# Watcher condition setup

**URL:** <https://discuss.elastic.co/t/watcher-condition-setup/291151>\
**Category:** Elasticsearch\
**Created:** [December 7, 2021, 5:40pm UTC](https://discuss.elastic.co/t/watcher-condition-setup/291151 "2021-12-07T17:40:06Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Luis\_P](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luis_p/32/92453_2.png) [@Luis\_P](https://discuss.elastic.co/u/Luis_P)\
**Post date:** [December 7, 2021, 5:40pm UTC](https://discuss.elastic.co/t/watcher-condition-setup/291151/1 "2021-12-07T17:40:06Z")

</div>

Hello,

I've been having trouble creating a watcher. My query has a terms aggregation to **aggregate** by **process** , this aggregation has a **date\_histogram sub-aggregation** , which itself has other **sub-aggregations** for **metrics**. My goal is to **compare** the **average value** of the **last bucket** of **each process**  **with bucket\_script value** from the **same bucket**

I've tried many things and I feel this is close to the solution, but I can't get it to work with the bucket\_script value, since it **can** be **null** :

```auto
"aggs": {
            "processes": {
              "terms": {
                "field": "processName.keyword"
              },
              "aggs": {
                "histo": {
                  "date_histogram": {
                    "field": "@timestamp",
                    "interval": "day"
                  },
                  "aggs": {
                    "stats": {
                      "extended_stats": {
                        "field": "RobotExecutionTime"
                      }
                    },
                    "movavg_mean": {
                      "moving_fn": {
                        "buckets_path": "stats.avg",
                        "window": 30,
                        "script": "MovingFunctions.unweightedAvg(values)"
                      }
                    },
                    "movavg_std": {
                      "moving_fn": {
                        "buckets_path": "stats.std_deviation",
                        "window": 30,
                        "script": "MovingFunctions.unweightedAvg(values)"
                      }
                    },
                    "shewhart_ucl": {
                      "bucket_script": {
                        "buckets_path": {
                          "mean": "movavg_mean.value",
                          "std": "movavg_std.value"
                        },
                        "script": "params.mean + (1 * params.std)"
                      }
                    }
                  }
                }
              }
            }
          }
        }
      }
    }
  },
  "condition": {
    "script": {
      "source": """
        for (def i = 0 ; i < ctx.payload.aggregations.processes.buckets.size() ; i++ )
        {
          def b = ctx.payload.aggregations.processes.buckets[i];
          def lastIndex = b.histo.buckets.size() - 1;
          def b2 = b.histo.buckets[lastIndex];
          boolean c = b2.shewhart_ucl.isEmpty();
          if (!c)
            continue;
          def result = b2.stats.avg > b2.shewhart_ucl.value;
          if (result == true)
          {
            return true;
          }
        }
        return false;
      """
    }
  }

```

When I run the watcher simulation it keeps throwing the following error:

 ![watcher_java_help](https://us1.discourse-cdn.com/elastic/original/3X/e/d/ed2ad7f593481909736197f28e69956e606fbd77.png)

I've tried with shewhart\_ucl.isEmpty() and shewart\_ucl.value.isNaN() with no success and the same error. I'd really appreciate some help please.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 4, 2022, 5:40pm UTC](https://discuss.elastic.co/t/watcher-condition-setup/291151/2 "2022-01-04T17:40:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
