# Alerting on compared aggregations

**URL:** <https://discuss.elastic.co/t/alerting-on-compared-aggregations/348075>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [November 27, 2023, 6:11pm UTC](https://discuss.elastic.co/t/alerting-on-compared-aggregations/348075 "2023-11-27T18:11:38Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![GD\_DV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gd_dv/32/142454_2.png) [@GD\_DV](https://discuss.elastic.co/u/GD_DV)\
**Post date:** [November 27, 2023, 6:11pm UTC](https://discuss.elastic.co/t/alerting-on-compared-aggregations/348075/1 "2023-11-27T18:11:38Z")

</div>

Hello folks, I'm hoping to get a little insight from experienced folks as to how to approach my problem.

I have a bunch of devices creating documents in my index. Each document is identified as belonging to a particular device with the hostname.keyword field. All devices create a document every 5 minutes.

What I'm trying to do is create something that will watch this index and send an alarm if any given device stops sending data, and another alarm when it starts sending data again after stopping.

I've come up with the following query, this creates a top-level aggregation per hostname, followed by sub-aggregations for 2 time periods. By comparing the doc\_counts of these sub-aggregations, I should be able to determine if something went down or came back up.

```auto
POST my-index/_search?size=0
{
  "query": {
    "bool": {
      "filter": [
        {
          "match": {
            "webhook": "heartbeat"
          }
        },
        {
         "range": {
              "@timestamp": {
                "gte": "now-25m",
                "lte": "now-5m"
              }
            }
        }
      ]
    }
  },
  "aggs": {
    "hostname": {
      "terms": {
        "field": "hostname.keyword"
      },
      "aggs": {
        "beforeChunk": {
          "filter": {
            "range": {
              "@timestamp": {
                "gte": "now-25m",
                "lte": "now-15m"
              }
            }
          }
        },
        "afterChunk": {
          "filter": {
            "range": {
              "@timestamp": {
                "gte": "now-15m",
                "lte": "now-5m"
              }
            }
          }
        }
      }
    }
  }
}

```

Here's the relevant part of the response (truncated down to two devices)

```auto
"aggregations": {
    "hostname": {
      "doc_count_error_upper_bound": 0,
      "sum_other_doc_count": 0,
      "buckets": [
        {
          "key": "hostname-1",
          "doc_count": 4,
          "beforeChunk": {
            "doc_count": 2
          },
          "afterChunk": {
            "doc_count": 2
          }
        },
        {
          "key": "hostname-2",
          "doc_count": 4,
          "beforeChunk": {
            "doc_count": 2
          },
          "afterChunk": {
            "doc_count": 2
          }
        }
      ]
    }
  }

```

I suppose I will need to do this in a watcher, but I'm honestly not sure where to begin. I am still pretty new to Elastic. Any guidance you could provide would be appreciated.

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [November 27, 2023, 8:51pm UTC](https://discuss.elastic.co/t/alerting-on-compared-aggregations/348075/2 "2023-11-27T20:51:06Z")

</div>

Take a look at this example Watch that does something similar. They key is the use of the bucket\_selector aggregation to list (in this case) indices that were getting data 2 days ago, but not in the last 1 day

> <https://gist.github.com/richcollier/32d291d9b960d903864113a211dbbb23>

Note the example uses the `_execute` endpoint which doesn't permanently define the Watch, just allows a debug, one-shot execution of it

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 25, 2023, 8:51pm UTC](https://discuss.elastic.co/t/alerting-on-compared-aggregations/348075/3 "2023-12-25T20:51:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
