# Need help with creating a Watcher and trigger Email

**URL:** <https://discuss.elastic.co/t/need-help-with-creating-a-watcher-and-trigger-email/338542>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [July 17, 2023, 11:14am UTC](https://discuss.elastic.co/t/need-help-with-creating-a-watcher-and-trigger-email/338542 "2023-07-17T11:14:13Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jayakrishna\_Manokara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jayakrishna_manokara/32/122851_2.png) [@Jayakrishna\_Manokara](https://discuss.elastic.co/u/Jayakrishna_Manokara)\
**Post date:** [July 17, 2023, 11:14am UTC](https://discuss.elastic.co/t/need-help-with-creating-a-watcher-and-trigger-email/338542/1 "2023-07-17T11:14:13Z")

</div>

I would like to create a Watcher Alert using Watcher JSON and trigger email.  
Could you help me create a Watcher JSON that is equivalent to the below formula:

```auto
unique_count(id, kql='abcresult.keyword : "SUCCESS" ') / (unique_count(id, kql='abcresult.keyword : "SUCCESS" ') + unique_count(id, kql='abcresult.keyword: "FAILURE" '))

```

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [July 17, 2023, 10:49pm UTC](https://discuss.elastic.co/t/need-help-with-creating-a-watcher-and-trigger-email/338542/2 "2023-07-17T22:49:58Z")

</div>

Hi - welcome to the forum!

Questions for you:

1. Have you created Watches before and do you know the [basics](https://www.elastic.co/guide/en/elasticsearch/reference/current/watcher-getting-started.html)?
2. Have you queried Elasticsearch using DSL syntax (plus used [aggregations](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations.html)) before?
3. Have you heard of a [bucket\_script](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-pipeline-bucket-script-aggregation.html) aggregation?

The use of a bucket\_script aggregation is likely the easiest way to go here to calculate the ratio right in the query.

---

<div class="post-metadata">

**Author:** ![Jayakrishna\_Manokara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jayakrishna_manokara/32/122851_2.png) [@Jayakrishna\_Manokara](https://discuss.elastic.co/u/Jayakrishna_Manokara)\
**Post date:** [July 18, 2023, 11:59am UTC](https://discuss.elastic.co/t/need-help-with-creating-a-watcher-and-trigger-email/338542/3 "2023-07-18T11:59:39Z")

</div>

Hi, I am new to ELK.  
I am going through the links you have provided.  
I have a doubt here.  
Will I be able to create a Watcher using bucket script aggregation?

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [July 19, 2023, 12:50pm UTC](https://discuss.elastic.co/t/need-help-with-creating-a-watcher-and-trigger-email/338542/4 "2023-07-19T12:50:38Z")

</div>

Yes, a Watch can contain any valid Elasticsearch DSL query/aggregation. Here's an example of a watch that looks at weblogs and computes the ratio of status codes in web logs. Not your exact use case, but pretty close!

```auto
POST _watcher/watch/_execute
{
  "watch": {
    "trigger": {
      "schedule": {
        "interval": "1d"
      }
    },
    "input": {
      "search": {
        "request": {
          "indices": [
            "kibana_sample_data_logs"
            ],
            "body": {
              "size": 0,
              "query": {
                "bool": {
                  "filter": [
                    {
                      "range": {
                        "@timestamp": {
                          "gte": "now-1d"
                        }
                      }
                    }
                    ]
                }
              },
              "aggregations": {
                "buckets": {
                  "date_histogram": {
                    "field": "@timestamp",
                    "calendar_interval": "1d"
                  },
                  "aggregations": {
                    "200s": {
                      "filter": {
                        "term": {
                          "response.keyword": "200"
                        }
                      }
                    },
                    "404s": {
                      "filter": {
                        "term": {
                          "response.keyword": "404"
                        }
                      }
                    },
                    "ratio": {
                      "bucket_script": {
                        "buckets_path": {
                          "two_hundreds": "200s._count",
                          "four_oh_fours": "404s._count"
                        },
                        "script": "params.four_oh_fours / (params.two_hundreds + params.four_oh_fours)"
                      }
                    }
                  }
                }
              }
            }
        }
      }
    },
    "condition": {
      "script": """
      // check to see if the ratio is higher than 5%
      return ctx.payload.aggregations.buckets.buckets.0.ratio.value > 0.05; 
      """
    },
    "actions": {
      "log": {
        "logging": {
          "text": """
          Alert - the ratio is higher than 5%. See raw data:
          
          {{ctx.payload}}
          """
        }
      }
    }
  }
}    

```

The output just logs (doesn't email) but there are plenty of examples on how to email from a Watch

---

<div class="post-metadata">

**Author:** ![Jayakrishna\_Manokara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jayakrishna_manokara/32/122851_2.png) [@Jayakrishna\_Manokara](https://discuss.elastic.co/u/Jayakrishna_Manokara)\
**Post date:** [July 20, 2023, 12:57pm UTC](https://discuss.elastic.co/t/need-help-with-creating-a-watcher-and-trigger-email/338542/5 "2023-07-20T12:57:31Z")

</div>

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 17, 2023, 12:57pm UTC](https://discuss.elastic.co/t/need-help-with-creating-a-watcher-and-trigger-email/338542/6 "2023-08-17T12:57:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
