# Need to alert if nested aggregation returns more than 3 results

**URL:** <https://discuss.elastic.co/t/need-to-alert-if-nested-aggregation-returns-more-than-3-results/260433>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [January 7, 2021, 12:13pm UTC](https://discuss.elastic.co/t/need-to-alert-if-nested-aggregation-returns-more-than-3-results/260433 "2021-01-07T12:13:57Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![victor.nilsson](https://avatars.discourse-cdn.com/v4/letter/v/eb8c5e/32.png) [@victor.nilsson](https://discuss.elastic.co/u/victor.nilsson)\
**Post date:** [January 7, 2021, 12:13pm UTC](https://discuss.elastic.co/t/need-to-alert-if-nested-aggregation-returns-more-than-3-results/260433/1 "2021-01-07T12:13:57Z")

</div>

Hi,

I have the following watch:

```
{
  "trigger": {
    "schedule": {
      "interval": "5m"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "logstash-network-*"
        ],
        "rest_total_hits_as_int": true,
        "body": {
          "query": {
            "bool": {
              "must": [
                {
                  "match_phrase": {
                    "message": "%SEC_LOGIN-SW1-4-LOGIN_FAILED"
                  }
                }
              ],
              "must_not": [
                {
                  "query_string": {
                    "default_field": "host.keyword",
                    "query": "(127.0.0.1) OR (172.16.123.123) OR (192.168.1.100)"
                  }
                },
                {
                  "query_string": {
                    "default_field": "user.keyword",
                    "query": "kiwi"
                  }
                }
              ],
              "filter": [
                {
                  "range": {
                    "@timestamp": {
                      "gte": "now-10m"
                    }
                  }
                }
              ]
            }
          },
          "aggs": {
            "user": {
              "terms": {
                "field": "user.keyword",
                "size": 10
              },
              "aggs": {
                "series": {
                  "date_histogram": {
                    "field": "@timestamp",
                    "fixed_interval": "1m",
                    "min_doc_count": 3
                  }
                }
              }
            }
          }
        }
      }
    }
  },
  "condition" : {
      "array_compare": {
      "ctx.payload.aggregations.user.0.series.buckets" : { 
        "path": "doc_count", 
        "gte": { 
          "value": 1
        }
      }
    }
    }
}

```

Which produces the following output:

```
"aggregations" : {
    "user" : {
      "doc_count_error_upper_bound" : 0,
      "sum_other_doc_count" : 0,
      "buckets" : [
        {
          "key" : "testuser",
          "doc_count" : 3,
          "series" : {
            "buckets" : [
              {
                "key_as_string" : "2021-01-04T07:51:00.000Z",
                "key" : 1609746660000,
                "doc_count" : 1
              },
              {
                "key_as_string" : "2021-01-04T07:52:00.000Z",
                "key" : 1609746720000,
                "doc_count" : 2
              }
            ]
          }
        }

```

I want to be able to create an alert if a user fails generates 3 events in 1 minute. That is i want to check if the nested aggregation "series" doc\_value is 3 or higher. I've tried it with the "array\_compare" condition but that does not seem to take into account any nested aggregations.

Could anyone help out?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 4, 2021, 12:14pm UTC](https://discuss.elastic.co/t/need-to-alert-if-nested-aggregation-returns-more-than-3-results/260433/2 "2021-02-04T12:14:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
