# Watcher for string value - Returns 'met : false'

**URL:** <https://discuss.elastic.co/t/watcher-for-string-value-returns-met-false/221497>\
**Category:** Kibana\
**Tags:** elastic-stack-monitoring\
**Created:** [February 28, 2020, 11:14pm UTC](https://discuss.elastic.co/t/watcher-for-string-value-returns-met-false/221497 "2020-02-28T23:14:30Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![EricJohnson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ericjohnson/32/53592_2.png) [@EricJohnson](https://discuss.elastic.co/u/EricJohnson)\
**Post date:** [February 28, 2020, 11:14pm UTC](https://discuss.elastic.co/t/watcher-for-string-value-returns-met-false/221497/1 "2020-02-28T23:14:30Z")

</div>

Greetings

I'm looking at logs coming from the application layer of a server. The records look like this:

> {  
> "\_index": "applog-test-001",  
> "\_type": "\_doc",  
> ...  
> "level": "LOG",  
> "message": "Database connected...",  
> "host": {  
> "hostname": "applog\_host",  
> "os": {  
> "kernel": "2.6.32-754.24.3.el6.x86\_64",  
> "codename": "Santiago",  
> "name": "Red",  
> "family": "redhat",  
> "version": "6.10 (Santiago)",  
> "platform": "redhat"  
> ...  
> },  
> "fields": {  
> "@timestamp": [  
> "2020-02-28T21:31:02.583Z"  
> (etc)

What I am interested in is that field that says 'level.' Basically if the level is set to 'LOG,' I want to alert.

I created a watcher with the API with this syntax:

> PUT \_watcher/watch/watcher\_log\_level  
> {  
> "trigger": {  
> "schedule": {  
> "interval": "1m"  
> }  
> },  
> "input": {  
> "search": {  
> "request": {  
> "indices": [  
> "applog-test-\*"  
> ],  
> "body": {  
> "size": 0,  
> "query": {  
> "bool": {  
> "filter": [  
> {  
> "range": {  
> "@timestamp": {  
> "gte": "now-48h"  
> }  
> }  
> },  
> {  
> "exists": {  
> "field": "level"  
> }  
> }  
> ]  
> }  
> }  
> }  
> }  
> }  
> },  
> "condition": {  
> "compare": {  
> "level": {  
> "eq": "LOG"  
> }  
> }  
> },  
> "actions": {  
> "logging\_1": {  
> "logging": {  
> "text": "Watcher\_Log\_Level [{{ctx.metadata.name}}] is LOG"  
> }  
> },  
> "index\_1": {  
> "index": {  
> "index": "log\_level\_watcher"  
> }  
> }  
> }  
> }

It runs okay. But under "met" is says "false." This should return true because I know I have lots of "level == LOG" type documents in that index.

If I set the condition part like this, "met" says "true."

> "condition": {  
> "compare": {  
> "level": {  
> "not\_eq": ""  
> }  
> }

What am I doing wrong? This should be simple to fix but I don't know what's wrong.

Thank you!

---

<div class="post-metadata">

**Author:** ![EricJohnson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ericjohnson/32/53592_2.png) [@EricJohnson](https://discuss.elastic.co/u/EricJohnson)\
**Post date:** [March 2, 2020, 8:57pm UTC](https://discuss.elastic.co/t/watcher-for-string-value-returns-met-false/221497/2 "2020-03-02T20:57:47Z")

</div>

I updated my question.

> [@Field "level" only returns Null in Watcher](https://discuss.elastic.co/t/field-level-only-returns-null-in-watcher/221704):
>
> Greetings I'm trying to write a watcher to look at a string field called "level." If level is LOG, I need to alert on it. The watcher is running but the value appears to always be null. I've tried various things but nothing has worked so far. The record looks like this: { "\_index": "applog-test-001", "\_type": "\_doc", ... "level": "LOG", "message": "Database connected...", "host": { "hostname": "applog\_host", "os": { "kernel": "2.6.32-754.24.3.el6.x86\_64", "codename": "Santiago", "name": "R…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 30, 2020, 8:57pm UTC](https://discuss.elastic.co/t/watcher-for-string-value-returns-met-false/221497/3 "2020-03-30T20:57:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
