Kibana Watcher to trigger email by checking aggregation results with dynamic threshold value

Hi , I had a Kibana watcher which will give aggregation buckets in below format

key:"Error 1 Occured",
key:"Error 2 Occured",
key:"Error 3 Occured",

I need to send email which contains these errors but before that I need to check for each and every key in distinct_error_count if distinct_count > threshold(dynamic value which can be placed anywhere in external or Elastic space).

In Splunk we have lookups which is csv file on the Splunk and can be retrieved in Splunk Alert.

Want to know if there we can create lookups in Elastic as above. If so, where I can create this file else Is there a way I can place this file externally and retrieve in Watcher?

I heard ingest pipeline is better in this scenario , Want in detail how can i implement this if applicable and any detailed example of entire watcher with this ingestion implementation will be useful for me.

Thanks in Advance for the help.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.