# Want System memory usage to be come in Percentile form

**URL:** <https://discuss.elastic.co/t/want-system-memory-usage-to-be-come-in-percentile-form/133914>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [May 30, 2018, 4:14pm UTC](https://discuss.elastic.co/t/want-system-memory-usage-to-be-come-in-percentile-form/133914 "2018-05-30T16:14:44Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pushpak\_Bhawsar](https://avatars.discourse-cdn.com/v4/letter/p/5e9695/32.png) [@Pushpak\_Bhawsar](https://discuss.elastic.co/u/Pushpak_Bhawsar)\
**Post date:** [May 30, 2018, 4:14pm UTC](https://discuss.elastic.co/t/want-system-memory-usage-to-be-come-in-percentile-form/133914/1 "2018-05-30T16:14:44Z")

</div>

Hello,  
I have set an advance watcher to get System memory usage of an Instance via mail, but I am getting the response as **Watch [{0={value=0.7806375838926162, key=wp-bookopidia-prod-vm}}] has exceeded the threshold** via email alert.

But I want the content via email to be - **bookopidia-prod-vm has exceeded the memory by 70% or the actual result in percentage.**

This is the JSON for the watch that I've configured:

{  
"trigger": {  
"schedule": {  
"interval": "1m"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"metricbeat-wp-_"  
],  
"types": [],  
"body": {  
"size": 0,  
"query": {  
"bool": {  
"filter": {  
"range": {  
"@timestamp": {  
"gte": "{{ctx.trigger.scheduled\_time}}||-1d",  
"lte": "{{ctx.trigger.scheduled\_time}}",  
"format": "strict\_date\_optional\_time||epoch\_millis"  
}  
}  
}  
}  
},  
"aggs": {  
"bucketAgg": {  
"terms": {  
"field": "beat.hostname",  
"size": 50,  
"order": {  
"metricAgg": "desc"  
}  
},  
"aggs": {  
"metricAgg": {  
"avg": {  
"field": "system.memory.used.pct"  
}  
}  
}  
}  
}  
}  
}  
}  
},  
"condition": {  
"script": {  
"source": "ArrayList arr = ctx.payload.aggregations.bucketAgg.buckets; for (int i = 0; i \< arr.length; i++) { if (arr[i]['metricAgg'].value \> params.threshold) { return true; } } return false;",  
"lang": "painless",  
"params": {  
"threshold": 0.7  
}  
}  
},  
"actions": {  
"email\_1": {  
"email": {  
"account": "gmail\_account",  
"profile": "gmail",  
"to": [  
 "maxjohnson968@gmail.com"  
],  
"subject": "Host has exceeded the threshold",  
"body": {  
"text": "Watch [{{ctx.payload.results}}] has exceeded the threshold"  
}  
}  
}  
},  
"metadata": {  
"watcherui": {  
"trigger\_interval\_unit": "m",  
"agg\_type": "avg",  
"time\_field": "@timestamp",  
"trigger\_interval\_size": 1,  
"term\_size": 50,  
"time\_window\_unit": "d",  
"threshold\_comparator": "\>",  
"term\_field": "beat.hostname",  
"index": [  
"metricbeat-wp-_"  
],  
"time\_window\_size": 1,  
"threshold": 0.7,  
"agg\_field": "system.memory.used.pct"  
}  
},  
"transform": {  
"script": {  
"source": "HashMap result = new HashMap(); ArrayList arr = ctx.payload.aggregations.bucketAgg.buckets; ArrayList filteredHits = new ArrayList(); for (int i = 0; i \< arr.length; i++) { HashMap filteredHit = new HashMap(); filteredHit.key = arr[i].key; filteredHit.value = arr[i]['metricAgg'].value; if (filteredHit.value \> params.threshold) { filteredHits.add(filteredHit); } } result.results = filteredHits; return result;",  
"lang": "painless",  
"params": {  
"threshold": 0.7  
}  
}  
}  
}

Please help

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [May 31, 2018, 10:46am UTC](https://discuss.elastic.co/t/want-system-memory-usage-to-be-come-in-percentile-form/133914/2 "2018-05-31T10:46:14Z")

</div>

Perhaps just modify the text to use Mustache notation to loop through the result array:

```auto
          "text": "The following hosts have exceeded the threshold:\n{{#ctx.payload.results}}{{key}}:{{value}}\n{{/ctx.payload.results}}"

```

This would yield something like:

```auto
The following hosts have exceeded the threshold:
host1:0.8676520305709595
host2:0.71281805909704554

```

---

<div class="post-metadata">

**Author:** ![Pushpak\_Bhawsar](https://avatars.discourse-cdn.com/v4/letter/p/5e9695/32.png) [@Pushpak\_Bhawsar](https://discuss.elastic.co/u/Pushpak_Bhawsar)\
**Post date:** [June 4, 2018, 6:28pm UTC](https://discuss.elastic.co/t/want-system-memory-usage-to-be-come-in-percentile-form/133914/3 "2018-06-04T18:28:40Z")

</div>

Thank-you so much Rich for the prompt reply, it is very helpful but I want the threshold to come in percentile.  
I want hosts have exceeded the threshold:  
host1:0.8676520305709595 to be like host1: 80%

Is there any way to convert the decimal value to % value.

Thanx

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [June 4, 2018, 7:41pm UTC](https://discuss.elastic.co/t/want-system-memory-usage-to-be-come-in-percentile-form/133914/4 "2018-06-04T19:41:40Z")

</div>

Do the rounding in the `transform`:

```auto
      "transform": {
"script": {
"source": "HashMap result = new HashMap(); ArrayList arr = ctx.payload.aggregations.bucketAgg.buckets; ArrayList filteredHits = new ArrayList(); for (int i = 0; i < arr.length; i++) { HashMap filteredHit = new HashMap(); filteredHit.key = arr[i].key; filteredHit.value = Math.round(arr[i]['metricAgg'].value*100); if (filteredHit.value > params.threshold) { filteredHits.add(filteredHit); } } result.results = filteredHits; return result;",
"lang": "painless",
"params": {
"threshold": 70
}
}
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2018, 11:59pm UTC](https://discuss.elastic.co/t/want-system-memory-usage-to-be-come-in-percentile-form/133914/6 "2018-07-06T23:59:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
