# Watcher Kibana : How can i use double condition in a "compare"

**URL:** <https://discuss.elastic.co/t/watcher-kibana-how-can-i-use-double-condition-in-a-compare/170999>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [March 5, 2019, 10:56pm UTC](https://discuss.elastic.co/t/watcher-kibana-how-can-i-use-double-condition-in-a-compare/170999 "2019-03-05T22:56:02Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![hmezoughi](https://avatars.discourse-cdn.com/v4/letter/h/e79b87/32.png) [@hmezoughi](https://discuss.elastic.co/u/hmezoughi)\
**Post date:** [March 5, 2019, 10:56pm UTC](https://discuss.elastic.co/t/watcher-kibana-how-can-i-use-double-condition-in-a-compare/170999/1 "2019-03-05T22:56:02Z")

</div>

I want to compare two conditon to send an alert mail

My exemple :

```
  "query": {
    "bool": {
      "must": [
        {
          "range": {
            "AUDITTIMESTAMP": {
              "gte": "now-15m"
            }
          }
        }
      ],
      "filter": [
        {
          "term": {
            "SERVICE_NAME": "my-service-name"
          }
        },
        {
          "term": {
            "STATE": "ERROR"
          }
        }
      ],
      "should": [],
      "must_not": []
    }
  }
}

```

}  
}  
},  
"condition": {  
"compare": {  
"ctx.payload.hits.total": {  
"gte": 10  
}  
}  
},  
"actions": {  
"send\_email": {  
"email": {  
"profile": "standard"

i want to add an another condition (total error \>10) and a least 50 totals hits already on the last 15 minutes to firing alert ?

Thx

---

<div class="post-metadata">

**Author:** ![andres-perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andres-perez/32/136461_2.png) [@andres-perez](https://discuss.elastic.co/u/andres-perez)\
**Post date:** [March 6, 2019, 5:55pm UTC](https://discuss.elastic.co/t/watcher-kibana-how-can-i-use-double-condition-in-a-compare/170999/2 "2019-03-06T17:55:31Z")

</div>

Hi,

I don't understand well the extra condition you want to add

> [@hmezoughi](#):
>
> at least 50 totals hits already on the last 15 minutes

Your current input query looks for `"ERROR"` value for the field `"STATE"` from the last 15 minutes.

If you want to look for different data in the same watch, you can use [chain inputs](https://www.elastic.co/guide/en/elastic-stack-overview/current/input-chain.html).

There is a thread in this forum with a full example: [A watch alert example based on two different searches using CHAIN input and Painless script condition](https://discuss.elastic.co/t/a-watch-alert-example-based-on-two-different-searches-using-chain-input-and-painless-script-condition/113829)

For example, you can set

- One search input named _"errors"_ with your current query
- Another one named _"all\_messages"_ with a similar query minus the `"ERROR"` filter to get all messages in the last 15 minutes.

Customize them with your desired searches.

Then, you may use a [script condition](https://www.elastic.co/guide/en/elastic-stack-overview/current/condition-script.html) to be able to evaluate two conditions.

Something like:

```
  "condition": {
    "script": {
      "source": "return ctx.payload.errors.hits.total >= 15 && ctx.payload.all_messages.hits.total >= 50",
      "lang": "painless"
    }

```

---

<div class="post-metadata">

**Author:** ![hmezoughi](https://avatars.discourse-cdn.com/v4/letter/h/e79b87/32.png) [@hmezoughi](https://discuss.elastic.co/u/hmezoughi)\
**Post date:** [March 6, 2019, 10:00pm UTC](https://discuss.elastic.co/t/watcher-kibana-how-can-i-use-double-condition-in-a-compare/170999/3 "2019-03-06T22:00:48Z")

</div>

Hello andres-perez,

Thank you very very much, i customize your example condition and it work 🙂

Excuse me for my english if the presentation of my problem was not very clear (i am french 😉 )

---

<div class="post-metadata">

**Author:** ![hmezoughi](https://avatars.discourse-cdn.com/v4/letter/h/e79b87/32.png) [@hmezoughi](https://discuss.elastic.co/u/hmezoughi)\
**Post date:** [March 7, 2019, 11:16am UTC](https://discuss.elastic.co/t/watcher-kibana-how-can-i-use-double-condition-in-a-compare/170999/4 "2019-03-07T11:16:34Z")

</div>

Last question : how to tranform ctx.payload.error.hits.totals to calculate the error percentage from the total number, for example, I accept 10% error on total calls

---

<div class="post-metadata">

**Author:** ![andres-perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andres-perez/32/136461_2.png) [@andres-perez](https://discuss.elastic.co/u/andres-perez)\
**Post date:** [March 7, 2019, 4:46pm UTC](https://discuss.elastic.co/t/watcher-kibana-how-can-i-use-double-condition-in-a-compare/170999/5 "2019-03-07T16:46:54Z")

</div>

You can operate directly with the values.

If you just use the integrated editor in kibana (which enforces the 1-line limit of JSON), you can write multiple statements separated with semicolons.

A condition roughly like `((errors * 100) / total_messages) >= 10` should be enough; you have to verify the proper syntax, operators, maybe data types... this is not a literal code example.

If you want to save the resulting percentage value, you can add elements to the [watch execution context](https://www.elastic.co/guide/en/elastic-stack-overview/current/how-watcher-works.html#watch-execution-context) object whenever you use painless script.

The `ctx.vars` would be a good place to set new variables.

Again, a _pseudocode-ish_ example

```auto
   "script": {
      "source": "ctx.vars.error_percentage = ctx.payload.errors.hits.total * 100 / ctx.payload.all_messages.hits.total; more statements separated by semicolons"

```

If this is part of the `condition`, then it must finish with a suitable evaluation:

```auto
"source": "...previous statements; return ctx.vars.error_percentage >= 10"

```

This way, you will be able to use this value later in the `actions` section (e.g. an email): `"bla bla bla the system has registered {{ctx.vars.error_percentage}} % error rate"`

_J'espère que ça vous aidera_ 🙂

---

<div class="post-metadata">

**Author:** ![hmezoughi](https://avatars.discourse-cdn.com/v4/letter/h/e79b87/32.png) [@hmezoughi](https://discuss.elastic.co/u/hmezoughi)\
**Post date:** [March 7, 2019, 4:58pm UTC](https://discuss.elastic.co/t/watcher-kibana-how-can-i-use-double-condition-in-a-compare/170999/6 "2019-03-07T16:58:04Z")

</div>

Thx Andreas,

I write like this ??

"condition": {  
"script": {  
"source": "return (ctx.payload.error\_15m.hits.total \* 100 / ctx.payload.all\_15m.hits.total ) \>= 10 && ctx.payload.all\_15m.hits.total \> 2000",  
"lang": "painless"  
}  
},

---

<div class="post-metadata">

**Author:** ![hmezoughi](https://avatars.discourse-cdn.com/v4/letter/h/e79b87/32.png) [@hmezoughi](https://discuss.elastic.co/u/hmezoughi)\
**Post date:** [March 7, 2019, 10:43pm UTC](https://discuss.elastic.co/t/watcher-kibana-how-can-i-use-double-condition-in-a-compare/170999/7 "2019-03-07T22:43:45Z")

</div>

Awesome guy, it work for me !

My final version 😄

"condition": {  
"script": {  
"source": "ctx.vars.error\_percentage = ctx.payload.error\_15m.hits.total \* 100 / ctx.payload.all\_15m.hits.total; return ctx.vars.error\_percentage \>= 10 && ctx.payload.all\_15m.hits.total \> 2000",  
"lang": "painless"  
}  
},  
"actions": {  
"send\_email": {  
"email": {  
"profile": "standard",  
"to": [  
"username@domain.fr"  
],  
"subject": "[Kibana - Alert - Grave] Test envoi alerte si % d'erreur \> 10",  
"body": {  
"html": "Détection sur les 15 dernieres minutes de 10 % d'erreur ({{ctx.vars.error\_percentage}} % error )   
{{ctx.payload.error\_15m.hits.total}} erreurs sur un TOTAL de : {{ctx.payload.all\_15m.hits.total}} appels Merci de vérifier sur le Dashboard QOS "  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 4, 2019, 10:43pm UTC](https://discuss.elastic.co/t/watcher-kibana-how-can-i-use-double-condition-in-a-compare/170999/8 "2019-04-04T22:43:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
