# Group Watcher results per host

**URL:** <https://discuss.elastic.co/t/group-watcher-results-per-host/301079>\
**Category:** Elastic Observability\
**Tags:** elastic-stack-alerting\
**Created:** [March 30, 2022, 11:29am UTC](https://discuss.elastic.co/t/group-watcher-results-per-host/301079 "2022-03-30T11:29:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![700grm](https://avatars.discourse-cdn.com/v4/letter/7/3ec8ea/32.png) [@700grm](https://discuss.elastic.co/u/700grm)\
**Post date:** [March 30, 2022, 11:29am UTC](https://discuss.elastic.co/t/group-watcher-results-per-host/301079/1 "2022-03-30T11:29:00Z")

</div>

Hi,

I'm trying to create a watcher that can monitor service sshd.service status on multiple hosts and create aggregated log entry per host every five minutes. instead of creating log entry every time it detects "system.service.state" = "inactive".  
The service status metrics are shipped to elastic by metricbeat agent.

```auto
{
  "trigger": {
    "schedule": {
      "interval": "300s"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "metrics-*"
        ],
        "rest_total_hits_as_int": true,
        "body": {
          "query": {
            "bool": {
              "filter": [
                {
                  "bool": {
                    "should": [
                      {
                        "match_phrase": {
                          "system.service.name": "{{ctx.metadata.service_name}}"
                        }
                      }
                    ],
                    "minimum_should_match": 1
                  }
                },
                {
                  "bool": {
                    "should": [
                      {
                        "match_phrase": {
                          "system.service.state": "inactive"
                        }
                      }
                    ],
                    "minimum_should_match": 1
                  }
                },
                {
                  "range": {
                    "@timestamp": {
                      "from": "now-{{ctx.metadata.window_period}}",
                      "to": "now"
                    }
                  }
                }
              ]
            }
          }
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "gt": 0
      }
    }
  },
  "actions": {
    "log": {
      "logging": {
        "text": "{{ctx.payload._source.host.hostname}}: Service {{ctx.metadata.service_name}} is inactive"
      }
    }
  },
  "metadata": {
    "window_period": "300s",
    "service_name": "sshd.service"
  }
}

```

Expected logging output should look as follow:  
10:00:00 web-server01.local: Service sshd.service is inactive.  
10:00:00 web-server02.local: Service sshd.service is inactive.  
10:00:00 web-server03.local: Service sshd.service is inactive.  
10:05:00 web-server01.local: Service sshd.service is inactive.  
10:05:00 web-server02.local: Service sshd.service is inactive.  
10:05:00 web-server03.local: Service sshd.service is inactive.

My current logging looks as follow:  
10:00:00 web-server01.local: Service sshd.service is inactive.  
10:00:00 web-server01.local: Service sshd.service is inactive.  
10:00:00 web-server01.local: Service sshd.service is inactive.  
10:00:00 web-server01.local: Service sshd.service is inactive.  
10:00:00 web-server01.local: Service sshd.service is inactive.  
10:00:00 web-server01.local: Service sshd.service is inactive.  
10:00:00 web-server01.local: Service sshd.service is inactive.  
10:00:00 web-server01.local: Service sshd.service is inactive.  
....

When throttle period is enabled: "throttle\_period": "5m", it just sends one alert even if the sshd.service inactivity was detected on multiple hosts, for example:  
10:00:00 web-server01.local: Service sshd.service is inactive.

Thanks in advance

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 31, 2022, 11:46am UTC](https://discuss.elastic.co/t/group-watcher-results-per-host/301079/2 "2022-03-31T11:46:47Z")

</div>

You need to iterate through the array of `ctx.payload.hits.hits`. This is on top of my head and worth a try, but I haven't tested it myself

```auto
{{#ctx.payload.hits.hits}}{{_source.host.hostname}}:{{/ctx.payload.hits.hits}}

```

hope this helps. There are a couple of examples at [examples/Alerting at master · elastic/examples · GitHub](https://github.com/elastic/examples/tree/master/Alerting) where you can take a further look.

---

<div class="post-metadata">

**Author:** ![700grm](https://avatars.discourse-cdn.com/v4/letter/7/3ec8ea/32.png) [@700grm](https://discuss.elastic.co/u/700grm)\
**Post date:** [April 6, 2022, 3:09pm UTC](https://discuss.elastic.co/t/group-watcher-results-per-host/301079/3 "2022-04-06T15:09:52Z")

</div>

Thanks @spinscale it worked

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:34am UTC](https://discuss.elastic.co/t/group-watcher-results-per-host/301079/4 "2022-11-04T08:34:54Z")

</div>


