# New to Watcher and trying to find examples

**URL:** <https://discuss.elastic.co/t/new-to-watcher-and-trying-to-find-examples/132870>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [May 22, 2018, 6:18pm UTC](https://discuss.elastic.co/t/new-to-watcher-and-trying-to-find-examples/132870 "2018-05-22T18:18:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rhonda\_Bailey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rhonda_bailey/32/31485_2.png) [@Rhonda\_Bailey](https://discuss.elastic.co/u/Rhonda_Bailey)\
**Post date:** [May 22, 2018, 6:18pm UTC](https://discuss.elastic.co/t/new-to-watcher-and-trying-to-find-examples/132870/1 "2018-05-22T18:18:31Z")

</div>

Hi,

I'm brand new to Watcher and trying to understand some of the nuances. I am looking at examples I have found and don't understand some of the conditions. Could someone take a look at this script and explain what it is doing? I don't fully understand the the condition compare bolded part (ctx.payload.aggregations.load\_time\_outlier\*\*.values.6.value\*\*). How is that configured or where does it come from? I'm not finding anything in the documentation to help explain this.

"trigger": {  
"schedule": {  
"interval": "5m"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"_"  
],  
"types": [],  
"body": {  
"size": 0,  
"query": {  
"bool": {  
"must": [  
{  
"match": {  
"\_index": "mwp_"  
}  
},  
{  
"range": {  
"@timestamp": {  
"gte": "now-5m",  
"lt": "now"  
}  
}  
},  
{  
"term": {  
"json.data.team": "sbn"  
}  
},  
{  
"term": {  
"json.tags": "http-api-receive"  
}  
},  
{  
"terms": {  
"json.data.responseStatusCode": [  
200  
]  
}  
}  
]  
}  
},  
"aggs": {  
"load\_time\_outlier": {  
"percentiles": {  
"field": "json.data.timeTakenInMSec",  
"keyed": false  
}  
}  
}  
}  
}  
}  
},  
"condition": {  
"compare": {  
"ctx.payload.aggregations.load\_time\_outlier.values.6.value": {  
"gte": 1000  
}  
}  
}

Thanks,

Rhonda Bailey

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [May 31, 2018, 2:12pm UTC](https://discuss.elastic.co/t/new-to-watcher-and-trying-to-find-examples/132870/2 "2018-05-31T14:12:10Z")

</div>

Hi Rhonda,

When the input query is run as part of this watch, a query aggregation is run (in this case, a [`percentiles` aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-metrics-percentile-aggregation.html)). The output of that will be an array that will look something like:

```auto
          "aggregations": {
            "load_time_outlier": {
              "values": [
                {
                  "value": 8.924114057624271,
                  "key": 1
                },
                {
                  "value": 10.54291390330281,
                  "key": 5
                },
                {
                  "value": 20.738003111191084,
                  "key": 25
                },
                {
                  "value": 187.80716667566568,
                  "key": 50
                },
                {
                  "value": 406.51588899356284,
                  "key": 75
                },
                {
                  "value": 1870.7552690639914,
                  "key": 95
                },
                {
                  "value": 9998.294815264673,
                  "key": 99
                }
              ]
            }
          }

```

therefore, `ctx.payload.aggregations.load_time_outlier.values.6.value` will be the `value` element of the 7th element of this array (since the array is 0-based). This is thus, the 99th percentile value of the `json.data.timeTakenInMSec` field .

In the above example, this 99th percentile would resolve out to:

`"ctx.payload.aggregations.load_time_outlier.values.6.value": 9998.294815264673`

And in your `compare` logic, would be just slightly under the `threshold` of `1000`

---

<div class="post-metadata">

**Author:** ![Rhonda\_Bailey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rhonda_bailey/32/31485_2.png) [@Rhonda\_Bailey](https://discuss.elastic.co/u/Rhonda_Bailey)\
**Post date:** [May 31, 2018, 3:50pm UTC](https://discuss.elastic.co/t/new-to-watcher-and-trying-to-find-examples/132870/3 "2018-05-31T15:50:41Z")

</div>

Thank you. That makes much more sense now.

Rhonda

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 28, 2018, 3:50pm UTC](https://discuss.elastic.co/t/new-to-watcher-and-trying-to-find-examples/132870/4 "2018-06-28T15:50:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
