# Watcher Condition Returning "Null"

**URL:** <https://discuss.elastic.co/t/watcher-condition-returning-null/195640>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [August 18, 2019, 9:48am UTC](https://discuss.elastic.co/t/watcher-condition-returning-null/195640 "2019-08-18T09:48:44Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![ntran](https://avatars.discourse-cdn.com/v4/letter/n/73ab20/32.png) [@ntran](https://discuss.elastic.co/u/ntran)\
**Post date:** [August 18, 2019, 9:48am UTC](https://discuss.elastic.co/t/watcher-condition-returning-null/195640/1 "2019-08-18T09:48:44Z")

</div>

Hi everyone,

My condition is currently returning "null", however I know there are documents.  
Can you please help me in figuring out why it's returning "null"?

// My watcher code thus far:

> <https://gist.github.com/nhtrn/d552a42a767826a4ab072fe5a32ea4a5>

// Stimulated results output

> <https://gist.github.com/nhtrn/db2fa1211ae4fb49a438a759be2838ae>

Thank you in advanced 🙂

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 19, 2019, 7:09am UTC](https://discuss.elastic.co/t/watcher-condition-returning-null/195640/2 "2019-08-19T07:09:01Z")

</div>

the addressing scheme of your condition is wrong. Your condition is

```auto
ctx.payload.aggregations.managedobjectref.timerange.buckets.0.doc_count

```

the first part `ctx.payload.aggregations.managedobjectref` is correct, however before reaching the `timerange` field, you missed that there is a `buckets` array where each element contains a `timerange` field.

---

<div class="post-metadata">

**Author:** ![ntran](https://avatars.discourse-cdn.com/v4/letter/n/73ab20/32.png) [@ntran](https://discuss.elastic.co/u/ntran)\
**Post date:** [August 19, 2019, 8:12am UTC](https://discuss.elastic.co/t/watcher-condition-returning-null/195640/3 "2019-08-19T08:12:21Z")

</div>

Thanks for replying @spinscale 🙂

I realised that yesterday, however I am still getting "null".

//This is the output I am getting now.

> <https://gist.github.com/nhtrn/49477465f9ce1b6690586a33304047d2>

// This is my console

> <https://gist.github.com/nhtrn/62cbb0412c0021437fbacc22c16f1c46>

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 19, 2019, 9:30am UTC](https://discuss.elastic.co/t/watcher-condition-returning-null/195640/4 "2019-08-19T09:30:36Z")

</div>

this snippet

```auto
"ctx.payload.aggregations.managedobjectref.buckets.timerange.buckets.doc_count": {

```

does access the array, but does not take the element position into account like `buckets.0.` for the first element

---

<div class="post-metadata">

**Author:** ![ntran](https://avatars.discourse-cdn.com/v4/letter/n/73ab20/32.png) [@ntran](https://discuss.elastic.co/u/ntran)\
**Post date:** [August 19, 2019, 9:33am UTC](https://discuss.elastic.co/t/watcher-condition-returning-null/195640/5 "2019-08-19T09:33:41Z")

</div>

So it should be  
`"ctx.payload.aggregations.managedobjectref.buckets.timerange.buckets.0.doc_count"`

which takes the element position starting from 0?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 19, 2019, 9:39am UTC](https://discuss.elastic.co/t/watcher-condition-returning-null/195640/6 "2019-08-19T09:39:15Z")

</div>

please look at the data more closely. You will see that there are two `buckets` fields, and each of them is an array, so you need to use an index twice.

---

<div class="post-metadata">

**Author:** ![ntran](https://avatars.discourse-cdn.com/v4/letter/n/73ab20/32.png) [@ntran](https://discuss.elastic.co/u/ntran)\
**Post date:** [August 19, 2019, 9:39am UTC](https://discuss.elastic.co/t/watcher-condition-returning-null/195640/7 "2019-08-19T09:39:46Z")

</div>

Yes, I just did that and got the answer

Thank you so much @spinscale  
Really appreciate your help on this one 🙂

**Answer for future readers:**  
`"ctx.payload.aggregations.<first_agg>.buckets.0.<second_agg>.buckets.0.<field>"`

**// Example:**  
`"ctx.payload.aggregations.managedobjectref.buckets.0.timerange.buckets.0.doc_count"`  
Note: This is when there is only ONE array

---

<div class="post-metadata">

**Author:** ![ntran](https://avatars.discourse-cdn.com/v4/letter/n/73ab20/32.png) [@ntran](https://discuss.elastic.co/u/ntran)\
**Post date:** [August 19, 2019, 10:17am UTC](https://discuss.elastic.co/t/watcher-condition-returning-null/195640/8 "2019-08-19T10:17:17Z")

</div>

Hi @spinscale,

Following on from this, what if I wanted to look at all the arrays, not just Array 0?

Thanks,  
Nhung

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 19, 2019, 11:08am UTC](https://discuss.elastic.co/t/watcher-condition-returning-null/195640/9 "2019-08-19T11:08:17Z")

</div>

the you need use a `script` condition instead of the `compare` one, which allows you to walk through all the buckets.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 16, 2019, 11:08am UTC](https://discuss.elastic.co/t/watcher-condition-returning-null/195640/10 "2019-09-16T11:08:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
