# Multiple aggregates in Watcher configuration logging output

**URL:** <https://discuss.elastic.co/t/multiple-aggregates-in-watcher-configuration-logging-output/209455>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [November 26, 2019, 9:25am UTC](https://discuss.elastic.co/t/multiple-aggregates-in-watcher-configuration-logging-output/209455 "2019-11-26T09:25:03Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![elastic\_user.pk](https://avatars.discourse-cdn.com/v4/letter/e/ad7895/32.png) [@elastic\_user.pk](https://discuss.elastic.co/u/elastic_user.pk)\
**Post date:** [November 26, 2019, 9:25am UTC](https://discuss.elastic.co/t/multiple-aggregates-in-watcher-configuration-logging-output/209455/1 "2019-11-26T09:25:03Z")

</div>

Hello,

I need help regarding logging text of the Watcher alert. I've created a Watcher in elastic-search with the following configuration:

```
{
  "trigger": {
    "schedule": {
      "interval": "30m"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "auditbeat*"
        ],
        "rest_total_hits_as_int": true,
        "body": {
          "size": 1,
          "query": {
            "bool": {
              "must": [],
              "filter": [
                {
                  "match_all": {}
                },
                {
                  "match_phrase": {
                    "event.action": {
                      "query": "user_login"
                    }
                  }
                },
                {
                  "match_phrase": {
                    "event.type": {
                      "query": "authentication_failure"
                    }
                  }
                },
                {
                  "range": {
                    "@timestamp": {
                      "format": "strict_date_optional_time",
                      "gte": "now-12h",
                      "lte": "now"
                    }
                  }
                }
              ],
              "should": [],
              "must_not": []
            }
          },
          "aggs": {
            "user_name": {
              "terms": {
                "field": "user.name",
                "size": 30
              }
            },
            "host_name": {
              "terms": {
                "field": "host.name",
                "size": 30
              }
            },
            "source_ip": {
              "terms": {
                "field": "source.ip",
                "size": 30
              }
            }
          }
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "gte": 5
      }
    }
  },
  "actions": {
    "log_hits": {
      "logging": {
        "level": "info",
        "text": "text": " Total {{ctx.payload.hits.total}} failed logins. Hostname: {{#ctx.payload.aggregations.host_name.buckets}} {{key}}: {{/ctx.payload.aggregations.host_name.buckets}}, and Source IP: {{#ctx.payload.aggregations.source_ip.buckets}} {{key}}: {{/ctx.payload.aggregations.source_ip.buckets}}"
      }
    }
  }
}

```

Output of this alert is following:

"logged\_text": " Total 16 failed logins. Hostname: mailserver1: mailserver2: mailserver3: mailserver4: mailserver5: mailserver6: mailserver6: , and Source IP: 192.168.36.160: 192.168.18.115: "

Currently using my configuration, it is printing all host\_name and then all source\_ip.

How can I modify the watcher to use aggregates as host\_name1 source\_ip1, host\_name2, source\_ip2....? for example:

"logged\_text": " Total 16 failed logins. Hostname: mailserver1: Source IP: 192.168.36.160 mailserver2: Source IP: 192.168.36.160 mailserver3: Source IP: 192.168.36.160 mailserver4: Source IP: 192.168.18.115: mailserver5: Source IP: 192.168.18.115: mailserver6: Source IP: 192.168.18.115: mailserver6: Source IP: 192.168.18.115:"

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 28, 2019, 9:19am UTC](https://discuss.elastic.co/t/multiple-aggregates-in-watcher-configuration-logging-output/209455/2 "2019-11-28T09:19:55Z")

</div>

You need to use a [transform](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/transform-script.html) to change the data to your needs, in this case merging ip/name together.

Also you may want to do this on index instead of query time to speed things, for example with an ingest pipeline.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2019, 9:19am UTC](https://discuss.elastic.co/t/multiple-aggregates-in-watcher-configuration-logging-output/209455/3 "2019-12-26T09:19:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
