# Post insert of a transaction to Elastic Search

**URL:** <https://discuss.elastic.co/t/post-insert-of-a-transaction-to-elastic-search/73156>\
**Category:** Elasticsearch\
**Created:** [January 30, 2017, 6:09am UTC](https://discuss.elastic.co/t/post-insert-of-a-transaction-to-elastic-search/73156 "2017-01-30T06:09:38Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sjs](https://avatars.discourse-cdn.com/v4/letter/s/278dde/32.png) [@sjs](https://discuss.elastic.co/u/sjs)\
**Post date:** [January 30, 2017, 6:09am UTC](https://discuss.elastic.co/t/post-insert-of-a-transaction-to-elastic-search/73156/1 "2017-01-30T06:09:39Z")

</div>

Hi everyone,

I receive transactions on MQ and i wrote a JMS listener that stores those transactions to Elastic Search using ES Rest API.

once the transaction is stored to ES, i would like to perform some operations, like:  
i) aggregating the data with few fields(for eg: field1 and field 2)  
ii) compare the aggregated values of field 1 and field 2 with some predefined values.  
iii) if the aggregated values are breached, then i need to raise an alert.

I went through all the products of elastic, like logstash, beats, watcher etc. none of them seems to work for my usecase.

Can you please provide your valuable inputs to how to realized this usecase using elastic stack?

Many Thanks  
Srinivas

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [January 31, 2017, 8:14am UTC](https://discuss.elastic.co/t/post-insert-of-a-transaction-to-elastic-search/73156/2 "2017-01-31T08:14:54Z")

</div>

Hey,

so your first use-case can be solved with Elasticsearch using [aggregations](https://www.elastic.co/guide/en/elasticsearch/guide/2.x/aggregations.html) (see also the [reference docs](https://www.elastic.co/guide/en/elasticsearch/reference/5.1/search-aggregations.html)).

Your second and third use-case could be done via [x-pack alerting](https://www.elastic.co/guide/en/x-pack/5.1/xpack-alerting.html).

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 28, 2017, 8:14am UTC](https://discuss.elastic.co/t/post-insert-of-a-transaction-to-elastic-search/73156/3 "2017-02-28T08:14:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
