# Switch from Watchers to Rules and Connectors

**URL:** <https://discuss.elastic.co/t/switch-from-watchers-to-rules-and-connectors/316088>\
**Category:** Elasticsearch\
**Created:** [October 7, 2022, 2:05pm UTC](https://discuss.elastic.co/t/switch-from-watchers-to-rules-and-connectors/316088 "2022-10-07T14:05:40Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![federica.forti](https://avatars.discourse-cdn.com/v4/letter/f/f17d59/32.png) [@federica.forti](https://discuss.elastic.co/u/federica.forti)\
**Post date:** [October 7, 2022, 2:05pm UTC](https://discuss.elastic.co/t/switch-from-watchers-to-rules-and-connectors/316088/1 "2022-10-07T14:05:40Z")

</div>

Hi,  
we would like to move from watchers to rules (Rule and connectors section). In particular, in the past, we have defined a watcher that performs the following queries / aggregations:

```auto
{
"query": {
    "bool": {
      "must": [
        {
          "query_string": {
            "query": "transaction.result : *",
            "analyze_wildcard": true
          }
        },
        {
          "range": {
            "@timestamp": {
              "gte": "now-2m",
              "lte": "now",
              "format": "strict_date_optional_time||epoch_millis"
            }
          }
        }
      ]
    }
  },
  "aggs": {
    "by_hosts": {
      "terms": {
        "field": "host.name",
        "size": 200
      },
      "aggs": {
        "by_app": {
          "terms": {
            "field": "application.name"
          },
          "aggs": {
            "successes": {
              "filter": {
                "term": {
                  "transaction.result": "0"
                }
              }
            },
            "by_error": {
              "bucket_script": {
                "buckets_path": {
                  "attempts": "_count",
                  "successes": "successes._count"
                },
                "script": "1-(params.successes / params.attempts)"
              }
            }
          }
        }
      }
    }
  }
}

```

Queries and aggregations were done over filebeat- \* index.

Do you know if there is a way to write the same rule, for example using as rule\_type: log threshold? This is because I need to see active alerts in "Observability--\>Alerts" section.

The alert should be triggered if the by\_error value is greater than: 0.1.

Thanks.

Federica Forti | Elastic Certified Engineer

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 2:06pm UTC](https://discuss.elastic.co/t/switch-from-watchers-to-rules-and-connectors/316088/2 "2022-11-04T14:06:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
