# Watcher for string value - Returns 'met : false'

**URL:** <https://discuss.elastic.co/t/watcher-for-string-value-returns-met-false/221497>\
**Category:** Kibana\
**Tags:** elastic-stack-monitoring\
**Created:** [February 28, 2020, 11:14pm UTC](https://discuss.elastic.co/t/watcher-for-string-value-returns-met-false/221497 "2020-02-28T23:14:30Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![EricJohnson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ericjohnson/32/53592_2.png) [@EricJohnson](https://discuss.elastic.co/u/EricJohnson)\
**Post date:** [March 2, 2020, 8:57pm UTC](https://discuss.elastic.co/t/watcher-for-string-value-returns-met-false/221497/2 "2020-03-02T20:57:47Z")

</div>

I updated my question.

> [@Field "level" only returns Null in Watcher](https://discuss.elastic.co/t/field-level-only-returns-null-in-watcher/221704):
>
> Greetings I'm trying to write a watcher to look at a string field called "level." If level is LOG, I need to alert on it. The watcher is running but the value appears to always be null. I've tried various things but nothing has worked so far. The record looks like this: { "\_index": "applog-test-001", "\_type": "\_doc", ... "level": "LOG", "message": "Database connected...", "host": { "hostname": "applog\_host", "os": { "kernel": "2.6.32-754.24.3.el6.x86\_64", "codename": "Santiago", "name": "R…

---

_[View the full topic](https://discuss.elastic.co/t/watcher-for-string-value-returns-met-false/221497)._
