# Watcher Help

**URL:** <https://discuss.elastic.co/t/watcher-help/269711>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [April 9, 2021, 1:19pm UTC](https://discuss.elastic.co/t/watcher-help/269711 "2021-04-09T13:19:00Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mdamera](https://avatars.discourse-cdn.com/v4/letter/m/ba9def/32.png) [@mdamera](https://discuss.elastic.co/u/mdamera)\
**Post date:** [April 9, 2021, 1:19pm UTC](https://discuss.elastic.co/t/watcher-help/269711/1 "2021-04-09T13:19:00Z")

</div>

Team,

I have a need to monitor "code [" in the filebeat logs and it should trigger an email alert when it find the word "code ["

I have tried with below string, but it did not helped me, instead of looking for "code [" , where it see the word code its getting alerting

Can you please help me what I should use to detect only -- code [ ( there is a space after the word code)

{  
"query\_string": {  
"query": """ (message:"code\ [")"""  
}

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 12, 2021, 1:28am UTC](https://discuss.elastic.co/t/watcher-help/269711/2 "2021-04-12T01:28:06Z")

</div>

Can you provide a couple sample documents and your mapping?

---

<div class="post-metadata">

**Author:** ![Felix\_Roessel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felix_roessel/32/41623_2.png) [@Felix\_Roessel](https://discuss.elastic.co/u/Felix_Roessel)\
**Post date:** [April 12, 2021, 4:26am UTC](https://discuss.elastic.co/t/watcher-help/269711/3 "2021-04-12T04:26:20Z")

</div>

I think with Kibana alerting (\>v7.8) its pretty simple to do it. Any reason you still want to use Watcher for.this?

---

<div class="post-metadata">

**Author:** ![mdamera](https://avatars.discourse-cdn.com/v4/letter/m/ba9def/32.png) [@mdamera](https://discuss.elastic.co/u/mdamera)\
**Post date:** [April 12, 2021, 4:14pm UTC](https://discuss.elastic.co/t/watcher-help/269711/4 "2021-04-12T16:14:14Z")

</div>

Is there any article around this ?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 12, 2021, 4:53pm UTC](https://discuss.elastic.co/t/watcher-help/269711/5 "2021-04-12T16:53:04Z")

</div>

Hi @mdamera

Yes there are articles and the new Kibana Alerting is really nice.  
[Here](https://www.elastic.co/guide/en/kibana/current/alerting-getting-started.html) and most likely [Here](https://www.elastic.co/guide/en/kibana/current/alert-type-es-query.html) for your Use case the new DSL Query Alert.

However I think the hardest part no matter what you use will be the query / parsing that is why I asked for a few sample documents so perhaps we can help you with the query etc.

The Text analyzer will be breaking up that string into tokens which may or may or may not be easy to detect.

Example is it really

`code [some message or code]`

Please provide a couple sample documents and your mapping as well can you do that please.

Also please format your code / documents with the` </>` button above.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 10, 2021, 4:53pm UTC](https://discuss.elastic.co/t/watcher-help/269711/6 "2021-05-10T16:53:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
