# Kibana Watcher to trigger email by checking aggregation results with dynamic threshold value

**URL:** <https://discuss.elastic.co/t/kibana-watcher-to-trigger-email-by-checking-aggregation-results-with-dynamic-threshold-value/338357>\
**Category:** Elasticsearch\
**Tags:** ingest-pipeline\
**Created:** [July 13, 2023, 8:30pm UTC](https://discuss.elastic.co/t/kibana-watcher-to-trigger-email-by-checking-aggregation-results-with-dynamic-threshold-value/338357 "2023-07-13T20:30:17Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Santosh1667](https://avatars.discourse-cdn.com/v4/letter/s/dbc845/32.png) [@Santosh1667](https://discuss.elastic.co/u/Santosh1667)\
**Post date:** [July 13, 2023, 8:30pm UTC](https://discuss.elastic.co/t/kibana-watcher-to-trigger-email-by-checking-aggregation-results-with-dynamic-threshold-value/338357/1 "2023-07-13T20:30:17Z")

</div>

Hi , I had a Kibana watcher which will give aggregation buckets in below format

```auto
distinct_error_count:[
{
key:"Error 1 Occured",
distinct_count:6
},
{
key:"Error 2 Occured",
distinct_count:4
},
{
key:"Error 3 Occured",
disctinct_count:1
}]

```

I need to send email which contains these errors but before that I need to check for each and every key in distinct\_error\_count if distinct\_count \> threshold(dynamic value which can be placed anywhere in external or Elastic space).

In Splunk we have lookups which is csv file on the Splunk and can be retrieved in Splunk Alert.

**Want to know if there we can create lookups in Elastic as above. If so, where I can create this file else Is there a way I can place this file externally and retrieve in Watcher?**

I heard ingest pipeline is better in this scenario , Want in detail how can i implement this if applicable and any detailed example of entire watcher with this ingestion implementation will be useful for me.

Thanks in Advance for the help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2023, 8:30pm UTC](https://discuss.elastic.co/t/kibana-watcher-to-trigger-email-by-checking-aggregation-results-with-dynamic-threshold-value/338357/2 "2023-08-10T20:30:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
