# \[Kibana painless alert\] Unable to read a string value from an array

**URL:** <https://discuss.elastic.co/t/kibana-painless-alert-unable-to-read-a-string-value-from-an-array/250837>\
**Category:** Kibana\
**Created:** [October 2, 2020, 6:44pm UTC](https://discuss.elastic.co/t/kibana-painless-alert-unable-to-read-a-string-value-from-an-array/250837 "2020-10-02T18:44:27Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![roel\_m](https://avatars.discourse-cdn.com/v4/letter/r/d2c977/32.png) [@roel\_m](https://discuss.elastic.co/u/roel_m)\
**Post date:** [October 2, 2020, 6:44pm UTC](https://discuss.elastic.co/t/kibana-painless-alert-unable-to-read-a-string-value-from-an-array/250837/1 "2020-10-02T18:44:27Z")

</div>

Hi,

We are using elastic and kibana to store and visualize automated testing data and we want to create an alerting system that sends a message to Flowdock if a certain threshold of failed tests is reached.  
For this purpose I've created a monitor in kibana.  
So far I've been able to set up the monitor query and destination correctly.

The response of the query is as following:

```auto
    {
        "_shards": {
            "total": 150,
            "failed": 0,
            "successful": 150,
            "skipped": 145
        },
        "hits": {
            "hits": [],
            "total": 79,
            "max_score": 0
        },
        "took": 23,
        "timed_out": false,
        "aggregations": {
            "testStepName": {
                "doc_count_error_upper_bound": 0,
                "sum_other_doc_count": 0,
                "buckets": [
                    {
                        "doc_count": 17,
                        "key": "CreateReviewBufferSession"
                    },
                    {
                        "doc_count": 10,
                        "key": "Fetch thumbnails"
                    },
                    {
                        "doc_count": 9,
                        "key": "Verify manifest"
                    },
                    {
                        "doc_count": 7,
                        "key": "Fetch manifest"
                    }
                ]
            }
        }
    }

```

I'm using aggregations to us a single monitor for our alerting system. (Instead of creating and managing 32 different monitors)

Now I'm trying to create a trigger condition for this query.  
I want to trigger the actions if the doc\_count of one of the buckets reaches a certain value.

The painless code I have so far is as following:

```auto
    for(int i=0; i < ctx.results[0].aggregations.testStepName.buckets.length;i++){
        if (ctx.results[0].aggregations.testStepName.buckets[i].key === "Verify manifest") {
            if (ctx.results[0].aggregations.testStepName.buckets[i].doc_count > 5) {
                return true;
            }
        }
    }

```

However this does not seem to work.  
I still get a false as trigger condition response.  
I've done some debugging and it appears I'm unable to read the key value from any of the objects in the buckets array. I am however able to read the doc\_count correctly.

I've also tried using doc values (doc['field']) but I'm afraid I'm still to new to elastic to get it working that way.

If someone is able to have a look and provide some advice that would be greatly appreciated.  
Regards

The version of Kibana we are running is 6.8.0

---

<div class="post-metadata">

**Author:** ![roel\_m](https://avatars.discourse-cdn.com/v4/letter/r/d2c977/32.png) [@roel\_m](https://discuss.elastic.co/u/roel_m)\
**Post date:** [October 5, 2020, 1:15pm UTC](https://discuss.elastic.co/t/kibana-painless-alert-unable-to-read-a-string-value-from-an-array/250837/2 "2020-10-05T13:15:07Z")

</div>

After lots of trial and error I was able to solve/workaround the issue by using contains instead of an exact match.  
This is what I'm use now:

```auto
    for(int i=0; i < ctx.results[0].aggregations.testStepName.buckets.length;i++){
        if (ctx.results[0].aggregations.testStepName.buckets[i].key.contains("Verify manifest")) {
            if (ctx.results[0].aggregations.testStepName.buckets[i].doc_count > 5) {
                return true;
            }
        }
    }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 2, 2020, 1:15pm UTC](https://discuss.elastic.co/t/kibana-painless-alert-unable-to-read-a-string-value-from-an-array/250837/3 "2020-11-02T13:15:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
