# Need help getting the Watcher "condition" to trigger from the JVM Heap Pct usage

**URL:** <https://discuss.elastic.co/t/need-help-getting-the-watcher-condition-to-trigger-from-the-jvm-heap-pct-usage/212048>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [December 16, 2019, 7:08pm UTC](https://discuss.elastic.co/t/need-help-getting-the-watcher-condition-to-trigger-from-the-jvm-heap-pct-usage/212048 "2019-12-16T19:08:51Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![dis](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@dis](https://discuss.elastic.co/u/dis)\
**Post date:** [December 16, 2019, 7:08pm UTC](https://discuss.elastic.co/t/need-help-getting-the-watcher-condition-to-trigger-from-the-jvm-heap-pct-usage/212048/1 "2019-12-16T19:08:52Z")

</div>

I am not sure what I am doing wrong in getting the watcher to trigger. Each of the current three nodes has the JVM Heap Usage Pct over 25% (attached screenshot). The condition in the watcher is purposely set at \> 5% to get a trigger. The aggregation basically return doc\_count \> 0 when the "node\_stats.jvm.mem.heap\_used\_percent" is "gt" 5. Here is the gists for the Watcher, GET & RESPONSE:

Watcher:

> <https://gist.github.com/dcvtruong/424b36b4322fddbc960760d6a5e283b5>

GET & RESPONSE from aggregations:

> <https://gist.github.com/dcvtruong/6886095512066adeca552faf49376ef2>

Logs Result for condition met is false,  
_result.condition.met_ **false**  
_result.condition.status_ **success**

JVM Heap Percent Usage:  
 ![Screen Shot 2019-12-16 at 1.06.50 PM](https://us1.discourse-cdn.com/elastic/original/3X/f/3/f359fde71d0b1aea1cb30b0bcd2cd2414499779c.png)

Thanks in Advance.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [December 17, 2019, 12:24pm UTC](https://discuss.elastic.co/t/need-help-getting-the-watcher-condition-to-trigger-from-the-jvm-heap-pct-usage/212048/2 "2019-12-17T12:24:40Z")

</div>

can you share the output of the execute watch API or the watcher history? This will show the data that was retrieved and was executed against the watch condition - which should help to pinpoint the problem.

Thanks!

---

<div class="post-metadata">

**Author:** ![dis](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@dis](https://discuss.elastic.co/u/dis)\
**Post date:** [December 17, 2019, 3:48pm UTC](https://discuss.elastic.co/t/need-help-getting-the-watcher-condition-to-trigger-from-the-jvm-heap-pct-usage/212048/3 "2019-12-17T15:48:53Z")

</div>

This is the latest from watcher history,

> <https://gist.github.com/dcvtruong/98d294c190e9f32fb62f8fdbf9176436>

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [December 17, 2019, 4:56pm UTC](https://discuss.elastic.co/t/need-help-getting-the-watcher-condition-to-trigger-from-the-jvm-heap-pct-usage/212048/4 "2019-12-17T16:56:56Z")

</div>

Hey,

so this one states

> "condition": {  
> "type": "script",  
> "status": "success",  
> "met": false  
> }

which means that the condition was not met. Looking at the response data this makes sense

> "aggregations": {  
> "minutes": {  
> "buckets":   
> }  
> }

The first aggregation buckets are empty.

---

<div class="post-metadata">

**Author:** ![dis](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@dis](https://discuss.elastic.co/u/dis)\
**Post date:** [December 17, 2019, 5:55pm UTC](https://discuss.elastic.co/t/need-help-getting-the-watcher-condition-to-trigger-from-the-jvm-heap-pct-usage/212048/5 "2019-12-17T17:55:22Z")

</div>

Thanks for pointing out the buckets was empty. Took out the field "types": ["node\_stats"] and now the condition is met the bucket contain the three nodes heap jvm used pct. Not sure why taking out the field "types" would caused the condition to be met.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [December 17, 2019, 6:41pm UTC](https://discuss.elastic.co/t/need-help-getting-the-watcher-condition-to-trigger-from-the-jvm-heap-pct-usage/212048/6 "2019-12-17T18:41:20Z")

</div>

gflad you got it up and running. happy to take a further look with the help of the execute api if you want

---

<div class="post-metadata">

**Author:** ![dis](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@dis](https://discuss.elastic.co/u/dis)\
**Post date:** [December 17, 2019, 8:37pm UTC](https://discuss.elastic.co/t/need-help-getting-the-watcher-condition-to-trigger-from-the-jvm-heap-pct-usage/212048/7 "2019-12-17T20:37:23Z")

</div>

Please have a look,

> <https://gist.github.com/dcvtruong/c43def80cceb4aa3ccc5631704ebd4cc>

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [December 18, 2019, 8:44am UTC](https://discuss.elastic.co/t/need-help-getting-the-watcher-condition-to-trigger-from-the-jvm-heap-pct-usage/212048/9 "2019-12-18T08:44:16Z")

</div>

are you using a newer ES version like 7.x? Then the document types have started to vanish, thus you don't see anything when the type query remains.

---

<div class="post-metadata">

**Author:** ![dis](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@dis](https://discuss.elastic.co/u/dis)\
**Post date:** [December 18, 2019, 2:28pm UTC](https://discuss.elastic.co/t/need-help-getting-the-watcher-condition-to-trigger-from-the-jvm-heap-pct-usage/212048/10 "2019-12-18T14:28:05Z")

</div>

I'm using ES 7.4. Are you saying is not necessary to have 'types' in 7.x? Thanks.

---

<div class="post-metadata">

**Author:** ![dis](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@dis](https://discuss.elastic.co/u/dis)\
**Post date:** [December 18, 2019, 2:51pm UTC](https://discuss.elastic.co/t/need-help-getting-the-watcher-condition-to-trigger-from-the-jvm-heap-pct-usage/212048/11 "2019-12-18T14:51:02Z")

</div>

I'm trying out the 'array\_compare' in condition to trigger only node that met the condition and was to set the the 'path' for the array. I was not able to find from ES 7.x documentation how to set the path for array, [https://www.elastic.co/guide/en/elasticsearch/reference/7.5/condition-array-compare.html](https://www.elastic.co/guide/en/elasticsearch/reference/7.5/condition-array-compare.html)

Since there are buckets nested within another buckets, what is the path syntax to get to the field in the nested buckets?

> <https://gist.github.com/dcvtruong/b356957d6b4e3313c51a4217c2e26568>

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [December 19, 2019, 9:05am UTC](https://discuss.elastic.co/t/need-help-getting-the-watcher-condition-to-trigger-from-the-jvm-heap-pct-usage/212048/12 "2019-12-19T09:05:02Z")

</div>

If you have to check for two nested `buckets` arrays, then array compare will not work and you have to use the script condition.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 16, 2020, 9:05am UTC](https://discuss.elastic.co/t/need-help-getting-the-watcher-condition-to-trigger-from-the-jvm-heap-pct-usage/212048/13 "2020-01-16T09:05:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
