# Aggregate watchers over multiple fields for term aggregation

**URL:** <https://discuss.elastic.co/t/aggregate-watchers-over-multiple-fields-for-term-aggregation/143449>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [August 8, 2018, 8:01am UTC](https://discuss.elastic.co/t/aggregate-watchers-over-multiple-fields-for-term-aggregation/143449 "2018-08-08T08:01:18Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![sahil\_sawhney](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sahil_sawhney/32/88932_2.png) [@sahil\_sawhney](https://discuss.elastic.co/u/sahil_sawhney)\
**Post date:** [August 8, 2018, 8:01am UTC](https://discuss.elastic.co/t/aggregate-watchers-over-multiple-fields-for-term-aggregation/143449/1 "2018-08-08T08:01:19Z")

</div>

I have a scenario where i want to aggregate my result with the combination of 2 fields value.  
Following is the json of index on which my watcher targets

> ```
> {
> "_index": ".monitoring-es-6-2018.08.08",
> "_type": "doc",
> "_id": "AWUYhYcMSsCneLp5ymFB",
> "_version": 1,
> "_score": null,
> "_source": {
> "cluster_uuid": "If7i-iVaQsWQvxjV9J1Atg",
> "timestamp": "2018-08-08T07:52:06.733Z",
> "type": "node_stats",
> "source_node": {
> "uuid": "iu7bnPFDTWeqXAjdfTIrkg",
> "host": "data-1-node.elastic.autoip.dcos.thisdcos.directory",
> "transport_address": "16.234.226.205:1026",
> "ip": "16.234.226.205",
> "name": "data-1-node",
> "attributes": {
> "ml.max_open_jobs": "10",
> "ml.enabled": "true"
> }
> }
> }
> 
> ```

Following is my watcher body

> ```
> {
> "trigger": {
> "schedule": {
> "interval": "1m"
> }
> },
> "input": {
> "search": {
> "request": {
> "indices": [
> ".monitoring-es-6-*"
> ],
> "body": {
> "size" : 0,
> "query": {
> "bool": {
> "filter": {
> "range": {
> "timestamp": {
> "gte": "now-2m",
> "lte": "now"
> }
> }
> }
> }
> },
> "aggs": {
> "minutes": {
> "date_histogram": {
> "field": "timestamp",
> "interval": "1m"
> },
> "aggs": {
> "nodes": {
> "terms": {
> "field": "source_node.ip",
> "order": {
> "free_disk": "desc"
> }
> },
> "aggs": {
> "free_disk": {
> "avg": {
> "field": "node_stats.fs.total.free_in_bytes"
> }
> },
> "total_disk": {
> "avg": {
> "field": "node_stats.fs.total.total_in_bytes"
> }
> }
> }
> }
> }
> }
> }
> }
> }
> }
> },
> "condition": {
> "script": "if (ctx.payload.aggregations.minutes.buckets.size() == 0) return false; def latest = ctx.payload.aggregations.minutes.buckets.get(ctx.payload.aggregations.minutes.buckets.size() - 1); def node = latest.nodes.buckets[0]; def status = (node != null && node.free_disk != null && node.free_disk.value / 1000000000L <= 7000); return status;"
> },
> "actions": {
> "send_email": { 
> "transform": {
> "script": "def latest = ctx.payload.aggregations.minutes.buckets.get(ctx.payload.aggregations.minutes.buckets.size() - 1); def result = latest.nodes.buckets.stream().filter(it -> it != null && it.free_disk != null && it.free_disk.value > 0).filter(it -> (float) it.free_disk.value / it.total_disk.value * 100 < 100).collect(Collectors.toList()); return result;"
> },
> "email": {
> "to": "sahil.sawhney@knoldus.in", 
> "subject": "Watcher Notification - LOW FREE HARD DISK ON SATURN ES",
> "body": "Nodes with LOW FREE HARD DISK (BELOW 100):\n\n{{#ctx.payload._value}}\"{{key}}\" - FREE HARD DISK is {{free_disk.value}}%\n{{/ctx.payload._value}}"
> }
> }
> }
> }
> 
> ```

Here i want am doing the aggregation over the field 'source\_node.ip' but i want the key formed to be something like 'source\_node.ip + source\_node.name'

I had tried something like

```
"aggs": {
                "nodes": {
                  "terms": {
                    "script": "docs['source_node.ip'] + docs['source_node.name']",
                    "order": {
                      "free_disk": "desc"
                    }
                  },
                  .
                  . // sub aggregations
                  .
                 }
              }

```

But this results in error that no field source\_node found  
How can i achieve the above mentioned scenario ?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 8, 2018, 8:18am UTC](https://discuss.elastic.co/t/aggregate-watchers-over-multiple-fields-for-term-aggregation/143449/2 "2018-08-08T08:18:19Z")

</div>

use `doc` instead of `docs` and make sure you are accessing a field that is not analyzed. See this example

```auto
DELETE foo

PUT foo/doc/1?refresh=
{
  "source_node": {
    "ip": "8.8.8.8",
    "name": "node_name"
  }
}

GET foo/doc/_search
{
  "size": 0,
  "aggs": {
    "scripted": {
      "terms": {
        "script": {
          "source" : "doc['source_node.name.keyword'].value + '_-_' + doc['source_node.ip.keyword'].value"
        }, 
        "size": 10
      }
    }
  }
}

```

hope this helps

---

<div class="post-metadata">

**Author:** ![sahil\_sawhney](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sahil_sawhney/32/88932_2.png) [@sahil\_sawhney](https://discuss.elastic.co/u/sahil_sawhney)\
**Post date:** [August 8, 2018, 10:04am UTC](https://discuss.elastic.co/t/aggregate-watchers-over-multiple-fields-for-term-aggregation/143449/3 "2018-08-08T10:04:55Z")

</div>

@spinscale  
i did tried the solution you suggested but it fails with following message  
`failed to execute watch input`  
And the reason for failure is  
`SearchPhaseExecutionException[all shards failed]; nested: ScriptException[compile error]; nested: IllegalArgumentException[Variable [source_node] is not defined.];`  
The error is same as before

---

<div class="post-metadata">

**Author:** ![sahil\_sawhney](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sahil_sawhney/32/88932_2.png) [@sahil\_sawhney](https://discuss.elastic.co/u/sahil_sawhney)\
**Post date:** [August 24, 2018, 10:20am UTC](https://discuss.elastic.co/t/aggregate-watchers-over-multiple-fields-for-term-aggregation/143449/4 "2018-08-24T10:20:52Z")

</div>

Any pointers on this @spinscale ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 21, 2018, 10:20am UTC](https://discuss.elastic.co/t/aggregate-watchers-over-multiple-fields-for-term-aggregation/143449/5 "2018-09-21T10:20:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
