# Watcher with dynamic filter

**URL:** <https://discuss.elastic.co/t/watcher-with-dynamic-filter/175833>\
**Category:** Elasticsearch\
**Created:** [April 8, 2019, 12:31pm UTC](https://discuss.elastic.co/t/watcher-with-dynamic-filter/175833 "2019-04-08T12:31:45Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jesus\_Rodrigo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jesus_rodrigo/32/43168_2.png) [@Jesus\_Rodrigo](https://discuss.elastic.co/u/Jesus_Rodrigo)\
**Post date:** [April 8, 2019, 12:31pm UTC](https://discuss.elastic.co/t/watcher-with-dynamic-filter/175833/1 "2019-04-08T12:31:45Z")

</div>

Hi,

I'm trying to make a Watcher that compares if a number field of a document deviates from the average a percentage.

The mapping the following:

{  
"Datapoint" : "Taller10#Montaje#Skillets#M111#RODILLOS\_LONG#M111R",  
"ACTUAL\_CONSUMPTION" : 80  
}

The problem is that I have to calculate the average of the ACTUAL\_CONSUMPTION field of the logs that have the same value in the field "Datapoint" and not of the rest.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 9, 2019, 9:08am UTC](https://discuss.elastic.co/t/watcher-with-dynamic-filter/175833/2 "2019-04-09T09:08:29Z")

</div>

so you want to group by the value of the `DataPoint` field and then calculate the avg of the `ACTUAL_CONSUMPTION` field?

If you, you should check out aggregations, if you need to this for more than one value of the `DataPoint` field. You could use a `terms` aggregation and inside of that a `avg` agg.

If you only need the avg value of a single value of `DataPoint` then a `filter query` for that value and an `avg` aggregation are sufficient.

---

<div class="post-metadata">

**Author:** ![Jesus\_Rodrigo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jesus_rodrigo/32/43168_2.png) [@Jesus\_Rodrigo](https://discuss.elastic.co/u/Jesus_Rodrigo)\
**Post date:** [April 11, 2019, 9:47am UTC](https://discuss.elastic.co/t/watcher-with-dynamic-filter/175833/3 "2019-04-11T09:47:22Z")

</div>

Hi,

First thank the help, I got the average DataPoint. My problem now is that I do not know how to compare the average with the ACTUAL\_CONSUMPTION.

This is my watcher code:

{  
"trigger": {  
"schedule": {  
"interval": "1d"  
}  
},  
"input": {  
"search": {  
"request": {  
"indices": "consum\*",  
"body": {  
"query": {  
"bool": {  
"filter": {  
"range": {  
"ACTUAL\_CONSUMPTIONst": {  
"from": "now-5d",  
"to": "now"  
}  
}  
}  
}  
},  
"aggs":{  
"datapoint":{  
"terms": {  
"field": "Datapoint.keyword"  
},  
"aggs":{  
"dp\_avg": {  
"avg":{  
"field": "ACTUAL\_CONSUMPTION",  
"script": "\_value_1.1"  
}  
},  
"dp\_actual":{  
"terms": {  
"field": "ACTUAL\_CONSUMPTION"  
}  
}  
}  
}  
}  
}  
}  
}  
},  
"condition":{  
"array\_compare":{  
"ctx.payload.aggregations.datapoint.buckets.dp\_actual.buckets":{  
"path": "key",  
"gte":{  
"value": "{{ctx.payload.aggregations.datapoint.buckets.dp\_avg}}"  
}  
}  
}  
},  
"actions": {  
"log": {  
"logging": {  
"level": "info",  
"text": "_\*\*\* Watcher para informar si un motor tiene una media anómala \*\*\*\*\n"  
}  
}  
}  
}

One part of the response is the following:

"aggregations" : {  
"datapoint" : {  
"doc\_count\_error\_upper\_bound" : 0,  
"sum\_other\_doc\_count" : 0,  
"buckets" : [  
{  
"doc\_count" : 4,  
"dp\_avg" : {  
"value" : 52.25  
},  
"key" : "Taller10#Montaje#Skillets#M11#RODILLOS\_LONG#M11",  
"dp\_actual" : {  
"doc\_count\_error\_upper\_bound" : 0,  
"sum\_other\_doc\_count" : 0,  
"buckets" : [  
{  
"doc\_count" : 2,  
"key" : 40  
},  
{  
"doc\_count" : 1,  
"key" : 50  
},  
{  
"doc\_count" : 1,  
"key" : 60  
}  
]  
}  
}

And I want know that Datapoint has a document with ACTUAL\_CONSUMPTION \> Average\*1.1

Is possible do it??

Thank you!

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 11, 2019, 1:54pm UTC](https://discuss.elastic.co/t/watcher-with-dynamic-filter/175833/4 "2019-04-11T13:54:47Z")

</div>

hey,

you cannot use a `compare` condition for this to properly access the fields, you need to use a `script` condition.

--Alex

---

<div class="post-metadata">

**Author:** ![Jesus\_Rodrigo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jesus_rodrigo/32/43168_2.png) [@Jesus\_Rodrigo](https://discuss.elastic.co/u/Jesus_Rodrigo)\
**Post date:** [April 12, 2019, 9:35am UTC](https://discuss.elastic.co/t/watcher-with-dynamic-filter/175833/5 "2019-04-12T09:35:34Z")

</div>

Thanks you for your help!

I resolved my problem using a script that compare two buckets and return a list with all Datapoint's names.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 10, 2019, 9:35am UTC](https://discuss.elastic.co/t/watcher-with-dynamic-filter/175833/6 "2019-05-10T09:35:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
