# Watcher issue (for real)

**URL:** <https://discuss.elastic.co/t/watcher-issue-for-real/57159>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [August 3, 2016, 10:52pm UTC](https://discuss.elastic.co/t/watcher-issue-for-real/57159 "2016-08-03T22:52:16Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![kartikvelastic](https://avatars.discourse-cdn.com/v4/letter/k/7ba0ec/32.png) [@kartikvelastic](https://discuss.elastic.co/u/kartikvelastic)\
**Post date:** [August 3, 2016, 10:52pm UTC](https://discuss.elastic.co/t/watcher-issue-for-real/57159/1 "2016-08-03T22:52:16Z")

</div>

The examples on [elastic.co](http://elastic.co) seem to work unmodified in my environment, I am however having an issue:

This works and sends email:  
0}[root@test75 ~]# curl -XPUT '[http://test45:9200/\_watcher/watch/cluster\_health\_watch7](http://test45:9200/_watcher/watch/cluster_health_watch7)' -d '{

> "trigger" : {  
> "schedule" : { "cron" : "0 0/1 \* \* \* ?" }  
> },  
> "input" : {  
> "search" : {  
> "request" : {  
> "indices" : [  
> "filebeat\*"  
> "body" : {  
> ],  
> "body" : {  
> "filtered": {  
> "query" : {  
> "filtered": {  
> },  
> "query": {  
> "match": { "response": 404 }  
> },  
> "filter": {  
> "range": {  
> "@timestamp" : {  
> "from": "{{ctx.trigger.scheduled\_time}}||-5m",  
> "to": "{{ctx.trigger.triggered\_time}}"  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> },  
> "actions" : {  
> "email\_admin" : {  
> "email" : {  
> "to" : "[kartik.unix@gmail.com](mailto:kartik.unix@gmail.com)",  
> "subject" : "404 recently encountered"  
> }  
> }  
> }  
> }'  
> {"\_id":"cluster\_health\_watch7","\_version":1,"created":true}[root@test75 ~]#

This does not:

PUT \_watcher/watch/my-watch8  
{  
"trigger" : {  
"schedule" : { "cron" : "0 0/1 \* \* \* ?" }  
},  
"input" : {  
"search" : {  
"request" : {  
"indices" : [  
"filebeat\*"  
],  
"body" : {  
"query" : {  
"filtered": {  
"query": {  
"match": { "response": 404 }  
},  
"filter": {  
"range": {  
"@timestamp" : {  
"from": "{{ctx.trigger.scheduled\_time}}||-5m",  
"to": "{{ctx.trigger.triggered\_time}}"  
}  
}  
}  
}  
}  
}  
}  
}  
},  
"condition" : {  
"script" : "ctx.payload.hits.total \> 1"  
},  
"actions" : {  
"email\_admin" : {  
"email" : {  
"to" : "[kartik.unix@gmail.com](mailto:kartik.unix@gmail.com)",  
"subject" : "404 recently encountered"  
}  
}  
}  
}'

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 4, 2016, 8:00am UTC](https://discuss.elastic.co/t/watcher-issue-for-real/57159/2 "2016-08-04T08:00:10Z")

</div>

What doesn't work?  
Do you get an error?  
What is the error?

Please provide more information.

---

<div class="post-metadata">

**Author:** ![kartikvelastic](https://avatars.discourse-cdn.com/v4/letter/k/7ba0ec/32.png) [@kartikvelastic](https://discuss.elastic.co/u/kartikvelastic)\
**Post date:** [August 4, 2016, 10:35am UTC](https://discuss.elastic.co/t/watcher-issue-for-real/57159/3 "2016-08-04T10:35:20Z")

</div>

Well, first allow me to thank you for your interest.  
To generate an email I browse to a non existent page, in the first instance I get an email alert, not so in the second instance. I think it has something to do with the: ctx.payload.hits.total \> 1" which I am introducing only to be alerted for "real" alerts.......

---

<div class="post-metadata">

**Author:** ![tanguy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tanguy/32/6030_2.png) [@tanguy](https://discuss.elastic.co/u/tanguy)\
**Post date:** [August 4, 2016, 2:17pm UTC](https://discuss.elastic.co/t/watcher-issue-for-real/57159/4 "2016-08-04T14:17:51Z")

</div>

Hi,

You should check if the second time your browse to the non existing page a corresponding document has been created in your index.

If so, you can try to run the watch search request to check that the document is correctly found.

If so, you can check in the .watch-history index if the watch has been triggered and what was the result of the execution.

---

<div class="post-metadata">

**Author:** ![kartikvelastic](https://avatars.discourse-cdn.com/v4/letter/k/7ba0ec/32.png) [@kartikvelastic](https://discuss.elastic.co/u/kartikvelastic)\
**Post date:** [August 4, 2016, 3:06pm UTC](https://discuss.elastic.co/t/watcher-issue-for-real/57159/5 "2016-08-04T15:06:12Z")

</div>

Since this code is verbatim from [elastic.co](http://elastic.co), I'd much rather someone tell me if there's something I am doing wrong, the only thing that stands out is that I am using filebeat instead of logstash, but is not "filebeat" a step up...........

any answers will be most appreciated.

---

<div class="post-metadata">

**Author:** ![kartikvelastic](https://avatars.discourse-cdn.com/v4/letter/k/7ba0ec/32.png) [@kartikvelastic](https://discuss.elastic.co/u/kartikvelastic)\
**Post date:** [August 4, 2016, 3:26pm UTC](https://discuss.elastic.co/t/watcher-issue-for-real/57159/6 "2016-08-04T15:26:46Z")

</div>

If I remove:  
"condition" : {  
"script" : "ctx.payload.hits.total \> 1"  
},  
then I constantly get alerted.

This is what I see in Kibana, here I am sending from filebeat to logstash and from logstash to ES:  
[http://pastebin.com/20LZMgku](http://pastebin.com/20LZMgku)

---

<div class="post-metadata">

**Author:** ![kartikvelastic](https://avatars.discourse-cdn.com/v4/letter/k/7ba0ec/32.png) [@kartikvelastic](https://discuss.elastic.co/u/kartikvelastic)\
**Post date:** [August 4, 2016, 6:10pm UTC](https://discuss.elastic.co/t/watcher-issue-for-real/57159/7 "2016-08-04T18:10:03Z")

</div>

figured this one out:  
works with logstash output to ES , I'm using logstash\* as index

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:43pm UTC](https://discuss.elastic.co/t/watcher-issue-for-real/57159/8 "2017-07-06T13:43:49Z")

</div>


