# Problem extracting buckets

**URL:** <https://discuss.elastic.co/t/problem-extracting-buckets/43160>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [March 1, 2016, 9:19pm UTC](https://discuss.elastic.co/t/problem-extracting-buckets/43160 "2016-03-01T21:19:29Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bwgriffith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bwgriffith/32/7695_2.png) [@bwgriffith](https://discuss.elastic.co/u/bwgriffith)\
**Post date:** [March 1, 2016, 9:19pm UTC](https://discuss.elastic.co/t/problem-extracting-buckets/43160/1 "2016-03-01T21:19:29Z")

</div>

I've been using the excellent engineering blog posts on the atlas algorithm using watcher:

> **[Implementing a Statistical Anomaly Detector in Elasticsearch - Part 3](https://www.elastic.co/blog/implementing-a-statistical-anomaly-detector-part-3)**
>
> In the final article of this three-part series, we build a fully automated anomaly detector using Watcher to send email alerts.

And I'm trying to implement something similar here. I am basically trying to track operation calls and their duration over a sliding 24 hour window.

The query works and returns data in this format:

{  
"took": 89,  
"timed\_out": false,  
"\_shards": {  
"total": 495,  
"successful": 495,  
"failed": 0  
},  
"hits": {  
"total": 14776,  
"max\_score": 0,  
"hits": []  
},  
"aggregations": {  
"metrics": {  
"doc\_count\_error\_upper\_bound": 0,  
"sum\_other\_doc\_count": 123,  
"buckets": [  
{  
"key": "TEST\_OPERATION",  
"doc\_count": 4884,  
"queries": {...}  
"ninetieth\_surprise": {  
"values": {  
"90.0": 1110.8029139975035  
}  
}  
}

However when I run the following watch, the buckets that are returned are empty. Any ideas? Thanks!

{  
"trigger":{  
"schedule":{  
"interval":"1m"  
}  
},  
"input":{  
"search":{  
"request":{  
"indices":[  
"test\*"  
],  
"body":{  
"query":{...},  
"size":0,  
"aggs":{  
"metrics":{  
"terms":{  
"field":"operationname.raw"  
},  
"aggs":{  
"queries":{  
"terms":{  
"field":"operationname.raw"  
},  
"aggs":{  
"series":{  
"date\_histogram":{  
"field":"lastmodified",  
"interval":"hour",  
"min\_doc\_count":0  
},  
"aggs":{  
"avg":{  
"avg":{  
"field":"duration"  
}  
},  
"movavg":{  
"moving\_avg":{  
"buckets\_path":"avg",  
"window":24,  
"model":"simple"  
}  
},  
"surprise":{  
"bucket\_script":{  
"buckets\_path":{  
"avg":"avg",  
"movavg":"movavg"  
},  
"script":"(avg - movavg).abs()"  
}  
}  
}  
},  
"largest\_surprise":{  
"max\_bucket":{  
"buckets\_path":"series.surprise"  
}  
}  
}  
},  
"ninetieth\_surprise":{  
"percentiles\_bucket":{  
"buckets\_path":"queries\>largest\_surprise",  
"percents":[  
90.0  
]  
}  
}  
}  
}  
}  
}  
},  
"extract":[  
"aggregations.metrics.buckets.key",  
"aggregations.metrics.buckets.ninetieth\_surprise"  
]  
}  
},  
"actions":{...}  
}

Thanks again.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 4, 2016, 9:04am UTC](https://discuss.elastic.co/t/problem-extracting-buckets/43160/2 "2016-03-04T09:04:00Z")

</div>

Hey,

two things here.

First: You can use the [execute Watch API](https://www.elastic.co/guide/en/watcher/current/api-rest.html#api-rest-execute-watch) or the [watch history](https://www.elastic.co/guide/en/watcher/current/watch-history.html) to check what has been returned from your search requests - this will show you if the search response looks like excpected.

Second: Using the `extract` feature, you might actually want to combine this with the `keyed` feature of the `percentile` aggregation, so that you can specify the full path, see the [range aggs docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-range-aggregation.html#_keyed_response) (this will also work for the percentile agg).

Hope this helps. Otherwise feel free to share the output of the execute API.

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:46pm UTC](https://discuss.elastic.co/t/problem-extracting-buckets/43160/3 "2017-07-06T13:46:45Z")

</div>


