# Using conditions in watcher

**URL:** <https://discuss.elastic.co/t/using-conditions-in-watcher/318956>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting, painless\
**Created:** [November 15, 2022, 1:12pm UTC](https://discuss.elastic.co/t/using-conditions-in-watcher/318956 "2022-11-15T13:12:53Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ErGeek](https://avatars.discourse-cdn.com/v4/letter/e/e5b9ba/32.png) [@ErGeek](https://discuss.elastic.co/u/ErGeek)\
**Post date:** [November 15, 2022, 1:12pm UTC](https://discuss.elastic.co/t/using-conditions-in-watcher/318956/1 "2022-11-15T13:12:53Z")

</div>

Hi All,

I am trying to add conditions in a watcher.  
If the value of the ctx.payload.value is less than 100, it should print a particular message "Within the limit". And if not than it should print another message "Limit exceeded".  
I am trying the below snippet inside the Transform section, but it is showing compilation error. Could anyone please help on this?

"transform": {  
"script": {  
if (ctx.payload.total \< 100)  
{  
return "Within limit"  
}  
else  
{  
return "Out of limit"  
}  
return ctx.payload;  
""",  
"lang": "painless"  
}  
}

---

<div class="post-metadata">

**Author:** ![sai\_kiran1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sai_kiran1/32/44118_2.png) [@sai\_kiran1](https://discuss.elastic.co/u/sai_kiran1)\
**Post date:** [November 15, 2022, 3:36pm UTC](https://discuss.elastic.co/t/using-conditions-in-watcher/318956/2 "2022-11-15T15:36:59Z")

</div>

You can try ctx.payload.hits.total.value for referring total number of hits in your search results.

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [November 15, 2022, 3:55pm UTC](https://discuss.elastic.co/t/using-conditions-in-watcher/318956/3 "2022-11-15T15:55:55Z")

</div>

Exactly as @sai_kiran1 says... It really depends on what is executed before in order to tell where to set the condition.  
If you have a search input, it's likely you'll need to check the `ctx.payload.hits.total`.  
Also keep in mind the `transform` section (at Watcher root level) is executed after the `condition`.

In case you need help, I would suggest sharing the Watcher content AND the Watcher execution result (without the `transform`), so we can see the actual response from the input(s).

---

<div class="post-metadata">

**Author:** ![ErGeek](https://avatars.discourse-cdn.com/v4/letter/e/e5b9ba/32.png) [@ErGeek](https://discuss.elastic.co/u/ErGeek)\
**Post date:** [November 15, 2022, 4:25pm UTC](https://discuss.elastic.co/t/using-conditions-in-watcher/318956/4 "2022-11-15T16:25:14Z")

</div>

Hi @Luca_Belluccini ,

PF the current watcher below.  
We want to show if (ctx.payload.total \> 100 ) , print "limit exceeded".  
Else print "within limit".

{  
"trigger" : {  
"schedule" : {  
"interval" : "2m"  
}  
},  
"input": {  
"http": {  
"request": {  
"scheme": "https",  
"host": "####",  
"port": 9243,  
"method": "get",  
"path": "\_cat/indices",  
"params": {  
"format": "yaml",  
"human": "true",  
"bytes": "mb"  
},  
"headers": {},  
"auth": {  
"basic": {  
"username": "elastic",  
"password": "\*\*\*"  
}  
}  
}  
}  
},  
"condition": {  
"script": {  
"source": "return true;",  
"lang": "painless"  
}  
},  
"actions": {  
"email\_administrator": {  
"transform": {  
"script": {  
"source": """  
ctx.payload.total = (ctx.payload.data.stream().collect(Collectors.summarizingDouble(e -\> Double.parseDouble(e['store.size']))).sum)/1024;  
return ctx.payload;  
""",  
"lang": "painless"  
}  
},  
"email": {  
"profile": "standard",  
"to": [  
"[myemail@abc.com](mailto:myemail@abc.com)"  
],  
"subject": "Index-wise data",  
"body": {  
"html": """

## Index-wise data
  
{{#ctx.payload.data}} {{/ctx.payload.data}}

| IndexName | StoreSize |
| --- | --- |
| {{index}} | {{store.size}} MB |
| TOTAL STORE SIZE | {{ctx.payload.total}} GB |

"""  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [November 15, 2022, 4:58pm UTC](https://discuss.elastic.co/t/using-conditions-in-watcher/318956/5 "2022-11-15T16:58:43Z")

</div>

In the transform:

```auto
ctx.payload.total = (ctx.payload.data.stream().collect(Collectors.summarizingDouble(e -> Double.parseDouble(e['store.size']))).sum)/1024;
ctx.payload.message = ctx.payload.total > 100 ? "Limit exceeded" : "Within the limit";
return ctx.payload;

```

In the email payload you can use `{{ctx.payload.message}}`.

---

<div class="post-metadata">

**Author:** ![ErGeek](https://avatars.discourse-cdn.com/v4/letter/e/e5b9ba/32.png) [@ErGeek](https://discuss.elastic.co/u/ErGeek)\
**Post date:** [November 16, 2022, 12:55pm UTC](https://discuss.elastic.co/t/using-conditions-in-watcher/318956/6 "2022-11-16T12:55:41Z")

</div>

Thanks @Luca_Belluccini !

Working perfectly for me.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 14, 2022, 12:56pm UTC](https://discuss.elastic.co/t/using-conditions-in-watcher/318956/7 "2022-12-14T12:56:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
