# Print values from all aggregation buckets into alert email body

**URL:** <https://discuss.elastic.co/t/print-values-from-all-aggregation-buckets-into-alert-email-body/56442>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [July 26, 2016, 7:44pm UTC](https://discuss.elastic.co/t/print-values-from-all-aggregation-buckets-into-alert-email-body/56442 "2016-07-26T19:44:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ignaqui](https://avatars.discourse-cdn.com/v4/letter/i/c89c15/32.png) [@ignaqui](https://discuss.elastic.co/u/ignaqui)\
**Post date:** [July 26, 2016, 7:44pm UTC](https://discuss.elastic.co/t/print-values-from-all-aggregation-buckets-into-alert-email-body/56442/1 "2016-07-26T19:44:03Z")

</div>

Hello!

I'm trying to create watcher which will put data from aggregation into email's body. However, I stuck with the transformation. I even tried to hardcode say, 1st element of aggregation, like:

> {{ctx.payload.aggregations.ip\_buckets.buckets.1.doc\_count}}

without success. Please advise.

```
> {
> "trigger": {
> "schedule": {
> "interval": "1m"
> }
> },
> "input": {
> "search": {
> "request": {
> "indices": [
> "logstash-*"
> ],
> "body": {
> "size": 0,
> "query": {
> "bool": {
> "must": [
> {
> "range": {
> "date": {
> "gte": "now-1h",
> "lt": "now"
> }
> }
> },
> {
> "range": {
> "sc_status": {
> "gte": "500",
> "lte": "599"
> }
> }
> }
> ],
> "must_not": [
> {
> "match": {
> "cs_method": "GET"
> }
> },
> {
> "match": {
> "cs_method": "HEAD"
> }
> }
> ]
> }
> },
> "aggs": {
> "ip_buckets": {
> "terms": {
> "field": "ip",
> "min_doc_count": 30
> }
> }
> }
> }
> }
> }
> },
> "condition": {
> "array_compare": {
> "ctx.payload.aggregations.ip_buckets.buckets": {
> "path": "doc_count",
> "gt": {
> "value": 30,
> "quantifier": "some"
> }
> }
> }
> },
> "actions": {
> "send_email": {
> "throttle_period": "1m",
> "transform": {},
> "email": {
> "to": "john.doe@company.com",
> "subject": "ElasticSearch Cluster Alert -- Too many 500's have been discovered during last 60 min",
> "body": "Total # of errors per period: {{ctx.payload.hits.total}}"
> }
> }
> }
> }

```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [July 27, 2016, 7:27am UTC](https://discuss.elastic.co/t/print-values-from-all-aggregation-buckets-into-alert-email-body/56442/2 "2016-07-27T07:27:52Z")

</div>

Hey,

the core elasticsearch documentation about [templates](https://www.elastic.co/guide/en/elasticsearch/reference/2.3/search-template.html#_more_template_examples) contains some more infos how to loop over arrays. That should help!

--Alex

---

<div class="post-metadata">

**Author:** ![ignaqui](https://avatars.discourse-cdn.com/v4/letter/i/c89c15/32.png) [@ignaqui](https://discuss.elastic.co/u/ignaqui)\
**Post date:** [July 27, 2016, 1:37pm UTC](https://discuss.elastic.co/t/print-values-from-all-aggregation-buckets-into-alert-email-body/56442/3 "2016-07-27T13:37:23Z")

</div>

Thank you for quick response. I'll definitely give a try.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:44pm UTC](https://discuss.elastic.co/t/print-values-from-all-aggregation-buckets-into-alert-email-body/56442/4 "2017-07-06T13:44:10Z")

</div>


