# Watcher for monitor a process does not work

**URL:** <https://discuss.elastic.co/t/watcher-for-monitor-a-process-does-not-work/376064>\
**Category:** Kibana\
**Tags:** painless\
**Created:** [March 18, 2025, 11:20am UTC](https://discuss.elastic.co/t/watcher-for-monitor-a-process-does-not-work/376064 "2025-03-18T11:20:24Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![sreya\_14](https://avatars.discourse-cdn.com/v4/letter/s/5f8ce5/32.png) [@sreya\_14](https://discuss.elastic.co/u/sreya_14)\
**Post date:** [March 18, 2025, 11:20am UTC](https://discuss.elastic.co/t/watcher-for-monitor-a-process-does-not-work/376064/1 "2025-03-18T11:20:24Z")

</div>

We have created a watcher to monitor a process in a linux server but it does not fired and only taking the sleeping state of the process .

```auto
{
  "trigger": {
    "schedule": {
      "interval": "5m"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "nonprod-metric_beat"
        ],
        "rest_total_hits_as_int": true,
        "body": {
          "query": {
            "bool": {
              "must": [
                {
                  "range": {
                    "@timestamp": {
                      "gte": "now-5m"
                    }
                  }
                },
                {
                  "terms": {
                    "beat.hostname.keyword": [
                      "cgreupaio05uat"
                    ]
                  }
                },
                {
                  "term": {
                    "application.keyword": "tws"
                  }
                },
                {
                  "terms": {
                    "system.process.name.keyword": [
                      "jobman"
                    ]
                  }
                },
                {
                  "terms": {
                    "system.process.state": [
                      "running"
                    ]
                  }
                }
              ]
            }
          },
          "aggs": {
            "hostwise_agg": {
              "terms": {
                "field": "beat.hostname.keyword"
              },
              "aggs": {
                "service_wise": {
                  "terms": {
                    "field": "system.process.name.keyword"
                  },
                  "aggs": {
                    "service_cmdline": {
                      "terms": {
                        "field": "cmdline.keyword"
                      }
                    }
                  }
                }
              }
            }
          },
          "script_fields": {
            "description": {
              "script": {
                "lang": "painless",
                "source": "params.value",
                "params": {
                  "value": "Service Status Down"
                }
              }
            },
            "criticality": {
              "script": {
                "lang": "painless",
                "source": "params.value",
                "params": {
                  "value": "Warning"
                }
              }
            }
          },
          "_source": []
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "gt": 0
      }
    }
  },
  "actions": {
    "index_payload": {
      "index": {
        "index": "<watcher-alert-index-{now/d}>",
        "doc_type": "my-new-type",
        "execution_time_field": "@timestamp"
      }
    },
    "email_notifcation": {
      "email": {
        "profile": "standard",
        "from": "alerts@canon-europe.com",
        "to": [
          "TCS_TAM_ELK@CANONEUROPENV.onmicrosoft.com"
        ],
        "subject": "TWS | Jobman status: down | P2 | PRD",
        "body": {
          "text": """#account: canontcs
#source: web
#service_instance: TCS-Monitoring-TWS
#category: incident 
#impact: medium 
#ci: prd-tws-process-warning

Hi Team, 
You are receiving this mail because we have found an incident. The below Service Status is down 

{{#ctx.payload.aggregations.hostwise_agg.buckets}} {{key}}: 

{{#service_wise.buckets}} {{key}}: 

 {{#service_cmdline.buckets}} {{key}} {{/service_cmdline.buckets}}

 {{/service_wise.buckets}} {{/ctx.payload.aggregations.hostwise_agg.buckets}}

"""
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Keith\_Massey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keith_massey/32/83666_2.png) [@Keith\_Massey](https://discuss.elastic.co/u/Keith_Massey)\
**Post date:** [March 18, 2025, 1:35pm UTC](https://discuss.elastic.co/t/watcher-for-monitor-a-process-does-not-work/376064/2 "2025-03-18T13:35:39Z")

</div>

Take a look at your watcher history to see what might be going on. For example:

```auto
GET .watcher-history-*/_search?size=100
{
  "sort" : [
    { "@timestamp": "desc"}
  ]
}

```

If nothing stands out there, enabled debug logging for watcher, and see what is in your logs. For example:

```auto
PUT /_cluster/settings
{
  "persistent": {
    "org.elasticsearch.xpack.watcher": "DEBUG"
  }
}

```

Another thing to check is your SMTP server log -- several times I have seen a problem in the SMTP server, and Elasticsearch won't know anything about that.
