# Problem Watchers Failed Logins Index out of bounds exception Index 0 out of bounds for length 0

**URL:** <https://discuss.elastic.co/t/problem-watchers-failed-logins-index-out-of-bounds-exception-index-0-out-of-bounds-for-length-0/246694>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [August 27, 2020, 10:19pm UTC](https://discuss.elastic.co/t/problem-watchers-failed-logins-index-out-of-bounds-exception-index-0-out-of-bounds-for-length-0/246694 "2020-08-27T22:19:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![SerSSH](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/serssh/32/79174_2.png) [@SerSSH](https://discuss.elastic.co/u/SerSSH)\
**Post date:** [August 27, 2020, 10:19pm UTC](https://discuss.elastic.co/t/problem-watchers-failed-logins-index-out-of-bounds-exception-index-0-out-of-bounds-for-length-0/246694/1 "2020-08-27T22:19:08Z")

</div>

Hi Experts,

Currently I have an error that I have not been able to solve in a watcher, I am making some failed logins, so that when more than 3 attempts are detected per user it is activated and sends a notification by mail. However I have an error that appears when executing the watcher. This is my code and my mistake. I tried using a size: 50 or higher values but I don't really know how it works, previously it was in size: 0

```
{
  "trigger": {
"schedule": {
  "interval": "15m"
}
  },
  "input": {
"search": {
  "request": {
    "search_type": "query_then_fetch",
    "indices": [
      "o365beat-*"
    ],
    "rest_total_hits_as_int": true,
    "body": {
      "size": 50,
      "query": {
        "bool": {
          "must": [],
          "filter": [
            {
              "bool": {
                "filter": [
                  {
                    "bool": {
                      "should": [
                        {
                          "match_phrase": {
                            "Workload": "AzureActiveDirectory"
                          }
                        }
                      ],
                      "minimum_should_match": 1
                    }
                  },
                  {
                    "bool": {
                      "should": [
                        {
                          "match_phrase": {
                            "event.action": "UserLoginFailed"
                          }
                        }
                      ],
                      "minimum_should_match": 1
                    }
                  }
                ]
              }
            },
            {
              "range": {
                "@timestamp": {
                  "gte": "now-15m",
                  "lte": "now"
                }
              }
            }
          ],
          "should": [],
          "must_not": []
        }
      },
      "aggs": {
        "by": {
          "terms": {
            "field": "user.id.keyword"
          }
        }
      }
    }
  }
}
  },
  "condition": {
"compare": {
  "ctx.payload.aggregations.by.buckets.0.doc_count": {
    "gt": 3
  }
}
  },
  "actions": {
"send_email": {
  "email": {
    "profile": "gmail",
    "attachments": {
      "loginfailde.csv": {
        "reporting": {
          "url": "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx",
          "retries": 80,
          "interval": "4s",
          "auth": {
            "basic": {
              "username": "XXXXXXXXXXXXXX",
              "password": "XXXXXXXXXXXXXX"
            }
          }
        }
      }
    },
    "to": [
      "parami@paramiotravez"
    ],
    "subject": "New Event",
    "body": {
      "text": "Se han detectado {{ctx.payload.aggregations.by.buckets.0.doc_count}} evento(s) relacionado(s) con Intentos de Inicio de Sesión Fallidos"
    }
  }
}
  }
}

```

And the error is the following

```
"actions": []

```

},  
"exception": {  
"type": "index\_out\_of\_bounds\_exception",  
"reason": "Index 0 out of bounds for length 0"  
}  
}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 16, 2020, 12:30pm UTC](https://discuss.elastic.co/t/problem-watchers-failed-logins-index-out-of-bounds-exception-index-0-out-of-bounds-for-length-0/246694/2 "2020-09-16T12:30:26Z")

</div>

if `ctx.payload.aggregations.by.buckets` is an empty array because no documents are matching your query, you will face this exception.

You might want to use a [script condition](https://www.elastic.co/guide/en/elasticsearch/reference/7.9/condition-script.html) like

```auto
"condition" : {
  "script" : {
    "source" : "return ctx.payload.aggregations.buckets.size() > 0 && ctx.payload.aggregations.by.buckets.0.doc_count > 3"
  }
}

```

instead of the second part of the condition you could also go with [min\_doc\_count](https://www.elastic.co/guide/en/elasticsearch/reference/7.8/search-aggregations-bucket-terms-aggregation.html#_minimum_document_count_4)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 14, 2020, 12:30pm UTC](https://discuss.elastic.co/t/problem-watchers-failed-logins-index-out-of-bounds-exception-index-0-out-of-bounds-for-length-0/246694/3 "2020-10-14T12:30:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
