# Looping through aggregations result

**URL:** <https://discuss.elastic.co/t/looping-through-aggregations-result/79489>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [March 21, 2017, 6:55pm UTC](https://discuss.elastic.co/t/looping-through-aggregations-result/79489 "2017-03-21T18:55:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![seanziee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seanziee/32/45151_2.png) [@seanziee](https://discuss.elastic.co/u/seanziee)\
**Post date:** [March 21, 2017, 6:55pm UTC](https://discuss.elastic.co/t/looping-through-aggregations-result/79489/1 "2017-03-21T18:55:51Z")

</div>

Hi,

So I'm trying to create an email action that shows me weekly a summary of all the watches that I currently have running. I'm having trouble displaying it nicely though and it would be nice if I could display the results form my aggregation a bit nicer than what I can currently do.

```
POST _xpack/watcher/watch/currentActiveWatches
{
  "trigger": {
    "schedule": {
      "interval": "5s"
    }
  },
  "input": {
    "http": {
      "request": {
        "host": "XXXXX",
        "port": 9200,
        "path": ".watcher-history*/_search",
        "body": "{\"_source\": [\"watch_id\"], \"query\": { \"wildcard\": { \"watch_id\": \"A*\" }},
\"aggs\": {\"distinct_watches\": { \"terms\": {\"field\": \"watch_id\", \"size\": 15 } }} }"
      }
    }
  },
  "actions": {
    "send_email": {
      "email": {
        "from": "XX@X.com",
        "to": "XX@XX.com",
        "subject": "{{ctx.payload.aggregations.distinct_watches.buckets}} ",
        "body": "{{ctx.payload.aggregations.distinct_watches.buckets.0.key}}"
      }
    }
  }
}

```

The results of the code I have in the "subject" look like this:

> {0={key=AcTag-CM-1234, doc\_count=24182}, 1={key=AcTag-W-21308, doc\_count=15885}, 2={key=AcTag-D-10705, doc\_count=15849}, 3={key=AcTag-test, doc\_count=5491}, 4={key=AcTag-Test, doc\_count=102}, 5={key=AcTag-Test1, doc\_count=78}

I'd ideally have an array or list or table that can show these results rather than just this massive ugly text. Is there some way to make this look nicer?

And the results in the body only show one watch and I can't seem to say [0-], [0,] or anything like that to say that I want ALL of the results that I get from the given aggregation.

Any direction is appreciated!

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 29, 2017, 7:29am UTC](https://discuss.elastic.co/t/looping-through-aggregations-result/79489/2 "2017-03-29T07:29:08Z")

</div>

Hey,

sorry for the late reply, this one got overlooked somehow. So, you can loop through a list with mustache.

See [https://www.elastic.co/guide/en/elasticsearch/reference/5.3/search-template.html#\_more\_template\_examples](https://www.elastic.co/guide/en/elasticsearch/reference/5.3/search-template.html#_more_template_examples) and a concrete example looping through aggregation buckets is at [https://www.elastic.co/guide/en/x-pack/5.3/watching-meetup-data.html](https://www.elastic.co/guide/en/x-pack/5.3/watching-meetup-data.html)

Hope this helps!

--Alex

---

<div class="post-metadata">

**Author:** ![seanziee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seanziee/32/45151_2.png) [@seanziee](https://discuss.elastic.co/u/seanziee)\
**Post date:** [March 29, 2017, 4:59pm UTC](https://discuss.elastic.co/t/looping-through-aggregations-result/79489/3 "2017-03-29T16:59:37Z")

</div>

Ok great. So the

```
{{#ctx.payload.aggregations.group_by_city.buckets}}{{key}} {{/ctx.payload.aggregations.group_by_city.buckets}}

```

Is the way to do this if anyone in the future is interested. This is the mustache language.

Thanks for the help Alex!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 26, 2017, 4:59pm UTC](https://discuss.elastic.co/t/looping-through-aggregations-result/79489/4 "2017-04-26T16:59:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
