# Xpack\_machinelearning\_watch

**URL:** <https://discuss.elastic.co/t/xpack-machinelearning-watch/87543>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-machine-learning\
**Created:** [May 30, 2017, 9:43am UTC](https://discuss.elastic.co/t/xpack-machinelearning-watch/87543 "2017-05-30T09:43:49Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [May 30, 2017, 9:43am UTC](https://discuss.elastic.co/t/xpack-machinelearning-watch/87543/1 "2017-05-30T09:43:49Z")

</div>

Hi All,

We are using Xpack and new features with machine learning, am trying to set a watch for initial\_record\_score exceeds 70 , I need a trigger. but the execution fails ,please anyone let me know if am making any mistakes,i have gone through watch documentation still couldnt figure it out

{  
"trigger": {  
"schedule": {  
"interval": "30m"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
".ml-anomalies-\*"  
],  
"types": [],  
"body": {  
"size": 0,  
"query": {  
"range": {  
"initial\_record\_score": {  
"gte": 70  
},  
"@timestamp": {  
"from": "now-2h",  
"to": "now"  
}  
}  
}  
}  
}  
}  
},  
"condition": {  
"compare": {  
"ctx.payload.hits.total": {  
"gte": 0  
}  
}  
},  
"actions": {  
"send\_email": {  
"email": {  
"profile": "standard",  
"to": [  
"test@test.dk"  
],  
"subject": "Anamolydetection",  
"body": {  
"text": "Anamolydetection"  
}  
}  
}  
}  
}

Thanks in advance,  
Raj

---

<div class="post-metadata">

**Author:** ![sophie\_chang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sophie_chang/32/18008_2.png) [@sophie\_chang](https://discuss.elastic.co/u/sophie_chang)\
**Post date:** [May 31, 2017, 11:33am UTC](https://discuss.elastic.co/t/xpack-machinelearning-watch/87543/2 "2017-05-31T11:33:40Z")

</div>

Hi Raj

There was a recent excellent blog article which describes how to debug a Watch. [https://www.elastic.co/blog/watching-the-watches-writing-debugging-and-testing-watches](https://www.elastic.co/blog/watching-the-watches-writing-debugging-and-testing-watches)

Can I ask what errors you are seeing?

Without having looked at the JSON in detail, I see that the query is looking at `initial_record_score`. We are still working on documentation for how ML and Watcher integrate, but just to say that alerting off `anomaly_score` is the recommended best practice. The `anomaly_score` is the aggregated score for the analysis bucket. If you have very high cardinality data, then there could be 10's or 100's of records with a high `record_score`, therefore this is useful information when investigating, but not alerting.

Regards  
Sophie

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [June 1, 2017, 12:01pm UTC](https://discuss.elastic.co/t/xpack-machinelearning-watch/87543/3 "2017-06-01T12:01:29Z")

</div>

Hi Sophie,

Thanks alot for the reply 🙂

Am getting this message

```
"type": "search",
  "status": "failure",
  "reason": "ParsingException[[range] query doesn't support multiple fields, found [initial_record_score] and [@timestamp]]",
  "search": {
    "request": {
      "search_type": "query_then_fetch", 

```

Thanks,  
Raj

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [June 1, 2017, 5:57pm UTC](https://discuss.elastic.co/t/xpack-machinelearning-watch/87543/4 "2017-06-01T17:57:30Z")

</div>

Raj,

Indeed, the range filter can only handle one field at a time. In order to filter on more than one field, you'll need separate statements. See my example below:

```json
{
    "trigger" : {
      "schedule" : { "interval" : "5m" } 
    },
    "input" : {
      "search" : {
        "request" : {
          "indices" : [".ml-anomalies-myjob"],
          "body" : {
            "query": {
              "bool": {
                "filter": [
                    { "range" : { "timestamp" : { "gte": "now-10m" } } },
                    { "term" : { "result_type" : "bucket" } },
                    { "range" : {"anomaly_score" : {"gte" : "75"}}}
  
                ]
              }
            }
          }
      }
    }
   },
    "condition" : { 
      "compare" : { "ctx.payload.hits.total" : { "gt" : 0 }}
    },
    "actions" : {
      "log" : {
        "logging" : {
          "text" : "Anomalies:\n{{#ctx.payload.hits.hits}}score={{_source.anomaly_score}} at time={{_source.timestamp}}\n{{/ctx.payload.hits.hits}}"
        }
      }
    }    
  }

```

Please note a few things:

- the index name of `.ml-anomalies-myjob` is an pre-built alias for the anomaly results index for a job named "myjob"
- It's best to limit the search to `result_type:bucket` per Sophie's suggestion above
- Notice the two different `range` statements, one for `timestamp` and one for `anomaly_score`
- Used the field `timestamp`, not `@timestamp`

Example output from this would be:

```auto
Anomalies:
score=90.7 at time=1455034500000

```

Hope that helps

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [June 1, 2017, 8:42pm UTC](https://discuss.elastic.co/t/xpack-machinelearning-watch/87543/5 "2017-06-01T20:42:40Z")

</div>

You guys are awesome for explaining with an example that makes lot of difference ,

Thanks alot both of you Sophie and Rich 🙂

---

<div class="post-metadata">

**Author:** ![Ryan\_Groten](https://avatars.discourse-cdn.com/v4/letter/r/f9ae1b/32.png) [@Ryan\_Groten](https://discuss.elastic.co/u/Ryan_Groten)\
**Post date:** [June 9, 2017, 3:48pm UTC](https://discuss.elastic.co/t/xpack-machinelearning-watch/87543/6 "2017-06-09T15:48:41Z")

</div>

Hi Sophie, just curious if the ML/Watcher integration documentation is available yet? I don't see anything in the docs currently.

---

<div class="post-metadata">

**Author:** ![sophie\_chang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sophie_chang/32/18008_2.png) [@sophie\_chang](https://discuss.elastic.co/u/sophie_chang)\
**Post date:** [June 12, 2017, 8:41am UTC](https://discuss.elastic.co/t/xpack-machinelearning-watch/87543/7 "2017-06-12T08:41:14Z")

</div>

Hi @Ryan_Groten, please bear with us - this will likely land as a blog first within the next few weeks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 10, 2017, 8:42am UTC](https://discuss.elastic.co/t/xpack-machinelearning-watch/87543/8 "2017-07-10T08:42:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
