# Watcher alert for matching multiple fields in same index

**URL:** <https://discuss.elastic.co/t/watcher-alert-for-matching-multiple-fields-in-same-index/273690>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [May 21, 2021, 7:19pm UTC](https://discuss.elastic.co/t/watcher-alert-for-matching-multiple-fields-in-same-index/273690 "2021-05-21T19:19:34Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Patr123](https://avatars.discourse-cdn.com/v4/letter/p/ac91a4/32.png) [@Patr123](https://discuss.elastic.co/u/Patr123)\
**Post date:** [May 21, 2021, 7:19pm UTC](https://discuss.elastic.co/t/watcher-alert-for-matching-multiple-fields-in-same-index/273690/1 "2021-05-21T19:19:34Z")

</div>

Hello, I am trying to match multiple fields in a single index for my watcher alert and having some difficulties doing that.  
My watcher looks like:

```auto
{
  "trigger": {
    "schedule": {
      "interval": "15m"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "index123"
        ],
        "rest_total_hits_as_int": true,
        "body": {
          "query": {
            "bool": {
              "filter": [
                {
                  "range": {
                    "@timestamp": {
                      "gte": "now-15m",
                      "lte": "now"
                    }
                  }
                }
              ],
              "must": {
                "match": {
                  "LogLevel": "ERROR"
                }
              }
            }
          }
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "gt": 0
      }
    }
  },
  "actions": {
    "log": {
      "logging": {
        "level": "info",
        "text": """{{ctx.payload.hits.total}} Errors have occured in the logs 
:{{#toJson}}ctx.payload.hits.hits{{/toJson}}"""
      }
    },
    "email_administrator": {
      "email": {
        "profile": "standard",
        "attachments": {
          "attached_data": {
            "data": {
              "format": "json"
            }
          }
        },
        "from": "user123@testcompany.com",
        "to": [
          "user456@testcompany.com"
        ],
        "subject": "Test Application encountered {{ctx.payload.hits.total}} in the last 15 minutes",
        "body": {
          "text": "{{ctx.payload.hits.total}} Errors have occured in the logs "
        }
      }
    }
  },
  "throttle_period_in_millis": 900000
}

```

The above wathcher is working and sending email as expected.  
But now, I also want to match it against one more field called as tags along with the "LogLevel" field and create an alert :

```auto
"match": {
                  "tags": "test_env"
                }

```

and I am having problems in this.

How can I match against multiple fields in the same index and create an alert?

---

<div class="post-metadata">

**Author:** ![cheiligers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheiligers/32/73114_2.png) [@cheiligers](https://discuss.elastic.co/u/cheiligers)\
**Post date:** [May 25, 2021, 5:33pm UTC](https://discuss.elastic.co/t/watcher-alert-for-matching-multiple-fields-in-same-index/273690/2 "2021-05-25T17:33:22Z")

</div>

@Patr123 You can add your "tags" field to your bool "must" condition by turning the "must" into an array. e.g.

```auto
...
"query": {
    "bool": {
      "must": [
        {
          "match": {
            "LogLevel": "ERROR"
          }
        },
        {
          "match": {
            "tags": "test_env"
          }
        }
      ]
    }
  }
...

```

You can use the array format for [other](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-bool-query.html) clauses too.

---

<div class="post-metadata">

**Author:** ![Patr123](https://avatars.discourse-cdn.com/v4/letter/p/ac91a4/32.png) [@Patr123](https://discuss.elastic.co/u/Patr123)\
**Post date:** [June 1, 2021, 9:17pm UTC](https://discuss.elastic.co/t/watcher-alert-for-matching-multiple-fields-in-same-index/273690/3 "2021-06-01T21:17:32Z")

</div>

Thank you, this worked.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 29, 2021, 9:18pm UTC](https://discuss.elastic.co/t/watcher-alert-for-matching-multiple-fields-in-same-index/273690/4 "2021-06-29T21:18:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
