# Watcher send mail if it doesn't meet the requirement

**URL:** <https://discuss.elastic.co/t/watcher-send-mail-if-it-doesnt-meet-the-requirement/177973>\
**Category:** Kibana\
**Created:** [April 23, 2019, 7:51am UTC](https://discuss.elastic.co/t/watcher-send-mail-if-it-doesnt-meet-the-requirement/177973 "2019-04-23T07:51:13Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![yasin](https://avatars.discourse-cdn.com/v4/letter/y/9e8a1a/32.png) [@yasin](https://discuss.elastic.co/u/yasin)\
**Post date:** [April 23, 2019, 7:51am UTC](https://discuss.elastic.co/t/watcher-send-mail-if-it-doesnt-meet-the-requirement/177973/1 "2019-04-23T07:51:13Z")

</div>

Dear Team,

I want to setup a advanced watcher with:  
If it doesn't get the total hits or text message then it needs to send a mail(if possible within a timeframe).  
Please help me out with this one.

---

<div class="post-metadata">

**Author:** ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)\
**Post date:** [April 24, 2019, 6:28pm UTC](https://discuss.elastic.co/t/watcher-send-mail-if-it-doesnt-meet-the-requirement/177973/2 "2019-04-24T18:28:23Z")

</div>

Hello Yasin

You can do this by using threshold watches with our watcher feature:

 ![46%20PM](https://us1.discourse-cdn.com/elastic/original/3X/0/9/09514385f8118e55a524032e155c00b131e65ce8.png)

You need the default distro of elasticsearch with a valid platinum/gold license after your trial expires to use watcher.

Thanks,  
Bhavya

---

<div class="post-metadata">

**Author:** ![yasin](https://avatars.discourse-cdn.com/v4/letter/y/9e8a1a/32.png) [@yasin](https://discuss.elastic.co/u/yasin)\
**Post date:** [April 25, 2019, 9:40am UTC](https://discuss.elastic.co/t/watcher-send-mail-if-it-doesnt-meet-the-requirement/177973/3 "2019-04-25T09:40:16Z")

</div>

Dear Bhavya

Would first like to thank you for your reply.  
When checking the screenshot i've added but i want to do more such as:  
GROUPED OVER top 500'cam.routeid.keyword' --\> "1.incoming OFP" only and specify for a specific customer. Is that possible?

Note: Can we add slack query in advanced watcher place?

 ![17](https://us1.discourse-cdn.com/elastic/original/3X/6/b/6b06535be26c7f785a6fd05c5f21a64176368bc7.png)

---

<div class="post-metadata">

**Author:** ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)\
**Post date:** [April 25, 2019, 10:35am UTC](https://discuss.elastic.co/t/watcher-send-mail-if-it-doesnt-meet-the-requirement/177973/4 "2019-04-25T10:35:18Z")

</div>

@sebastien can we please get some help here?

I don't think we can filter on a single value yet in matching conditions here?  
You can definitely add slack actions on watcher so you will get watch notifications.

Thanks,  
Bhavya

---

<div class="post-metadata">

**Author:** ![sebastien](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sebastien/32/36119_2.png) [@sebastien](https://discuss.elastic.co/u/sebastien)\
**Post date:** [April 26, 2019, 7:52am UTC](https://discuss.elastic.co/t/watcher-send-mail-if-it-doesnt-meet-the-requirement/177973/5 "2019-04-26T07:52:26Z")

</div>

Hello,

Yes I don't think it is not possible to filter on a single value, @Bill_McConaghy can you confirm this?

Cheers

---

<div class="post-metadata">

**Author:** ![yasin](https://avatars.discourse-cdn.com/v4/letter/y/9e8a1a/32.png) [@yasin](https://discuss.elastic.co/u/yasin)\
**Post date:** [April 26, 2019, 11:53am UTC](https://discuss.elastic.co/t/watcher-send-mail-if-it-doesnt-meet-the-requirement/177973/6 "2019-04-26T11:53:23Z")

</div>

Dear Team,

Trying to figure out in putting it in query but still failed:

```
      "aggs": {
        "bucketAgg": {
          "terms": {
            "field": "camel.routeId.keyword",
            "size": 500,
            "order": {
              "_count": "desc"
            }
          }

```

So in field i'm trying to add a value and changed to :

```
  },
      "aggs": {
        "bucketAgg": {
          "terms": {
            "field": "camel.routeId.keyword:3a. EFF FTP download",
            "size": 500,
            "order": {
              "_count": "desc"
            }

```

Maybe i can use the prefix?:  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-prefix-query.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-prefix-query.html)

---

<div class="post-metadata">

**Author:** ![yasin](https://avatars.discourse-cdn.com/v4/letter/y/9e8a1a/32.png) [@yasin](https://discuss.elastic.co/u/yasin)\
**Post date:** [April 29, 2019, 12:18pm UTC](https://discuss.elastic.co/t/watcher-send-mail-if-it-doesnt-meet-the-requirement/177973/7 "2019-04-29T12:18:36Z")

</div>

Please help me out with this one.

---

<div class="post-metadata">

**Author:** ![yasin](https://avatars.discourse-cdn.com/v4/letter/y/9e8a1a/32.png) [@yasin](https://discuss.elastic.co/u/yasin)\
**Post date:** [May 15, 2019, 11:48am UTC](https://discuss.elastic.co/t/watcher-send-mail-if-it-doesnt-meet-the-requirement/177973/8 "2019-05-15T11:48:42Z")

</div>

Dear Team,

Any suggestions?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 12, 2019, 11:48am UTC](https://discuss.elastic.co/t/watcher-send-mail-if-it-doesnt-meet-the-requirement/177973/9 "2019-06-12T11:48:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
