# Watcher for percentage drop

**URL:** <https://discuss.elastic.co/t/watcher-for-percentage-drop/109028>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [November 24, 2017, 12:16pm UTC](https://discuss.elastic.co/t/watcher-for-percentage-drop/109028 "2017-11-24T12:16:07Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pbien](https://avatars.discourse-cdn.com/v4/letter/p/ed655f/32.png) [@Pbien](https://discuss.elastic.co/u/Pbien)\
**Post date:** [November 24, 2017, 12:16pm UTC](https://discuss.elastic.co/t/watcher-for-percentage-drop/109028/1 "2017-11-24T12:16:08Z")

</div>

My use case is a watcher for percentage drop. I have a query from a single field say “submit” and I want to get the percentage drop for the “submit”. Something like c\_submit will be the current submit and p\_submit is the submit 5 minutes earlier than c\_submit. So, say the latest query for “submit” is 10, that will be the value for c\_submit and say the query 5 minutes ago for “submit” was 20, that will be the value for p\_submit, then I’ll get the percentage.

c\_submit = 10  
p\_submit = 20

Script will be c\_submit / p\_submit \* 100  
10 / 20 \* 100 = 50%

50% will be the percentage drop, so, if I have my threshold set to \< 60, alert should be triggered.

Need help on how I can achieve a working watcher for the above case. Thank you very much in advance.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 28, 2017, 7:41am UTC](https://discuss.elastic.co/t/watcher-for-percentage-drop/109028/2 "2017-11-28T07:41:26Z")

</div>

Hey,

you have not mentioned at all, where your problem is. Is it writing the query? Is it writing the condition? Or the action? Maybe you start, where you cannot proceed, and we go from there.

Also, when writing watches, you should check out [this blog post](https://www.elastic.co/blog/watching-the-watches-writing-debugging-and-testing-watches), which guides you through the most productive experience writing watches.

--Alex

---

<div class="post-metadata">

**Author:** ![Pbien](https://avatars.discourse-cdn.com/v4/letter/p/ed655f/32.png) [@Pbien](https://discuss.elastic.co/u/Pbien)\
**Post date:** [November 28, 2017, 3:04pm UTC](https://discuss.elastic.co/t/watcher-for-percentage-drop/109028/3 "2017-11-28T15:04:31Z")

</div>

Hi Alex,

Thank you very much for your reply.

So far, here's what I have:

{  
"size": 0,  
"query": {"bool": {"must": [  
{"query\_string": {"query": "cte.subcategory:"Report Submitted""}},  
{"range": {"@timestamp": {  
"from": "now-15m",  
"to": "now"  
}}}  
]}},  
"aggs": {"month": {  
"date\_histogram": {  
"field": "@timestamp",  
"interval": "month"  
},  
"aggs": {  
"c\_submit-data": {  
"filter": {"term": {"cte.subcategory.analyzed": "submitted"}},  
"aggs": {"c": {"value\_count": {"field": "cte.subcategory"}}}  
},  
"p\_submit-data": {  
"filter": {"term": {"cte.subcategory.analyzed": "submitted"}},  
"aggs": {"c": {"value\_count": {"field": "cte.subcategory"}}}  
},  
"submit-percentage": {"bucket\_script": {  
"buckets\_path": {  
"c\_submit": "c\_submit-data\>c",  
"p\_submit": "p\_submit-data\>c"  
},  
"script": "c\_submit / p\_submit \* 100"  
}}  
}  
}}  
}

I'm already good with the value for c\_submit. What I am trying to get is the value for p\_submit which is from the same data but 5 minutes earlier than the data for c\_submit.

Hope you can help me on this.

Regards,  
Paul

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 29, 2017, 10:00am UTC](https://discuss.elastic.co/t/watcher-for-percentage-drop/109028/4 "2017-11-29T10:00:15Z")

</div>

I am confused now. Is this a watcher question or is this a pipeline aggregations question?

Also you query looks confusing. You are querying for the last 15 minutes, but then creating a date histogram with an interval of a month. That does not seem to make sense to me.

You could do two things here: First, simply execute two requests, which are similar, except they filter for different time ranges. Then check the percentage in the condition.

Second, execute one request, search for the whole timerange (the last one and the current one), and then use the [filters aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/6.0/search-aggregations-bucket-filters-aggregation.html) or a [date range](https://www.elastic.co/guide/en/elasticsearch/reference/6.0/search-aggregations-bucket-daterange-aggregation.html) aggregation (note the `s` at the end), to create one bucket for each time range.

Hope this helps.

--Alex

---

<div class="post-metadata">

**Author:** ![Pbien](https://avatars.discourse-cdn.com/v4/letter/p/ed655f/32.png) [@Pbien](https://discuss.elastic.co/u/Pbien)\
**Post date:** [November 29, 2017, 3:36pm UTC](https://discuss.elastic.co/t/watcher-for-percentage-drop/109028/5 "2017-11-29T15:36:11Z")

</div>

Hi Alex,

Sorry for the confusion but this is really a watcher question. Its a watcher that will trigger if the percentage drop is below 60% or 50%. With regards to the date histogram, I’m just testing it out but what I really need is the current count and the count last five minutes ago. I can get the current count but having a hard time getting the last five minutes count on the same query. Can you give me a sample query that will filter from two different time range so I can use it as reference.

Thanks and regards,  
Paul

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 30, 2017, 8:30am UTC](https://discuss.elastic.co/t/watcher-for-percentage-drop/109028/6 "2017-11-30T08:30:39Z")

</div>

Hey Paul,

The easiest solution would be to use a chained input like this

```auto
input: {
  chained: {
    "inputs" : [
       "current" : {
           "search" : YOUR_SEARCH_FOR_LAST_5_MINS-GOES-HERE
        },
       "last" : {
           "search" : YOUR_SEARCH_FOR_LAST_5_TO_10_MINS-GOES-HERE
        }
    ]
  }
}

```

This executes two searches, and allows you to check the two searches in your condition

```auto
condition: {
  "script" : {
     "source" : "return (ctx.payload.current.aggregations.foo.bar.anything + 0.0 / ctx.payload.last.aggregations.foo.bar.anything) < 0.6"
  }
}

```

This is untested pseudocode in both samples, the path `foo.bar.anything` is of course made up you but should give you a first indication, what I meant.

You can read more about the [chain input](https://www.elastic.co/guide/en/x-pack/6.0/input-chain.html) in the docs.

--Alex

---

<div class="post-metadata">

**Author:** ![Pbien](https://avatars.discourse-cdn.com/v4/letter/p/ed655f/32.png) [@Pbien](https://discuss.elastic.co/u/Pbien)\
**Post date:** [December 2, 2017, 3:33pm UTC](https://discuss.elastic.co/t/watcher-for-percentage-drop/109028/7 "2017-12-02T15:33:24Z")

</div>

Thank you very much Alex.

I will try your recommended approach and will let you know how it goes.

Regards,  
Paul

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 30, 2017, 3:33pm UTC](https://discuss.elastic.co/t/watcher-for-percentage-drop/109028/8 "2017-12-30T15:33:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
