# "compare" : { "ctx.payload.hits.total" : { "gt" : 5}} is not working

**URL:** <https://discuss.elastic.co/t/compare-ctx-payload-hits-total-gt-5-is-not-working/154376>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [October 29, 2018, 5:43am UTC](https://discuss.elastic.co/t/compare-ctx-payload-hits-total-gt-5-is-not-working/154376 "2018-10-29T05:43:50Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![gayathri](https://avatars.discourse-cdn.com/v4/letter/g/838e76/32.png) [@gayathri](https://discuss.elastic.co/u/gayathri)\
**Post date:** [October 29, 2018, 5:43am UTC](https://discuss.elastic.co/t/compare-ctx-payload-hits-total-gt-5-is-not-working/154376/1 "2018-10-29T05:43:51Z")

</div>

Hi Team,

"compare" : { "ctx.payload.hits.total" : { "gt" : 5}} is not working for me while creating the watch alert. We are getting mail alerts if we remove the below block:

"condition" : {  
"compare" : { "ctx.payload.hits.total" : { "gt" : 5}}  
},

tried:

"condition" : {  
"script" : "return ctx.payload.hits.total \> 5"  
}  
as well. But the condition block is not working. PFB, the complete watcher request:

{  
"trigger" : {  
"schedule" : { "interval" : "10s" }  
},  
"input" : {  
"search" : {  
"request" : {  
"body" : {  
"query" : {  
"match" : { "Status": "404" }  
}  
}  
}  
}  
},  
"condition" : {  
"compare" : { "ctx.payload.hits.total" : { "gt" : 5}}  
},  
"actions" : {  
"send\_email" : {  
"email" : {  
"to" : "[mail.dns.com](http://mail.dns.com)",  
"subject" : "Test",  
"body" : " Test"  
}  
}  
}  
}

Thanks,  
Gayathri

---

<div class="post-metadata">

**Author:** ![gayathri](https://avatars.discourse-cdn.com/v4/letter/g/838e76/32.png) [@gayathri](https://discuss.elastic.co/u/gayathri)\
**Post date:** [October 29, 2018, 5:56am UTC](https://discuss.elastic.co/t/compare-ctx-payload-hits-total-gt-5-is-not-working/154376/2 "2018-10-29T05:56:09Z")

</div>

Team,

Could see "ctx.payload.hits.total" is always taking as "0". Kindly help me to get the exact count.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 29, 2018, 10:00am UTC](https://discuss.elastic.co/t/compare-ctx-payload-hits-total-gt-5-is-not-working/154376/3 "2018-10-29T10:00:02Z")

</div>

please include the **full** output of the [execute watch API](https://www.elastic.co/guide/en/elasticsearch/reference/6.4/watcher-api-execute-watch.html) here, this will make debugging a lot easier. Also please include the **full** watch here. And please use proper formatting, as you can just use markdown.

--Alex

---

<div class="post-metadata">

**Author:** ![gayathri](https://avatars.discourse-cdn.com/v4/letter/g/838e76/32.png) [@gayathri](https://discuss.elastic.co/u/gayathri)\
**Post date:** [October 30, 2018, 1:16pm UTC](https://discuss.elastic.co/t/compare-ctx-payload-hits-total-gt-5-is-not-working/154376/4 "2018-10-30T13:16:13Z")

</div>

Hi,

That issue got resolved by adding "search\_type": "query\_then\_fetch" in input.

But having another issue, ctx.payload.hits.total is taking all the hits but not according to the query in the input.

So when we trigger for an error scenario with Success cases it is taking the count for both.

{  
"trigger": {  
"schedule": {  
"interval": "30s"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"index\*"  
],  
"types": [],  
"body": {  
"query": {  
"bool": {  
"must": {  
"match": {  
"message": "status ~ 404"  
}  
},  
"filter": {  
"bool": {  
"must": [  
{  
"range": {  
"@timestamp": {  
"gte": "now-30s"  
}  
}  
}  
]  
}  
}  
}  
}  
}  
}  
}  
},  
"condition": {  
"compare": {  
"ctx.payload.hits.total": {  
"gt": 5  
}  
}  
},  
"actions": {  
"send\_email": {  
"email": {  
"profile": "standard",  
"to": [  
"[mail.domain.com](http://mail.domain.com)"  
],  
"subject": "ALERT",  
"body": {  
"text": "Found {{ctx.payload.hits.total}} errors in the logs "  
}  
}  
}  
}  
}

Kindly help on the above issue.

---

<div class="post-metadata">

**Author:** ![gayathri](https://avatars.discourse-cdn.com/v4/letter/g/838e76/32.png) [@gayathri](https://discuss.elastic.co/u/gayathri)\
**Post date:** [November 2, 2018, 9:58am UTC](https://discuss.elastic.co/t/compare-ctx-payload-hits-total-gt-5-is-not-working/154376/5 "2018-11-02T09:58:07Z")

</div>

Kindly help me on the above

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 30, 2018, 9:58am UTC](https://discuss.elastic.co/t/compare-ctx-payload-hits-total-gt-5-is-not-working/154376/6 "2018-11-30T09:58:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
