# Watcher match "message" issue, How to fix for my watcher?

**URL:** <https://discuss.elastic.co/t/watcher-match-message-issue-how-to-fix-for-my-watcher/165784>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [January 25, 2019, 1:35pm UTC](https://discuss.elastic.co/t/watcher-match-message-issue-how-to-fix-for-my-watcher/165784 "2019-01-25T13:35:55Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![balamelangi](https://avatars.discourse-cdn.com/v4/letter/b/c77e96/32.png) [@balamelangi](https://discuss.elastic.co/u/balamelangi)\
**Post date:** [January 25, 2019, 1:35pm UTC](https://discuss.elastic.co/t/watcher-match-message-issue-how-to-fix-for-my-watcher/165784/1 "2019-01-25T13:35:55Z")

</div>

Hi ,

Some one please let me how to write regex for below log?

```
(84512) rest: Reply-Message := "Failed"

```

I want filter out "Reply-Message := "Failed"". In My watcher I tried below.

```
{ "regexp": { "message": "Reply-Message * Failed" } }
{ "regexp": { "message": "Reply-Message * .Failed." } }
{ "match": { "message": "Reply-Message := Failed" } }
{ "match": { "message": "Reply-Message := 'Failed' " } }

```

And also how to filter message particular logfile?

"bool": {  
"should": [  
{  
"regexp": {  
"message": "Reply-Message \* .Failed."  
}  
},  
{  
"match": {  
"source": "/var/log/radius.log"  
}  
}  
],  
"minimum\_should\_match": 2,  
"filter": {  
"range": {  
"@timestamp": {  
"from": "now-30s",  
"to": "now"  
}  
}  
}  
}

Please some one help me.

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 22, 2019, 1:36pm UTC](https://discuss.elastic.co/t/watcher-match-message-issue-how-to-fix-for-my-watcher/165784/2 "2019-02-22T13:36:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
