# Watcher Alert with multi match

**URL:** <https://discuss.elastic.co/t/watcher-alert-with-multi-match/323831>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [January 24, 2023, 12:43pm UTC](https://discuss.elastic.co/t/watcher-alert-with-multi-match/323831 "2023-01-24T12:43:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![vaibhav.ubale](https://avatars.discourse-cdn.com/v4/letter/v/e9a140/32.png) [@vaibhav.ubale](https://discuss.elastic.co/u/vaibhav.ubale)\
**Post date:** [January 24, 2023, 12:43pm UTC](https://discuss.elastic.co/t/watcher-alert-with-multi-match/323831/1 "2023-01-24T12:43:55Z")

</div>

Hi Team ,

I am New to community, I want to set up the watcher alert on the logs with messages like following  
"message: The user has selected account 84900-1 has no limit left"  
Where 84900 is account type and 1 is sub type.  
Can we set up the alert based on the multi match  
Following is something i am trying to create but is not working.

```auto
"must": {
                "query_string": {
                  "analyze_wildcard": true,
                  "default_field": "*",
                  "query": "message: \*"The user has selected account 84900-* has no limit left*\""
                }

```

Can some one help?

---

<div class="post-metadata">

**Author:** ![Ayush\_Mathur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ayush_mathur/32/77134_2.png) [@Ayush\_Mathur](https://discuss.elastic.co/u/Ayush_Mathur)\
**Post date:** [January 25, 2023, 7:44am UTC](https://discuss.elastic.co/t/watcher-alert-with-multi-match/323831/2 "2023-01-25T07:44:38Z")

</div>

Hi @vaibhav.ubale , welcome to the community !  
There are few options or ways to define the search query to get intended result. Since you just want to search for a substring in your message field in the same order, may be try `match_phrase_prefix` query with `84900-` in message field.

Please refer to Elastic documentation: [Match phrase prefix query | Elasticsearch Guide [8.6] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-match-query-phrase-prefix.html)

---

<div class="post-metadata">

**Author:** ![vaibhav.ubale](https://avatars.discourse-cdn.com/v4/letter/v/e9a140/32.png) [@vaibhav.ubale](https://discuss.elastic.co/u/vaibhav.ubale)\
**Post date:** [February 1, 2023, 10:03am UTC](https://discuss.elastic.co/t/watcher-alert-with-multi-match/323831/3 "2023-02-01T10:03:36Z")

</div>

Hi Ayush ,

Thanks for your suggestion.  
It worked well . I appreciate your help and suggestion here.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 1, 2023, 10:03am UTC](https://discuss.elastic.co/t/watcher-alert-with-multi-match/323831/4 "2023-03-01T10:03:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
