# Spike detection in elasticsearch

**URL:** <https://discuss.elastic.co/t/spike-detection-in-elasticsearch/26206>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [July 24, 2015, 5:25am UTC](https://discuss.elastic.co/t/spike-detection-in-elasticsearch/26206 "2015-07-24T05:25:03Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sajid\_Moinuddin](https://avatars.discourse-cdn.com/v4/letter/s/59ef9b/32.png) [@Sajid\_Moinuddin](https://discuss.elastic.co/u/Sajid_Moinuddin)\
**Post date:** [July 24, 2015, 5:25am UTC](https://discuss.elastic.co/t/spike-detection-in-elasticsearch/26206/1 "2015-07-24T05:25:03Z")

</div>

I am trying to get something like setup with watcher, would appreciate if anyone points me to the right direction. Basically I want my conditions to be more dynamic rather than just greater than / less than match.

> <https://github.com/Yelp/elastalert/blob/master/example_rules/example_spike.yaml>

---

<div class="post-metadata">

**Author:** ![colings86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/colings86/32/44960_2.png) [@colings86](https://discuss.elastic.co/u/colings86)\
**Post date:** [July 24, 2015, 8:37am UTC](https://discuss.elastic.co/t/spike-detection-in-elasticsearch/26206/2 "2015-07-24T08:37:35Z")

</div>

You will probably want to add more information to this in order for someone to be able to help you. What problem are you trying to solve? Could you explain " I want my conditions to be more dynamic rather than just greater than / less than match" a bit more? What conditions do you want to apply? And lastly, what have you tried so far when creating a Watch?

---

<div class="post-metadata">

**Author:** ![colings86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/colings86/32/44960_2.png) [@colings86](https://discuss.elastic.co/u/colings86)\
**Post date:** [July 24, 2015, 10:15am UTC](https://discuss.elastic.co/t/spike-detection-in-elasticsearch/26206/3 "2015-07-24T10:15:11Z")

</div>

I've just noticed you are talking about Watcher in the text of your question but the link is for Elastalert. Which one are you trying to use? Watcher or Elastalert?

---

<div class="post-metadata">

**Author:** ![Sajid\_Moinuddin](https://avatars.discourse-cdn.com/v4/letter/s/59ef9b/32.png) [@Sajid\_Moinuddin](https://discuss.elastic.co/u/Sajid_Moinuddin)\
**Post date:** [July 27, 2015, 12:42am UTC](https://discuss.elastic.co/t/spike-detection-in-elasticsearch/26206/4 "2015-07-27T00:42:54Z")

</div>

Hi ,

Sorry I should be more clear about my question.

The script I put before ([https://github.com/Yelp/elastalert/blob/master/example\_rules/example\_spike.yaml](https://github.com/Yelp/elastalert/blob/master/example_rules/example_spike.yaml) ) is from the product [https://github.com/Yelp/elastalert](https://github.com/Yelp/elastalert). It represents the typical usecase for Spike Detection which can be used .

For example, we get a steady stream of Error in our logs, lets say 20 errors per 30 mins on average. However, in case of a node / service failure in our microservice architecture, it has ripple effect and the error count spikes to 100+. A human observer monitoring the kibana board can clearly find the anomaly.

The elastalert product addresses this usecase. However, I would like to try use 'Watcher' to address the same use case. The reason being as a commercial product , I can hope there are lot more features to come from Watcher.

---

<div class="post-metadata">

**Author:** ![colings86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/colings86/32/44960_2.png) [@colings86](https://discuss.elastic.co/u/colings86)\
**Post date:** [July 27, 2015, 7:10am UTC](https://discuss.elastic.co/t/spike-detection-in-elasticsearch/26206/5 "2015-07-27T07:10:53Z")

</div>

Ok, thanks for clarifying. I'll move this topic back to the Watcher category, as I think it was moved to Elasticsearch because someone thought you were talking about Elastalert.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:49pm UTC](https://discuss.elastic.co/t/spike-detection-in-elasticsearch/26206/6 "2017-07-06T13:49:12Z")

</div>


