# Watcher Queries

**URL:** <https://discuss.elastic.co/t/watcher-queries/44465>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [March 15, 2016, 5:29pm UTC](https://discuss.elastic.co/t/watcher-queries/44465 "2016-03-15T17:29:20Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![piyush](https://avatars.discourse-cdn.com/v4/letter/p/ecb155/32.png) [@piyush](https://discuss.elastic.co/u/piyush)\
**Post date:** [March 15, 2016, 5:29pm UTC](https://discuss.elastic.co/t/watcher-queries/44465/1 "2016-03-15T17:29:20Z")

</div>

Hi,  
Please suggest where can i find sample queries on beats (topbeat,packetbeat, filebeat (message)). I am looking for cpu,disk, 4xx etc. alerts.

Regards...

---

<div class="post-metadata">

**Author:** ![piyush](https://avatars.discourse-cdn.com/v4/letter/p/ecb155/32.png) [@piyush](https://discuss.elastic.co/u/piyush)\
**Post date:** [March 15, 2016, 6:39pm UTC](https://discuss.elastic.co/t/watcher-queries/44465/2 "2016-03-15T18:39:10Z")

</div>

I tried this, but it giving me used\_p = 0 records as well:

get topbeat-2016.03.15/filesystem/\_search  
{  
"query": {  
{ "match\_all": {} },  
"filter":  
{  
"fs":  
{"range" :  
"used\_p": { "value" : 0.56}  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![piyush](https://avatars.discourse-cdn.com/v4/letter/p/ecb155/32.png) [@piyush](https://discuss.elastic.co/u/piyush)\
**Post date:** [March 16, 2016, 1:01am UTC](https://discuss.elastic.co/t/watcher-queries/44465/3 "2016-03-16T01:01:23Z")

</div>

Hi Team,  
I understand the query logic i was working will not work as it is with watcher. Here is how i configured a test alert but didn't received any email yet. (i tested with a sample, email is working)

\*i found lot of records where fs.used\_p=0, hence put that condition for trial.

put \_watcher/watch/fs\_disk\_watch\_top  
{  
"actions" : {  
"email\_admin" : {  
"email" : {  
"body" : "{{ctx.watch\_id}} executed with {{ctx.payload.hits.total}} hits",  
"subject" : "{{ctx.watch\_id}} executed",  
"to" : "'abc@xyz.com'"  
}  
}  
},  
"condition" : {  
"compare" : {  
"ctx.payload.hits.total" : {  
"gt" : 0  
}  
}  
},  
"input" : {  
"search" : {  
"request" : {  
"body" : {  
"query" : {  
"match" : {  
"fs.used\_p" : "0"  
}  
}  
},  
"indices" : ["topbeat-2016.03.16"]  
}  
}  
},  
"trigger" : {  
"schedule" : {  
"interval" : "60s"  
}  
}  
}

Regards...

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 17, 2016, 12:26pm UTC](https://discuss.elastic.co/t/watcher-queries/44465/4 "2016-03-17T12:26:03Z")

</div>

Hey,

if a search does not return any result, then a watch is also never going to be triggered.

Also, please take some time and format the JSON you got using markdown, so it is easier to follow your steps. In addition dont forget to check your log files. And try to execute the watch manually by executing the Execute Watch API, allowing you to see the single steps of an execution and find out what is wrong.

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:46pm UTC](https://discuss.elastic.co/t/watcher-queries/44465/5 "2017-07-06T13:46:25Z")

</div>


