# Condition In Watcher

**URL:** <https://discuss.elastic.co/t/condition-in-watcher/110379>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [December 5, 2017, 3:04pm UTC](https://discuss.elastic.co/t/condition-in-watcher/110379 "2017-12-05T15:04:24Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jasonespo](https://avatars.discourse-cdn.com/v4/letter/j/898d66/32.png) [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Post date:** [December 5, 2017, 3:04pm UTC](https://discuss.elastic.co/t/condition-in-watcher/110379/1 "2017-12-05T15:04:24Z")

</div>

```
 "condition": {
            "script": {
              "source": """
              def offenders = [];
                for (def source_ip: ctx.payload.aggregations.source_ip.buckets) {
                 for (def X_ID: source_ip.X_ID.buckets){
                   if (X_ID.doc_count >= 100) & (X_ID.doc_count < 500) {
                        offenders.add([
                          'source_ip': source_ip.key,
                          'X_ID': X_ID.key,
                          'attempts': X_ID.doc_count,
                          'events': X_ID.events,
                          'incident_name': 'XYZ',
                          'status_open' : 'open',
                          'description' : 'X X X X',
                          'incident_severity' : '10',
                          'conditions' : 'PasswordScan_SameDest_ManyAcct, 60mins',
                          'tenantId' : '67a76f18-487b-4033-a3d7-b706a8aa04f0'
                ]);
              }
            
          }
        }
      ctx.payload.offenders = offenders;
      return offenders.size() > 0;
""",
      "lang": "painless"
    }
  },
  "actions": {
    "web_hook": {
      "webhook": {
        "scheme": "https",
        "host": "xxxx",
        "port": 443,
```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [December 6, 2017, 8:48am UTC](https://discuss.elastic.co/t/condition-in-watcher/110379/2 "2017-12-06T08:48:42Z")

</div>

First, please format your messages properly using markdown snippts, this is impossible to read and thus super hard to help.

Second, please also include the search response you are trying to parse, otherwise everything would just be guesswork.

Thanks!

---

<div class="post-metadata">

**Author:** ![Jasonespo](https://avatars.discourse-cdn.com/v4/letter/j/898d66/32.png) [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Post date:** [December 6, 2017, 9:48am UTC](https://discuss.elastic.co/t/condition-in-watcher/110379/3 "2017-12-06T09:48:24Z")

</div>

Hi @spinscale,

Thanks for your response. I have edited the post and formatted it properly (I hope).

The idea of the watch would be to trigger the Webhook if the count of "source\_ip" is greater than or equal to 100 but less than 500.

I know that the rest of the condition works, it's just figuring out how to write the IF condition to trigger correctly.

I hope this makes some more sense

Jason

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [December 6, 2017, 10:22am UTC](https://discuss.elastic.co/t/condition-in-watcher/110379/4 "2017-12-06T10:22:15Z")

</div>

Hey,

you did not show the search response so this is just guessing here. First you can use the `min_doc_count` parameter in the `terms` agg to ensure a minimal count.

you might want to create those offender object as part of a transform, and use the condition only to check if there are buckets with a doc count between 100/500.

This might be it already

```auto
return ctx.payload.aggregations.source_ip.buckets.anyMatch(b -> b.doc_count > 100 && b.doc_count < 5000);

```

Then you can do a transform like this

```auto
return ['offenders' : ctx.payload.aggregations.source_ip.buckets.stream().filter(b -> b.doc_count > 100 && b.doc_count < 500).map(b -> { return [YOUR_LIST_WITH_FIELDS_GOES_HERE] }).collect(Collectors.toList()) ]

```

this was on top of my head, so no guarantees, but should give you an idea.

--Alex

---

<div class="post-metadata">

**Author:** ![Jasonespo](https://avatars.discourse-cdn.com/v4/letter/j/898d66/32.png) [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Post date:** [December 6, 2017, 10:35am UTC](https://discuss.elastic.co/t/condition-in-watcher/110379/5 "2017-12-06T10:35:56Z")

</div>

Thank you I'll have a look at this today 🙂

---

<div class="post-metadata">

**Author:** ![Jasonespo](https://avatars.discourse-cdn.com/v4/letter/j/898d66/32.png) [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Post date:** [December 6, 2017, 10:59am UTC](https://discuss.elastic.co/t/condition-in-watcher/110379/6 "2017-12-06T10:59:32Z")

</div>

The fix was just:

if (X\_ID.doc\_count \>= 100 && X\_ID.doc\_count \< 500).

I just had the wrong syntax I guess

Thanks for the support even with my lack of description

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 3, 2018, 10:59am UTC](https://discuss.elastic.co/t/condition-in-watcher/110379/7 "2018-01-03T10:59:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
