# Send an alert for each item in aggregation list

**URL:** <https://discuss.elastic.co/t/send-an-alert-for-each-item-in-aggregation-list/112316>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [December 18, 2017, 9:59pm UTC](https://discuss.elastic.co/t/send-an-alert-for-each-item-in-aggregation-list/112316 "2017-12-18T21:59:27Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![xanthus29](https://avatars.discourse-cdn.com/v4/letter/x/e8c25b/32.png) [@xanthus29](https://discuss.elastic.co/u/xanthus29)\
**Post date:** [December 18, 2017, 9:59pm UTC](https://discuss.elastic.co/t/send-an-alert-for-each-item-in-aggregation-list/112316/1 "2017-12-18T21:59:27Z")

</div>

After searching around for a while, I'm at a loss on how to accomplish my goal. I'm aggregating a list of items and would like to run the action for each item in the list. I found a post back in Jun '16 where that ability was not yet implemented. It's been a year and a half. Has any progress been made?

> [@Generic watch, specific alerts, duplicate alerting?](https://discuss.elastic.co/t/generic-watch-specific-alerts-duplicate-alerting/51610):
>
> Imagine that I have 100 machines to monitor and that each machine is named by its number (i.e. the first machine is named ("1"). Imagine that I wish to alert if the disk usage is over 90% on any of the machines. Imagine that LogStash is inserting data into ES every minute with the current disk percentage for each machine. I would like to send an alert to pagerduty for every machine that is over 90% disk usage. I know how to craft my search query to find machines with disk usage over 90%. Su…

@spinscale  
Do you know if this is possible?

Thanks,

Greg

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [December 19, 2017, 7:44am UTC](https://discuss.elastic.co/t/send-an-alert-for-each-item-in-aggregation-list/112316/2 "2017-12-19T07:44:59Z")

</div>

Hey,

even though we spent some R&D effort in that region, we have so far nothing changed around the current execution model - which means you are still bound to the current model, where an action is only run once.

Leaving you either with one action per machine or go with the logstash approach.

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 16, 2018, 7:45am UTC](https://discuss.elastic.co/t/send-an-alert-for-each-item-in-aggregation-list/112316/3 "2018-01-16T07:45:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
