We're using elastic to analyze some voip call traffic and I'm trying to figure out how to use watcher to monitor some limits we'd like to impose.
So an example would be;
Send me an alert when a calling number makes more than X minutes of calls in a 24hr period. Each time a different calling number breaks that threshold, send me a new alert.
I can query for numbers that are breaking the limit using a combination of terms, sum and bucket_selector aggregation, and then transform that into a series of new documents which I can index.
But what I would like is to execute a webhook action for each of those new documents, and have the throttle period apply per doc. Is it possible to do this all in watcher?