# Math operation with aggregated fields

**URL:** <https://discuss.elastic.co/t/math-operation-with-aggregated-fields/233569>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [May 20, 2020, 3:50pm UTC](https://discuss.elastic.co/t/math-operation-with-aggregated-fields/233569 "2020-05-20T15:50:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Thanura\_Kannangara](https://avatars.discourse-cdn.com/v4/letter/t/3bc359/32.png) [@Thanura\_Kannangara](https://discuss.elastic.co/u/Thanura_Kannangara)\
**Post date:** [May 20, 2020, 3:50pm UTC](https://discuss.elastic.co/t/math-operation-with-aggregated-fields/233569/1 "2020-05-20T15:50:49Z")

</div>

Hello Folks,

A newbie (to watchers at least) is here 🙂

I'm trying to create a watcher for disk\_space usage  
we have multiple hosts send data to same index pattern, so I was planning to aggregate hits with hostname and get required fields in buckets inside aggregation as `_source` fields

The Math calculation I need is very simple.

`"system.fsstat.total_size.used/system.fsstat.total_size.total > ctx.metadata.thresholdPercent"`

Below is my in progress watcher and I know for certain that, this condition does not work like this

```auto
{
  "trigger": {
    "schedule": {
      "interval": "30m"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "metricbeat-BlaBla-*"
        ],
        "rest_total_hits_as_int": true,
        "body": {
          "query": {
            "bool": {
              "must": [
                {
                  "query_string": {
                    "query": "(system.fsstat.total_size.total : *)"
                  }
                },
                {
                  "range": {
                    "@timestamp": {
                      "gte": "now-30m"
                    }
                  }
                }
              ]
            }
          },
          "_source": [
            "host.name",
            "system.fsstat.total_size.total",
            "system.fsstat.total_size.used",
            "system.fsstat.total_size.free"
          ],
          "sort": [
            {
              "@timestamp": {
                "order": "desc"
              }
            }
          ],
          "aggs": {
            "hostname": {
              "terms": {
                "field": "host.name"
              },
              "aggs": {
                "recent_diskspace_used": {
                  "top_hits": {
                    "sort": [
                      {
                        "@timestamp": {
                          "order": "desc"
                        }
                      }
                    ],
                    "_source": {
                      "includes": [
                        "system.fsstat.total_size.total",
                        "system.fsstat.total_size.used"
                      ]
                    },
                    "size": 1
                  }
                }
              }
            }
          }
        }
      }
    }
  },
  "condition": {
    "script" :{
        "source": "return ctx.payload.aggregations.hostname.buckets.recent_diskspace_used.hits.hits[0]._source.system.fsstat.total_size.used/ctx.payload.aggregations.hostname.buckets.recent_diskspace_used.hits.hits[0]._source.system.fsstat.total_size.total > ctx.metadata.thresholdPercent",
        "lang": "painless"
      }
  },
  "actions": {
    "my-logging-action": {
      ................................
    }
  },
  "metadata": {
    "thresholdPercent": 0.5
  }
}

```

And if we check the aggregations they look like this

```auto
            "aggregations":{
               "hostname":{
                  "doc_count_error_upper_bound":0,
                  "sum_other_doc_count":0,
                  "buckets":[
                     {
                        "doc_count":30,
                        "recent_diskspace_used":{
                           "hits":{
                              "hits":[
                                 {
                                    "_index":"metricbeat-BlaBla-000005",
                                    "_type":"_doc",
                                    "_source":{
                                       "system":{
                                          "fsstat":{
                                             "total_size":{
                                                "total":107372081152,
                                                "used":48694804480
                                             }
                                          }
                                       }
                                    },
                                    "_id":"gVimMnIBG9oIUupGvXgq",
                                    "sort":[
                                       1589987687069
                                    ],
                                    "_score":null
                                 }
                              ],
                              "total":30,
                              "max_score":null
                           }
                        },
                        "key":"hostname_one"
                     },
                     {
                        "doc_count":30,
                        "recent_diskspace_used":{
                           "hits":{
                              "hits":[
                                 {
                                    "_index":"metricbeat-BlaBla-000005",
                                    "_type":"_doc",
                                    "_source":{
                                       "system":{
                                          "fsstat":{
                                             "total_size":{
                                                "total":107372081152,
                                                "used":57353330688
                                             }
                                          }
                                       }
                                    },
                                    "_id":"3AWmMnIBzr28qyZPNQYk",
                                    "sort":[
                                       1589987651869
                                    ],
                                    "_score":null
                                 }
                              ],
                              "total":30,
                              "max_score":null
                           }
                        },
                        "key":"hostname_two"
                     }
                  ]
               }
            }

```

In the end, what I need to do is.

If the math calculation result is `false` (per hostname), I need to trigger action.  
So need to evaluate hits for each hostname aggregation field values...

I know this is not that complicated.  
However, I was lost in Elastic documentation pages.....  
Any help is much appreciated...

---

<div class="post-metadata">

**Author:** ![Thanura\_Kannangara](https://avatars.discourse-cdn.com/v4/letter/t/3bc359/32.png) [@Thanura\_Kannangara](https://discuss.elastic.co/u/Thanura_Kannangara)\
**Post date:** [May 20, 2020, 10:43pm UTC](https://discuss.elastic.co/t/math-operation-with-aggregated-fields/233569/2 "2020-05-20T22:43:46Z")

</div>

Hey @spinscale,

Sorry to spam you with the tag.  
Will you be able to shed some light on this?

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [May 26, 2020, 9:41am UTC](https://discuss.elastic.co/t/math-operation-with-aggregated-fields/233569/3 "2020-05-26T09:41:35Z")

</div>

Hey,

so a `script` condition is what you are after.

```auto
return ctx.payload.aggregations.buckets.stream().anyMatch(b -> { size = b.recent_diskspace.used.hits.hits[0]._source.system.fsstat.total_size; return size.used/size.total > THRESHOLD)}

```

This above returns true if any of the buckets matches the inside condition. I hope that helps as a start.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 23, 2020, 9:41am UTC](https://discuss.elastic.co/t/math-operation-with-aggregated-fields/233569/4 "2020-06-23T09:41:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
