# Memory Usage AND CPU Usage Not Work!

**URL:** <https://discuss.elastic.co/t/memory-usage-and-cpu-usage-not-work/91216>\
**Category:** Elasticsearch\
**Created:** [June 29, 2017, 4:45am UTC](https://discuss.elastic.co/t/memory-usage-and-cpu-usage-not-work/91216 "2017-06-29T04:45:02Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Thanadol\_Thadasade](https://avatars.discourse-cdn.com/v4/letter/t/7ab992/32.png) [@Thanadol\_Thadasade](https://discuss.elastic.co/u/Thanadol_Thadasade)\
**Post date:** [June 29, 2017, 4:45am UTC](https://discuss.elastic.co/t/memory-usage-and-cpu-usage-not-work/91216/1 "2017-06-29T04:45:03Z")

</div>

Hi,  
I'm following example in [https://www.elastic.co/guide/en/watcher/current/watching-marvel-data.html#watching-memory-usage](https://www.elastic.co/guide/en/watcher/current/watching-marvel-data.html#watching-memory-usage), I'm currently using elasticsearch, kibana and metricbeat version 5.4.1 setup on windows10. I created watcher memory usage and cpu usage i should get alert with email. When i executed the watch api, I'm getting this error as given below.

{  
"error": {  
"root\_cause": [  
{  
"type": "general\_script\_exception",  
"reason": "failed to compile script [ScriptException[compile error]; nested: IllegalArgumentException[unexpected token ['{'] was expecting one of [{, ';'}].];]"  
}  
],  
"type": "general\_script\_exception",  
"reason": "failed to compile script [ScriptException[compile error]; nested: IllegalArgumentException[unexpected token ['{'] was expecting one of [{, ';'}].];]"  
},  
"status": 500  
}

And i find this forum same issue, but no team to reply it at link [CPU usage and Memory usage](https://discuss.elastic.co/t/cpu-usage-and-memory-usage/87670)

Can anyone help me out with the situation.

Thanks!  
Dol

#Sorry for a little grammar

---

<div class="post-metadata">

**Author:** ![Thanadol\_Thadasade](https://avatars.discourse-cdn.com/v4/letter/t/7ab992/32.png) [@Thanadol\_Thadasade](https://discuss.elastic.co/u/Thanadol_Thadasade)\
**Post date:** [June 29, 2017, 4:49am UTC](https://discuss.elastic.co/t/memory-usage-and-cpu-usage-not-work/91216/2 "2017-06-29T04:49:39Z")

</div>

```
PUT _xpack/watcher/watch/mem_watch
    {
      "trigger": {
        "schedule": {
          "interval": "1m"
        }
      },
      "input": {
        "search": {
          "request": {
            "indices": [
              "metricbeat-*"
            ],
            "types" : [
              "node_stats"
            ],
            "body": {
              "size" : 0,
              "query": {
                "bool": {
                  "filter": {
                    "range": {
                      "timestamp": {
                        "gte": "now-2m",
                        "lte": "now"
                      }
                    }
                  }
                }
              },
              "aggs": {
                "minutes": {
                  "date_histogram": {
                    "field": "timestamp",
                    "interval": "minute"
                  },
                  "aggs": {
                    "nodes": {
                      "terms": {
                        "field": "source_node.name",
                        "size": 10,
                        "order": {
                          "memory": "desc"
                        }
                      },
                      "aggs": {
                        "memory": {
                          "avg": {
                            "field": "node_stats.jvm.mem.heap_used_percent"
                          }
                        }
                      }
                    }
                  }
                }
              }
            }
          }
        }
      },
      "throttle_period": "30m", 
      "condition": {
        "script": "if (ctx.payload.aggregations.minutes.buckets.size() == 0) return false; def latest = ctx.payload.aggregations.minutes.buckets[-1]; def node = latest.nodes.buckets[0]; return node && node.memory && node.memory.value >= 75;"
      },
      "actions": {
        "send_email": {
           "transform": {
            "script": "def latest = ctx.payload.aggregations.minutes.buckets[-1]; return latest.nodes.buckets.findAll { return it.memory && it.memory.value >= 75 };"
          },
          "email": { 
            "to": "example.email@domain.com", 
            "subject": "Watcher Notification - HIGH MEMORY USAGE",
            "body": "Nodes with HIGH MEMORY Usage (above 75%):\n\n{{#ctx.payload._value}}\"{{key}}\" - Memory Usage is at {{memory.value}}%\n{{/ctx.payload._value}}"
          }
        }
      }
    }

```

this is my code.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [July 3, 2017, 8:16am UTC](https://discuss.elastic.co/t/memory-usage-and-cpu-usage-not-work/91216/3 "2017-07-03T08:16:35Z")

</div>

The example you are checking out is for watching marvel data. Marvel was used in Elasticsearch 2.x, not in 5.x - and the example is also tailored for 2.x. because of this it used `groovy` as a scripting language, but you need to change those to use painless.

You can check out the alerting examples in our [examples repo](https://github.com/elastic/examples/tree/master/Alerting) for some painless scripting examples..

---

<div class="post-metadata">

**Author:** ![Thanadol\_Thadasade](https://avatars.discourse-cdn.com/v4/letter/t/7ab992/32.png) [@Thanadol\_Thadasade](https://discuss.elastic.co/u/Thanadol_Thadasade)\
**Post date:** [July 3, 2017, 10:41am UTC](https://discuss.elastic.co/t/memory-usage-and-cpu-usage-not-work/91216/4 "2017-07-03T10:41:35Z")

</div>

thanks for advice me. @spinscale  
i'll try again. if i have issue i will come back to ask you again.

---

<div class="post-metadata">

**Author:** ![Thanadol\_Thadasade](https://avatars.discourse-cdn.com/v4/letter/t/7ab992/32.png) [@Thanadol\_Thadasade](https://discuss.elastic.co/u/Thanadol_Thadasade)\
**Post date:** [July 4, 2017, 2:18am UTC](https://discuss.elastic.co/t/memory-usage-and-cpu-usage-not-work/91216/5 "2017-07-04T02:18:33Z")

</div>

> PUT \_xpack/watcher/watch/mem\_warning  
> {  
> "trigger": {  
> "schedule": {  
> "interval": "10m"  
> }  
> },  
> "input": {  
> "search": {  
> "request": {  
> "indices": [  
> "metricbeat-\*"  
> ],  
> "types" : [  
> "metricsets"  
> ],  
> "body": {  
> "size": 0,  
> "query": {  
> "bool": {  
> "filter": [  
> {  
> "range": {  
> "@timestamp": {  
> "gte": "now-7h",  
> "lte": "now"  
> }  
> }  
> }  
> ]  
> }  
> },  
> "aggs": {  
> "minutes": {  
> "date\_histogram": {  
> "field": "@timestamp",  
> "interval": "10m"  
> },  
> "aggs": {  
> "hosts": {  
> "terms": {  
> "field": "beat.hostname",  
> "size": 10  
> },  
> "aggs": {  
> "memory\_over\_75": {  
> "filters": {  
> "filters": {  
> "high": {  
> "range": {  
> "system.memory.used.pct": {  
> "gte": 75  
> }  
> }  
> },  
> "low": {  
> "range": {  
> "system.memory.used.pct": {  
> "lt": 75  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> },  
> "throttle\_period": "30m",  
> "condition": {  
> "script": "if (ctx.payload.aggregations.minutes.buckets.size() != 0) return true; def latest = ctx.payload.aggregations.minutes.buckets[-1]; def node = latest.hosts.buckets[0]; return doc['hosts'] && doc['system.memory.total'].value && doc['system.memory.used.pct'].value \>= 75;"  
> },  
> "actions": {  
> "send\_email": {  
> "email": {  
> "to": "thanadol.thad@wealth.co.th",  
> "subject": "Watcher Notification - HIGH MEMORY USAGE",  
> "body": "Nodes with HIGH MEMORY Usage (above 75%):\n\n{{#ctx.payload.\_value}}"{{key}}" - Memory Usage is at {{memory.value}}%\n{{/ctx.payload.\_value}}"  
> }  
> }  
> }  
> }

Hi @spinscale,  
i want you to introduce the show output actions body. result host name and mem used values more than 75%

thanks.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [July 5, 2017, 7:17am UTC](https://discuss.elastic.co/t/memory-usage-and-cpu-usage-not-work/91216/6 "2017-07-05T07:17:10Z")

</div>

hey

just to be sure. Is this working as expected now for you? Or was there a question hidden in your last post, which we need to work on? 🙂

--Alex

---

<div class="post-metadata">

**Author:** ![Thanadol\_Thadasade](https://avatars.discourse-cdn.com/v4/letter/t/7ab992/32.png) [@Thanadol\_Thadasade](https://discuss.elastic.co/u/Thanadol_Thadasade)\
**Post date:** [July 5, 2017, 8:11am UTC](https://discuss.elastic.co/t/memory-usage-and-cpu-usage-not-work/91216/7 "2017-07-05T08:11:10Z")

</div>

thanks for reply @spinscale  
i'm not sure this code is correct. because this result email actions is "  
Nodes with HIGH MEMORY Usage (above 75%): "

![](https://us1.discourse-cdn.com/elastic/original/3X/e/c/ec3e3433b5bcf8be55ead766f483ef105c811f99.png)

And result execute\_api

> "result": {  
> "execution\_time": "2017-07-05T08:18:14.619Z",  
> "execution\_duration": 14044,  
> "input": {  
> "type": "search",  
> "status": "success",  
> "payload": {  
> "\_shards": {  
> "total": 50,  
> "failed": 0,  
> "successful": 50  
> },  
> "hits": {  
> "hits": ,  
> "total": 329920,  
> "max\_score": 0  
> },  
> "took": 6108,  
> "timed\_out": false,  
> "aggregations": {  
> "minutes": {  
> "buckets": [  
> {  
> "key\_as\_string": "2017-07-05T01:50:00.000Z",  
> "doc\_count": 502,  
> "hosts": {  
> "doc\_count\_error\_upper\_bound": 0,  
> "sum\_other\_doc\_count": 0,  
> "buckets": [  
> {  
> "doc\_count": 502,  
> "memory\_over\_75": {  
> "buckets": {  
> "high": {  
> "doc\_count": 0  
> },  
> "low": {  
> "doc\_count": 7  
> }  
> }  
> },  
> "key": "DESKTOP-QDUTNR1"  
> }  
> ]  
> },  
> "key": 1499219400000  
> },

> "search": {  
> "request": {  
> "search\_type": "query\_then\_fetch",  
> "indices": [  
> "metricbeat-\*"  
> ],  
> "types": [  
> "metricsets"  
> ],  
> "body": {  
> "size": 0,  
> "query": {  
> "bool": {  
> "filter": [  
> {  
> "range": {  
> "@timestamp": {  
> "gte": "now-7h",  
> "lte": "now"  
> }  
> }  
> }  
> ]  
> }  
> },  
> "aggs": {  
> "minutes": {  
> "date\_histogram": {  
> "field": "@timestamp",  
> "interval": "10m"  
> },  
> "aggs": {  
> "hosts": {  
> "terms": {  
> "field": "beat.hostname",  
> "size": 10  
> },  
> "aggs": {  
> "memory\_over\_75": {  
> "filters": {  
> "filters": {  
> "high": {  
> "range": {  
> "system.memory.used.pct": {  
> "gte": 75  
> }  
> }  
> },  
> "low": {  
> "range": {  
> "system.memory.used.pct": {  
> "lt": 75  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> },  
> "condition": {  
> "type": "script",  
> "status": "success",  
> "met": true  
> },  
> "actions": [  
> {  
> "id": "send\_email",  
> "type": "email",  
> "status": "success",  
> "email": {  
> "account": "gmail\_account",  
> "message": {  
> "id": "mem\_warning\_2ad2b2fb-4177-401e-b50c-6706a6f46926-2017-07-05T08:18:14.619Z",  
> "sent\_date": "2017-07-05T08:18:22.203Z",  
> "to": [  
> "thanadol.thad@wealth.co.th"  
> ],  
> "subject": "Watcher Notification - HIGH MEMORY USAGE",  
> "body": {  
> "text": """  
> Nodes with HIGH MEMORY Usage (above 75%):

> """  
> }  
> }  
> }  
> }  
> ]  
> },  
> "messages":   
> }  
> }

--Dol

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 2, 2017, 8:11am UTC](https://discuss.elastic.co/t/memory-usage-and-cpu-usage-not-work/91216/8 "2017-08-02T08:11:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
