# Access to aggregation results using kibana alerting

**URL:** <https://discuss.elastic.co/t/access-to-aggregation-results-using-kibana-alerting/319112>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [November 16, 2022, 4:17pm UTC](https://discuss.elastic.co/t/access-to-aggregation-results-using-kibana-alerting/319112 "2022-11-16T16:17:32Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Youssef\_Mouadden](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/youssef_mouadden/32/113430_2.png) [@Youssef\_Mouadden](https://discuss.elastic.co/u/Youssef_Mouadden)\
**Post date:** [November 16, 2022, 4:17pm UTC](https://discuss.elastic.co/t/access-to-aggregation-results-using-kibana-alerting/319112/1 "2022-11-16T16:17:32Z")

</div>

Hello, I'm facing a problem with Kibana alerting:

1. I defined my query DSL and defined an aggregation
2. I want to access the result of the aggregation returned using the query. Kibana only suggest `{{context.hits}}` but I'm not interested on hits, instead I'm interested on something like `{{context.aggregations}}` but doesn't work. Is it also possible to use the `ctx` like in watchers ?

below the aggregations response :

```auto
#top of response ...
  "aggregations" : {
    "job_status" : {
      "doc_count_error_upper_bound" : 0,
      "sum_other_doc_count" : 0,
      "buckets" : [
        {
          "key" : "value1",
          "doc_count" : 53017
        },
        {
          "key" : "value2",
          "doc_count" : 52977
        },
        {
          "key" : "value3",
          "doc_count" : 40
        }
      ]
    }
  }

```

what i'm looking for:

![image](https://us1.discourse-cdn.com/elastic/original/3X/9/f/9feaed9d6e60dd697ce6759b267878d1991e446d.png)

Youssef  
Thank you

---

<div class="post-metadata">

**Author:** ![Alexandra\_Doak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexandra_doak/32/113239_2.png) [@Alexandra\_Doak](https://discuss.elastic.co/u/Alexandra_Doak)\
**Post date:** [November 16, 2022, 4:45pm UTC](https://discuss.elastic.co/t/access-to-aggregation-results-using-kibana-alerting/319112/2 "2022-11-16T16:45:47Z")

</div>

Hi Youssef,

For an ES query rule type only certain properties of the query are supported, and aggs are not: [Elasticsearch query | Kibana Guide [8.5] | Elastic](https://www.elastic.co/guide/en/kibana/current/rule-type-es-query.html#_define_the_conditions_2). We have an [issue](https://github.com/elastic/kibana/issues/95161) open to work on this, so you can follow along if you would like.

As an alternative to an ES query rule we would recommend using the index threshold rule type, which does a terms aggregation via the grouping over a field.

-Alexi

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 14, 2022, 4:45pm UTC](https://discuss.elastic.co/t/access-to-aggregation-results-using-kibana-alerting/319112/3 "2022-12-14T16:45:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
