# Watcher for http status code 500 in APM Transactions

**URL:** https://discuss.elastic.co/t/watcher-for-http-status-code-500-in-apm-transactions/182190
**Category:** APM
**Tags:** nodejs, ui
**Created:** [May 22, 2019, 9:39am UTC](https://discuss.elastic.co/t/watcher-for-http-status-code-500-in-apm-transactions/182190 "2019-05-22T09:39:42Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![hsaqib](https://avatars.discourse-cdn.com/v4/letter/h/45deac/32.png) [@hsaqib](https://discuss.elastic.co/u/hsaqib)
#### Post date: [May 22, 2019, 9:39am UTC](https://discuss.elastic.co/t/watcher-for-http-status-code-500-in-apm-transactions/182190/1 "2019-05-22T09:39:42Z")

</div>

Hi, I am trying to watch for every http request with code 500 and perform an action based on that. Does APM allow such watch when error is not explicitly fired from APM client but It logs that http request in Transactions section.

So far I've tried this config but this always fires no matter what

````auto
{
  "trigger": {
    "schedule": {
      "interval": "1m"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "apm-*"
        ],
        "types": [],
        "body": {
          "size": 0,
          "query": {
            "bool": {
              "filter": [
                {
                  "term": {
                    "context.service.name": "{{ctx.metadata.serviceName}}"
                  }
                },
                {
                  "term": {
                    "context.response.status_code": 500
                  }
                },
                {
                  "range": {
                    "@timestamp": {
                      "gte": "now-{{ctx.metadata.timeRangeValue}}{{ctx.metadata.timeRangeUnit}}"
                    }
                  }
                }
              ]
            }
          },
          "aggs": {
            "error_groups": {
              "terms": {
                "min_doc_count": "{{ctx.metadata.threshold}}",
                "field": "error.grouping_key",
                "size": 10,
                "order": {
                  "_count": "desc"
                }
              },
              "aggs": {
                "sample": {
                  "top_hits": {
                    "_source": [
                      "error.log.message",
                      "error.exception.message",
                      "error.exception.handled",
                      "error.culprit",
                      "error.grouping_key",
                      "@timestamp"
                    ],
                    "sort": [
                      {
                        "@timestamp": "desc"
                      }
                    ],
                    "size": 1
                  }
                }
              }
            }
          }
        }
      }
    }
  },
  "condition": {
    "always": {}
  },
  "actions": {
    "log_error": {
      "logging": {
        "level": "info",
        "text": "Your service \"{{ctx.metadata.serviceName}}\" has error groups which exceeds {{ctx.metadata.threshold}}"
      }
    },
    "ms_teams": {
      "webhook": {
        "scheme": "https",
        "host": "outlook.office.com",
        "port": 443,
        "method": "post",
        "path": "/webhook/xxx/xxx",
        "params": {},
        "headers": {
          "Content-Type": "application/json"
        },
        "body": " __json__ ::{\"text\":\"Your service <b>\\\"{{ctx.metadata.serviceName}}\\\"</b> has error groups which exceeds {{ctx.metadata.threshold}} occurrences within \\\"{{ctx.metadata.timeRangeValue}}{{ctx.metadata.timeRangeUnit}}\\\"\\n{{#ctx.payload.aggregations.error_groups.buckets}}\"}"
      }
    }
  },
  "metadata": {
    "emails": [
      "xxxx@gmail.com"
    ],
    "timeRangeValue": 1,
    "threshold": 1,
    "trigger": "This value must be changed in trigger section",
    "serviceName": "node-server-live",
    "timeRangeUnit": "m"
  }
}```
````

---

<div class="post-metadata">

### Author: ![sqren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sqren/32/26110_2.png) [@sqren](https://discuss.elastic.co/u/sqren)
#### Post date: [May 23, 2019, 11:33am UTC](https://discuss.elastic.co/t/watcher-for-http-status-code-500-in-apm-transactions/182190/2 "2019-05-23T11:33:28Z")

</div>

Hi,

Yes, you can create watches on transaction documents (and any other document for that matter).  
Since it is a transaction document, please note that it does not have any of the error properties, like `error.grouping_key`, `error.log.message`, `error.exception.message` etc.

I've replaced the `error.grouping_key` with `transaction.name` and added `context.request.url.full` and `context.request.method` to the aggregation output, since they might be useful in your watch output.

```auto
{
  "size": 0,
  "query": {
    "bool": {
      "filter": [
        {
          "term": {
            "context.service.name": "{{ctx.metadata.serviceName}}"
          }
        },
        {
          "term": {
            "context.response.status_code": 500
          }
        },
        {
          "range": {
            "@timestamp": {
              "gte": "now-{{ctx.metadata.timeRangeValue}}{{ctx.metadata.timeRangeUnit}}"
            }
          }
        }
      ]
    }
  },
  "aggs": {
    "transaction_groups": {
      "terms": {
        "min_doc_count": "{{ctx.metadata.threshold}}",
        "field": "transaction.name",
        "size": 10,
        "order": {
          "_count": "desc"
        }
      },
      "aggs": {
        "sample": {
          "top_hits": {
            "_source": [
              "context.request.url.full",
              "context.request.method",
              "@timestamp"
            ],
            "sort": [
              {
                "@timestamp": "desc"
              }
            ],
            "size": 1
          }
        }
      }
    }
  }
}

```

If you want to test out the above, refer to the Kibana Dev Tools and run the query like:

```auto
GET apm-*/_search
{
  "size": 0,
  "query": { ... },
  "aggs": { ... }
}

```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 13, 2019, 7:35am UTC](https://discuss.elastic.co/t/watcher-for-http-status-code-500-in-apm-transactions/182190/3 "2019-06-13T07:35:34Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
