# Problem with aggregation in Watcher

**URL:** <https://discuss.elastic.co/t/problem-with-aggregation-in-watcher/108908>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [November 23, 2017, 3:00pm UTC](https://discuss.elastic.co/t/problem-with-aggregation-in-watcher/108908 "2017-11-23T15:00:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![g\_ani](https://avatars.discourse-cdn.com/v4/letter/g/46a35a/32.png) [@g\_ani](https://discuss.elastic.co/u/g_ani)\
**Post date:** [November 23, 2017, 3:00pm UTC](https://discuss.elastic.co/t/problem-with-aggregation-in-watcher/108908/1 "2017-11-23T15:00:42Z")

</div>

Hi I am currently facing some problems when trying to create an alert. My use case is that I want to calculate a ratio for each country (field on my index) and get notified for each country that this ratio is less than 99%. Below is my Watch JSON:

{  
"trigger": {  
"schedule": {  
"hourly": {  
"minute": [  
15,  
45  
]  
}  
}  
},  
"input": {  
"chain": {  
"inputs": [  
{  
"acceptable": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [],  
"types": [],  
"body": {  
"query": {  
"query\_string": {  
"query": "topic:(event\_tts\_\* OR event\_sip\__) AND d.direction:out AND d.reason:(0, 200, 404, 484, 486, 600, 603, 606, 610) AND @timestamp:[now-60m TO now-3m]"  
}  
}  
}  
},  
"extract": [  
"hits.total"  
]  
}  
}  
},  
{  
"denom": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [],  
"types": [],  
"body": {  
"query": {  
"query\_string": {  
"query": "topic:(event\_tts\__ OR event\_sip\_\*) AND d.direction:out AND _exists_:d.reason AND !d.reason:202 AND @timestamp:[now-60m TO now-3m]"  
}  
}  
}  
},  
"extract": [  
"hits.total"  
]  
}  
}  
}  
]  
}  
},  
"condition": {  
"script": {  
"source": "return (params.threshold \* ctx.payload.denom.hits.total) \> ctx.payload.acceptable.hits.total",  
"lang": "painless",  
"params": {  
"threshold": 0.99  
}  
}  
},  
"actions": {  
"email\_admin": {  
"email": {  
"profile": "standard",  
"to": [  
"random@randommail.com"  
],  
"subject": "kibanaAlertTest",  
"body": {  
"text": "Found {{ctx.payload.acceptable.hits.total}} acceptable reasons hits and {{ctx.payload.denom.hits.total}} hits for the tts and sip topics in the last hour."  
}  
}  
}  
}  
}.

I understand from the documentation that I will need to use a term aggregation on the field country. In a simple input the aggregation would be in the search body request. But where should it be in a chain input?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 28, 2017, 7:39am UTC](https://discuss.elastic.co/t/problem-with-aggregation-in-watcher/108908/2 "2017-11-28T07:39:37Z")

</div>

please format you messages properly, this is impossible to read due to missing indendation.

If you want to add an aggregation, it is going to be part of the `body` field of the search request, that you want to aggregate on. If you have two searches, you need to add it in both.

Also, you are using the `extract` part to only extract the hits field, which means you cannot access the aggregations - just to keep in mind when playing around.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2017, 7:40am UTC](https://discuss.elastic.co/t/problem-with-aggregation-in-watcher/108908/3 "2017-12-26T07:40:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
