author:** ![Izek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/izek/32/37113_2.png) [@Izek](https://discuss.elastic.co/u/Izek)\
**Post date:** [October 20, 2017, 8:08am UTC](https://discuss.elastic.co/t/math-in-watcher-condition-part/104663/2 "2017-10-20T08:08:13Z")

</div>

Finally, I solved the problem.  
use script field to create a new field

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/5/d5e59caf7c15dd3fc720beed333fc821d3598741.png)

than just use compare in the condition

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 21, 2017, 6:51am UTC](https://discuss.elastic.co/t/math-in-watcher-condition-part/104663/3 "2017-10-21T06:51:03Z")

</div>

hey,

so script fields will have a considerable performance difference compared to a script condition - and they also solve a different problem.

If you dont spent some time on explaining your use-case, it will be hard to help.

Also, please refrain from using screenshots, as many people cannot see them (and you cannot paste it into a kibana instance and test it out yourself).

Thanks!

--Alex

---

<div class="post-metadata">

**Author:** ![Izek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/izek/32/37113_2.png) [@Izek](https://discuss.elastic.co/u/Izek)\
**Post date:** [October 23, 2017, 5:19am UTC](https://discuss.elastic.co/t/math-in-watcher-condition-part/104663/4 "2017-10-23T05:19:08Z")

</div>

Hi @spinscale ,

There have two field named "logstash\_stats.events.in" and "logstash\_stats.events.out" in the .monitoring-logstash index.  
I would like to calculate the gap of in and out to make there have no data missing.

But actually I tried to do the subtraction in the condition, but still cannot get it done.  
So I try to use script field, also cannot get it.

Here is my code:

{  
"trigger": {  
"schedule": {  
"interval": "10s"  
}  
},  
"input": {  
"http": {  
"request": {  
"host": "localhost",  
"port": 9200,  
"path": "/\<.monitoring-logstash-6-{now%2Fd}\>/\_search",  
"body" : "{"query":{"match\_all":{}},"script\_fields":{"logstash\_stats.events.gap":{"script":"doc['logstash\_stats.events.in'].value - doc['logstash\_stats.events.out'].value"}},"size":1,"sort":[{"logstash\_stats.timestamp":{"order":"desc"}}]}"  
}  
}  
},  
"condition": {  
"compare" : {  
"ctx.payload.hits.hits.0.\_source.logstash\_stats.events.gap" : {  
"gt" : "1000"  
}  
}  
},  
"actions": {  
"email\_administrator" : {  
"email" : {  
"to" : "test@mail.com",  
"subject" : "test",  
"body" : "test",  
"priority" : "high"  
}  
}  
}  
}

But the result of gap is null

```
  "condition": {
    "type": "compare",
    "status": "success",
    "met": false,
    "compare": {
      "resolved_values": {
        "ctx.payload.hits.hits.0._source.logstash_stats.events.gap": null
      }
    }
  }

```

Do you have any idea or suggestion about this?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 23, 2017, 7:36am UTC](https://discuss.elastic.co/t/math-in-watcher-condition-part/104663/5 "2017-10-23T07:36:44Z")

</div>

If you want to access a scripted field in the condition, you need to use the correct path.

A reply of a script fields looks a bit different

```auto
"hits": [
      {
        "_index": ".watcher-history-3-2017.10.23",
        "_type": "watch_record",
        "_id": "e4ZR1JpWQUCr7cFWH8l77Q_kibana_version_mismatch_41b24cc8-6269-45de-8252-6ecb593dcf29-2017-10-23T00:00:44.952Z",
        "_score": 1,
        "fields": {
          "foo": [
            "e4ZR1JpWQUCr7cFWH8l77Q_kibana_version_mismatch"
          ]
        }
      },
      {
...

```

so you would need to use `ctx.payload.hits.hits.0.fields.foo.0` in this example.

--Alex

---

<div class="post-metadata">

**Author:** ![Izek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/izek/32/37113_2.png) [@Izek](https://discuss.elastic.co/u/Izek)\
**Post date:** [October 24, 2017, 9:04am UTC](https://discuss.elastic.co/t/math-in-watcher-condition-part/104663/6 "2017-10-24T09:04:48Z")

</div>

Already solved the problem

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 21, 2017, 9:04am UTC](https://discuss.elastic.co/t/math-in-watcher-condition-part/104663/7 "2017-11-21T09:04:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
