# Issue with watcher and aggregation

**URL:** <https://discuss.elastic.co/t/issue-with-watcher-and-aggregation/269349>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [April 6, 2021, 3:33pm UTC](https://discuss.elastic.co/t/issue-with-watcher-and-aggregation/269349 "2021-04-06T15:33:13Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anna\_Foxx](https://avatars.discourse-cdn.com/v4/letter/a/a587f6/32.png) [@Anna\_Foxx](https://discuss.elastic.co/u/Anna_Foxx)\
**Post date:** [April 6, 2021, 3:33pm UTC](https://discuss.elastic.co/t/issue-with-watcher-and-aggregation/269349/1 "2021-04-06T15:33:13Z")

</div>

Hi!

I have faced the issue with watcher during data aggregation. The watcher works fine without aggregation, but after trying to group values I get this error:

```auto
"type": "illegal_argument_exception",
            "reason": "Text fields are not optimised for operations that require per-document field data like aggregations and sorting, so these operations are disabled by default. Please use a keyword field instead. Alternatively, set fielddata=true on [protoPayload.resourceName] in order to load field data by uninverting the inverted index. Note that this can use significant memory."

```

Is it problem with mapping?

here is my watcher:

```auto
{
    "trigger": {
      "schedule": {
        "interval": "5m"
      }
    },
    "input": {
      "search": {
        "request": {
          "search_type": "query_then_fetch",
          "indices": [
            "gcp-test-*"
          ],
          "rest_total_hits_as_int": true,
          "body": {
            "size": 100,
            "query": {
              "bool": {
                "filter": [
                  {
                    "range": {
                      "@timestamp": {
                        "gte": "now-{{ctx.metadata.query_period}}",
                        "lte": "now"
                      }
                    }
                  },
                  {
                    "match": {
                      "protoPayload.methodName": "protoPayload.authorizationInfo.resourceAttributes.name"
                    }
                  }
                ]
              }
            },
            "aggs": {
              "1": {
                "terms": {
                  "field": "protoPayload.resourceName",
                  "size": 100
                }
              }
            }
          }
        }
      }
    },
    "condition": {
      "compare": {
        "ctx.payload.aggregations.1.buckets.doc_count": {
          "gt": 0
        }
      }
    },
    "actions": {},
    "metadata": {
      "query_period": "5m"
    },
    "transform": {
      "script": {
        "source": "def payload = ctx.payload; payload.starttime = Instant.ofEpochMilli(ctx.execution_time.getMillis()-1800000); payload.endtime = ctx.execution_time; return payload;",
        "lang": "painless"
      }
    }
  }

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 6, 2021, 7:02pm UTC](https://discuss.elastic.co/t/issue-with-watcher-and-aggregation/269349/2 "2021-04-06T19:02:31Z")

</div>

Hi @Anna_Foxx

I suspect you may be using a default mapping on the

`protoPayload.resourceName`

field

Perhaps in the aggregation try

`protoPayload.resourceName.keyword`

If that works perhaps you should look at creating a mapping that is more specific to your data

---

<div class="post-metadata">

**Author:** ![Anna\_Foxx](https://avatars.discourse-cdn.com/v4/letter/a/a587f6/32.png) [@Anna\_Foxx](https://discuss.elastic.co/u/Anna_Foxx)\
**Post date:** [April 7, 2021, 6:24am UTC](https://discuss.elastic.co/t/issue-with-watcher-and-aggregation/269349/3 "2021-04-07T06:24:58Z")

</div>

Oh. It's my stupid fault 😅

Thank you for helping me!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 5, 2021, 6:25am UTC](https://discuss.elastic.co/t/issue-with-watcher-and-aggregation/269349/4 "2021-05-05T06:25:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
