# How to iterate through aggregation buckets and send mail corresponding to each bucket using watcher action

**URL:** <https://discuss.elastic.co/t/how-to-iterate-through-aggregation-buckets-and-send-mail-corresponding-to-each-bucket-using-watcher-action/312474>\
**Category:** Kibana\
**Created:** [August 19, 2022, 2:11pm UTC](https://discuss.elastic.co/t/how-to-iterate-through-aggregation-buckets-and-send-mail-corresponding-to-each-bucket-using-watcher-action/312474 "2022-08-19T14:11:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bhavya](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavya/32/45679_2.png) [@bhavya](https://discuss.elastic.co/u/bhavya)\
**Post date:** [August 19, 2022, 2:11pm UTC](https://discuss.elastic.co/t/how-to-iterate-through-aggregation-buckets-and-send-mail-corresponding-to-each-bucket-using-watcher-action/312474/1 "2022-08-19T14:11:31Z")

</div>

I am trying to iterate through the aggregation bucket results. The aggregation response is :

```auto
"aggregations" : {
    "agg1" : {
      "doc_count_error_upper_bound" : 0,
      "sum_other_doc_count" : 0,
      "buckets" : [
        {
          "key" : "India",
          "doc_count" : 1,
          "agg2" : {
            "hits" : {
              "total" : {
                "value" : 2,
                "relation" : "eq"
              },
              "max_score" : 1.0,
              "hits" : [
                {
                  "_index" : "my-idx",
                  "_type" : "_doc",
                  "_id" : "yCREtoIB_SgE9GPnmqdM",
                  "_score" : 1.0,
                  "_source" : {
                    "agent" : {
                      "name" : "john"
                    },
                    "country": "India",
                    "@timestamp" : "2022-08-19T13:22:03.818Z",
                  }
                },
                {
                  "_index" : "my-idx",
                  "_type" : "_doc",
                  "_id" : "zIxEtoIBwzTD3EsaokUn",
                  "_score" : 1.0,
                  "_source" : {
                    "agent" : {
                      "name" : "jack"
                    },
                    "country": "India",
                    "@timestamp" : "2022-08-19T13:22:04.771Z"
                  }
                }
              ]
          }
        }
      },
      {
          "key" : "USA",
          "doc_count" : 1,
          "agg2" : {
            "hits" : {
              "total" : {
                "value" : 1,
                "relation" : "eq"
              },
              "max_score" : 1.0,
              "hits" : [
                {
                  "_index" : "my-idx",
                  "_type" : "_doc",
                  "_id" : "SgE9GPnmqdM",
                  "_score" : 1.0,
                  "_source" : {
                    "agent" : {
                      "name" : "harry"
                    },
                    "country": "USA",
                    "@timestamp" : "2022-08-19T13:22:03.818Z",
                  }
                }
                }
              ]
          }
        }
      }

```

In the above response since the number of buckets formed are 2 (i.e for India and USA), so 2 emails should be sent.

And in the 1st email (corresponding to India), the body should contain its top hits aggregation response, such as:

```auto
agent.name: "john"
@timestamp: 
country: "India"

agent.name: "jack"
@timestamp: 
country: "India"

```

Similarly for 2nd email (corresponding to USA), the body should contain

```auto
agent.name: "harry"
@timestamp: 
country: "USA"

```

I have tried with this watcher config.

```auto
{
  "trigger": {
    "schedule": {
      "interval": "30m"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "my-idx"
        ],
        "rest_total_hits_as_int": true,
        "body": {
        }
      }
    }
  },
  "transform" : {
      "script":
      """
        return [
          'test1': ctx.payload.aggregations.agg1.buckets.stream().map(a->a.agg2.hits)
              .collect(Collectors.toList())
          ]
      """
    },
  "actions": {
    "send_email": {
      "foreach": "ctx.payload.aggregations.agg1.buckets",
      "max_iterations": 100,
      "email": {
        "profile": "standard",
        "to": [
          "test@gmail.com"
        ],
        "subject": "Foreach Test",
        "body": {
          "html": """
          <html>
          <body>    
          <table tyle="background-color: #f9f9ff;">
          <tr>
          <td class="col1">{{ctx.payload.test1}}</td>
          </tr>
          </table> 
          </body>
          </html>
          """
        }
      }
    }
  }
}

```

**The issue is that using the transform script, in the `ctx.payload.test1`, I am getting the complete hits response of top hits aggregation for both the keys (i.e India and USA) in a single email.** Although I added for each loop, but it's not working.

Can anyone please help me resolve this issue ?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 19, 2022, 5:40pm UTC](https://discuss.elastic.co/t/how-to-iterate-through-aggregation-buckets-and-send-mail-corresponding-to-each-bucket-using-watcher-action/312474/3 "2022-08-19T17:40:39Z")

</div>

Hi @bhavya please do not directly mention `@` people into your threads.

Also please be patient you thread is only a couple hours old if you need timely help perhaps you should investigate a commercial license., there are many question / topic on the forum and yours is no more important than anyone else.

And scripting is not my strength anyways so I am not sure I can help much.

---

<div class="post-metadata">

**Author:** ![bhavya](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavya/32/45679_2.png) [@bhavya](https://discuss.elastic.co/u/bhavya)\
**Post date:** [August 19, 2022, 6:14pm UTC](https://discuss.elastic.co/t/how-to-iterate-through-aggregation-buckets-and-send-mail-corresponding-to-each-bucket-using-watcher-action/312474/4 "2022-08-19T18:14:12Z")

</div>

Sorry @stephenb, will take care of this next time

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 16, 2022, 6:14pm UTC](https://discuss.elastic.co/t/how-to-iterate-through-aggregation-buckets-and-send-mail-corresponding-to-each-bucket-using-watcher-action/312474/5 "2022-09-16T18:14:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
