# Parsing complex bucket aggregations in watcher

**URL:** <https://discuss.elastic.co/t/parsing-complex-bucket-aggregations-in-watcher/81437>\
**Category:** Elasticsearch\
**Created:** [April 6, 2017, 9:35am UTC](https://discuss.elastic.co/t/parsing-complex-bucket-aggregations-in-watcher/81437 "2017-04-06T09:35:57Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![anishm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anishm/32/28796_2.png) [@anishm](https://discuss.elastic.co/u/anishm)\
**Post date:** [April 6, 2017, 9:35am UTC](https://discuss.elastic.co/t/parsing-complex-bucket-aggregations-in-watcher/81437/1 "2017-04-06T09:35:57Z")

</div>

In summary, I want to generate alerts when percentage disk usage of a device goes above a certain threshold. Using Beats for data collection, the documents individually look like the default System Beat. I wrote the following aggregation to get the percentage usage per device per host.  
{  
"query": {  
"range": {  
"@timestamp": {  
"gte": "now-15m",  
"lte": "now"  
}  
}  
},  
"aggs": {  
"by\_host": {  
"terms": {  
"field": "beat.hostname"  
},  
"aggs": {  
"by\_device": {  
"terms": {  
"field": "system.filesystem.device\_name"  
},  
"aggs": {  
"disk\_used\_pct": {  
"avg": {  
"field": "system.filesystem.used.pct"  
}  
}  
}  
}  
}  
}  
}  
}

How do I generate the alert for per device per host?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 10, 2017, 7:26am UTC](https://discuss.elastic.co/t/parsing-complex-bucket-aggregations-in-watcher/81437/2 "2017-04-10T07:26:09Z")

</div>

Hey,

right now, one query also only generates one alert. If you want to generate multiple alerts, it might be easier to forward the whole data to logstash using the watcher webhook and the logstash http input, and then create several events over there - or use the index action to create multiple documents in an index and use that index as source of alerts.

Hope this helps!

--Alex

---

<div class="post-metadata">

**Author:** ![anishm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anishm/32/28796_2.png) [@anishm](https://discuss.elastic.co/u/anishm)\
**Post date:** [April 14, 2017, 5:46am UTC](https://discuss.elastic.co/t/parsing-complex-bucket-aggregations-in-watcher/81437/3 "2017-04-14T05:46:46Z")

</div>

Yeah, makes sense actually. I was looking into templates and thought would have to make multiple types of alerts per host. But the Logstash way does sound good. I will give it a try  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 12, 2017, 5:49am UTC](https://discuss.elastic.co/t/parsing-complex-bucket-aggregations-in-watcher/81437/4 "2017-05-12T05:49:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
