# Aggregation in Watcher

**URL:** <https://discuss.elastic.co/t/aggregation-in-watcher/44670>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [March 17, 2016, 8:32am UTC](https://discuss.elastic.co/t/aggregation-in-watcher/44670 "2016-03-17T08:32:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![gringo](https://avatars.discourse-cdn.com/v4/letter/g/f19dbf/32.png) [@gringo](https://discuss.elastic.co/u/gringo)\
**Post date:** [March 17, 2016, 8:32am UTC](https://discuss.elastic.co/t/aggregation-in-watcher/44670/1 "2016-03-17T08:32:39Z")

</div>

How do I cater for scenario in which an alert will be sent out when a source IP has appeared within a period of time for more than X number of time.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 17, 2016, 12:37pm UTC](https://discuss.elastic.co/t/aggregation-in-watcher/44670/2 "2016-03-17T12:37:54Z")

</div>

Hey,

you could aggregate using a `date histogram` specifying your interval and a `terms` aggregation using `min_doc_count`. It highly depends on your document modeling, so showing an example would be useful.

--Alex

---

<div class="post-metadata">

**Author:** ![spraveenjd](https://avatars.discourse-cdn.com/v4/letter/s/a698b9/32.png) [@spraveenjd](https://discuss.elastic.co/u/spraveenjd)\
**Post date:** [July 21, 2016, 7:36pm UTC](https://discuss.elastic.co/t/aggregation-in-watcher/44670/3 "2016-07-21T19:36:24Z")

</div>

Is there any update on this? Please share with a sample

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:44pm UTC](https://discuss.elastic.co/t/aggregation-in-watcher/44670/4 "2017-07-06T13:44:26Z")

</div>


