# Watcher alert for an scripted field

**URL:** <https://discuss.elastic.co/t/watcher-alert-for-an-scripted-field/169518>\
**Category:** Elasticsearch\
**Created:** [February 22, 2019, 5:40am UTC](https://discuss.elastic.co/t/watcher-alert-for-an-scripted-field/169518 "2019-02-22T05:40:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alvaro\_Garrido](https://avatars.discourse-cdn.com/v4/letter/a/919ad9/32.png) [@Alvaro\_Garrido](https://discuss.elastic.co/u/Alvaro_Garrido)\
**Post date:** [February 22, 2019, 5:40am UTC](https://discuss.elastic.co/t/watcher-alert-for-an-scripted-field/169518/1 "2019-02-22T05:40:01Z")

</div>

Is it possible to set up a Watcher alert for an scripted field overcoming a threshold value? For example, when latency (scripted field for endTime - startTime) overcomes 500 ms, send me an alert

---

<div class="post-metadata">

**Author:** ![baz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/baz/32/5183_2.png) [@baz](https://discuss.elastic.co/u/baz)\
**Post date:** [March 5, 2019, 4:35pm UTC](https://discuss.elastic.co/t/watcher-alert-for-an-scripted-field/169518/2 "2019-03-05T16:35:17Z")

</div>

The [condition](https://www.elastic.co/guide/en/elastic-stack-overview/current/condition-script.html) in watcher allows you to use scripting to define the threshold, like 500ms. If your script is stored, there is also some info on that page for how to refer to it by ID. But you would likely just pull in the documents that have the `endTime` and `startTime` and then use the condition and your stored script by ID (or write a script).

---

<div class="post-metadata">

**Author:** ![baz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/baz/32/5183_2.png) [@baz](https://discuss.elastic.co/u/baz)\
**Post date:** [March 5, 2019, 4:38pm UTC](https://discuss.elastic.co/t/watcher-alert-for-an-scripted-field/169518/3 "2019-03-05T16:38:12Z")

</div>

Oh, I think maybe you were referring to [kibana scripted fields](https://www.elastic.co/guide/en/kibana/current/scripted-fields.html). Is this correct? If so, kibana just stores those scripts itself, so there is no easy way to refer to them. As per the docs, `Scripted field values are computed at query time so they aren’t indexed`, so this means elasticsearch knows nothing about them, sadly ☹

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 2, 2019, 4:38pm UTC](https://discuss.elastic.co/t/watcher-alert-for-an-scripted-field/169518/4 "2019-04-02T16:38:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
