# Watcher - Groovy User Guide

**URL:** <https://discuss.elastic.co/t/watcher-groovy-user-guide/98832>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [August 30, 2017, 9:48am UTC](https://discuss.elastic.co/t/watcher-groovy-user-guide/98832 "2017-08-30T09:48:24Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![vincentmarian](https://avatars.discourse-cdn.com/v4/letter/v/85f322/32.png) [@vincentmarian](https://discuss.elastic.co/u/vincentmarian)\
**Post date:** [August 30, 2017, 9:48am UTC](https://discuss.elastic.co/t/watcher-groovy-user-guide/98832/1 "2017-08-30T09:48:24Z")

</div>

We have created a Watcher script to calculate daily summary of details in our log and stored the output in a new index. This newly created index is not readable by Kibana.

After some googling I came to know that we need Groovy script to make Watcher script output index readable.

Could you please provide me a detailed user guide on Watcher with Groovy which will be helpful for us to achieve our requirement.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 30, 2017, 10:22am UTC](https://discuss.elastic.co/t/watcher-groovy-user-guide/98832/2 "2017-08-30T10:22:47Z")

</div>

What version are you running?

---

<div class="post-metadata">

**Author:** ![vincentmarian](https://avatars.discourse-cdn.com/v4/letter/v/85f322/32.png) [@vincentmarian](https://discuss.elastic.co/u/vincentmarian)\
**Post date:** [August 30, 2017, 11:00am UTC](https://discuss.elastic.co/t/watcher-groovy-user-guide/98832/3 "2017-08-30T11:00:49Z")

</div>

@warkolm we are using 5.4.3 version.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 30, 2017, 3:28pm UTC](https://discuss.elastic.co/t/watcher-groovy-user-guide/98832/4 "2017-08-30T15:28:05Z")

</div>

I'm sorry, but I do not understand this sentence

```auto
After some googling I came to know that we need Groovy script to make Watcher script output index readable.

```

Can you expand on this? You do not need groovy to make an index readable. Why do you think so?

Side note: We have developed an own scripting language called `painless` that should be used whenever possible. It might be faster, but more importantly it is more secure than groovy, especially if external users can trigger scripts.

---

<div class="post-metadata">

**Author:** ![vincentmarian](https://avatars.discourse-cdn.com/v4/letter/v/85f322/32.png) [@vincentmarian](https://discuss.elastic.co/u/vincentmarian)\
**Post date:** [August 30, 2017, 4:02pm UTC](https://discuss.elastic.co/t/watcher-groovy-user-guide/98832/5 "2017-08-30T16:02:51Z")

</div>

@spinscale Thanks for your reply. As per my organization network restrictions I am not able to upload screenshots of the problem, hence attaching only text so kindly bear with me.

I found the below link, where they used Watcher along with Groovy,

> **[Implementing a Statistical Anomaly Detector in Elasticsearch - Part 3](https://www.elastic.co/blog/implementing-a-statistical-anomaly-detector-part-3)**
>
> In the final article of this three-part series, we build a fully automated anomaly detector using Watcher to send email alerts.

So I assumed that I need to use Groovy with Watcher to make it work.

On trying to view my index(created by Watcher) in Discover tab in Kibana, I am getting the below error,

**Saved "field" parameter is now invalid. Please select a new field.**  
**Discover: "field" is a required parameter**

## Watcher Script Used:

{  
"trigger": {  
"schedule": {  
"interval": "24h"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"orbpm\_bpmi\_metrics-_"  
],  
"types": [],  
"body": {  
"query": {  
"bool": {  
"must": [  
{  
"query\_string": {  
"analyze\_wildcard": true,  
"query": "_"  
}  
},  
{  
"range": {  
"@timestamp": {  
"gte": 1501512796294,  
"lte": 1501513696294,  
"format": "epoch\_millis"  
}  
}  
}  
],  
"must\_not": []  
}  
},  
"size": 0,  
"\_source": {  
"excludes": []  
},  
"aggs": {  
"4": {  
"terms": {  
"field": "route",  
"exclude": "route1|route2|route3",  
"size": 50,  
"order": {  
"1": "desc"  
}  
},  
"aggs": {  
"1": {  
"max": {  
"field": "max\_process\_time"  
}  
},  
"5": {  
"date\_histogram": {  
"field": "@timestamp",  
"interval": "1d",  
"time\_zone": "America/New\_York",  
"min\_doc\_count": 1  
},  
"aggs": {  
"1": {  
"max": {  
"field": "max\_process\_time"  
}  
},  
"2": {  
"min": {  
"field": "min\_process\_time"  
}  
},  
"3": {  
"avg": {  
"field": "avg\_process\_time"  
}  
}  
}  
}  
}  
}  
}  
}  
}  
}  
},  
"condition": {  
"always": {}  
},  
"actions": {  
"index\_payload": {  
"index": {  
"index": "orbpm\_daily\_summary\_bpmi",  
"doc\_type": "json"  
}  
}  
}  
}

## orbpm\_daily\_summary\_bpmi INDEX:

name-------type   
aggregations.4.buckets.5.buckets.key\_as\_string string   
aggregations.4.buckets.5.buckets.1.value number   
aggregations.4.buckets.doc\_count number   
aggregations.4.buckets.5.buckets.doc\_count number   
hits.max\_score number   
aggregations.4.buckets.5.buckets.key number   
aggregations.4.buckets.1.value number   
took number   
hits.total number   
aggregations.4.buckets.5.buckets.2.value number   
timed\_out boolean   
message string   
@timestamp date   
aggregations.4.buckets.key string   
aggregations.4.buckets.5.buckets.3.value number   
\_source \_source   
aggregations.4.sum\_other\_doc\_count number   
aggregations.4.doc\_count\_error\_upper\_bound number   
\_id string   
\_type string   
\_index string   
\_score number

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 31, 2017, 6:41am UTC](https://discuss.elastic.co/t/watcher-groovy-user-guide/98832/6 "2017-08-31T06:41:29Z")

</div>

Hey, so this a Kibana or an Elasticsearch problem now? I want to make sure I understand this first.

If you use the console/dev tools, can you search in that index?

---

<div class="post-metadata">

**Author:** ![vincentmarian](https://avatars.discourse-cdn.com/v4/letter/v/85f322/32.png) [@vincentmarian](https://discuss.elastic.co/u/vincentmarian)\
**Post date:** [September 1, 2017, 10:35am UTC](https://discuss.elastic.co/t/watcher-groovy-user-guide/98832/7 "2017-09-01T10:35:27Z")

</div>

@spinscale Not sure whether it is a Kibana or an Elasticsearch problem. Queried the data contents of the index created by Watcher. It looks like below,

{  
"1" : {  
"value" : 1487735.375  
},  
"doc\_count" : 3,  
"5" : {  
"buckets" : [  
{  
"key\_as\_string" : "2017-07-31T00:00:00.000-04:00",  
"1" : {  
"value" : 1487735.375  
},  
"doc\_count" : 3,  
"2" : {  
"value" : 1373.9156494140625  
},  
"3" : {  
"value" : 1019515.5625  
},  
"key" : 1501473600000  
}  
]  
},  
"key" : "bpmServiceRouteId"  
}

Kindly guide me how to fix this problem. It looks like a nested JSON.

---

<div class="post-metadata">

**Author:** ![vincentmarian](https://avatars.discourse-cdn.com/v4/letter/v/85f322/32.png) [@vincentmarian](https://discuss.elastic.co/u/vincentmarian)\
**Post date:** [September 5, 2017, 11:35am UTC](https://discuss.elastic.co/t/watcher-groovy-user-guide/98832/8 "2017-09-05T11:35:54Z")

</div>

@spinscale can you please help me with this here.

Kindly let me know the details which you need from my end.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 3, 2017, 11:36am UTC](https://discuss.elastic.co/t/watcher-groovy-user-guide/98832/9 "2017-10-03T11:36:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
