# Alert on SUM of field exeeding certain value?

**URL:** <https://discuss.elastic.co/t/alert-on-sum-of-field-exeeding-certain-value/88654>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [June 8, 2017, 5:33am UTC](https://discuss.elastic.co/t/alert-on-sum-of-field-exeeding-certain-value/88654 "2017-06-08T05:33:01Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 8, 2017, 7:49am UTC](https://discuss.elastic.co/t/alert-on-sum-of-field-exeeding-certain-value/88654/2 "2017-06-08T07:49:08Z")

</div>

Hey,

this sounds possible to me. The important part here is to write a proper search query (independent from the watch). The search query needs to do the following

- have a `range` filter in your query that filters from the first of the month until `now`
- have a `term` filter in your query (or a `match` query), that filters for the host you are interested in
- have a `sum` aggregation in your request, that counts up your bytes (use the [sum aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/5.4/search-aggregations-metrics-sum-aggregation.html)

Now you got the correct data (a single aggregation response returning a number), which you can use in the watcher condition to check if it exceeds a threshold.

If it does, send an email - where you can include this exact data.

One last thing: If the IP is dynamic, you could just have an aggregation for the ip address, and then calculate the sum for each IP.

Hope this helps.

--Alex

---

_[View the full topic](https://discuss.elastic.co/t/alert-on-sum-of-field-exeeding-certain-value/88654)._
