# Send an email alert after 3 major/critical anomalies for a given time range

**URL:** <https://discuss.elastic.co/t/send-an-email-alert-after-3-major-critical-anomalies-for-a-given-time-range/190470>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-machine-learning\
**Created:** [July 15, 2019, 9:02am UTC](https://discuss.elastic.co/t/send-an-email-alert-after-3-major-critical-anomalies-for-a-given-time-range/190470 "2019-07-15T09:02:30Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jasgc](https://avatars.discourse-cdn.com/v4/letter/j/f9ae1b/32.png) [@jasgc](https://discuss.elastic.co/u/jasgc)\
**Post date:** [July 15, 2019, 9:02am UTC](https://discuss.elastic.co/t/send-an-email-alert-after-3-major-critical-anomalies-for-a-given-time-range/190470/1 "2019-07-15T09:02:31Z")

</div>

Is there a way for a watcher to generate email alert only after encountering 3 or more major/critical anomalies for a time range (i.e. if it encounters 3 anomalies within 3 months)?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 15, 2019, 9:38am UTC](https://discuss.elastic.co/t/send-an-email-alert-after-3-major-critical-anomalies-for-a-given-time-range/190470/2 "2019-07-15T09:38:12Z")

</div>

Welcome!

What you can do is to have 2 jobs:

The alerting job you already know. It will write the result in another index.  
A new alert job on the alert index.

Building alerts on alerts is normally the way to solve it.

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [July 15, 2019, 11:51am UTC](https://discuss.elastic.co/t/send-an-email-alert-after-3-major-critical-anomalies-for-a-given-time-range/190470/3 "2019-07-15T11:51:22Z")

</div>

Certainly, you can construct a Watch to use any logic of your choosing. This, in fact, as described, can be a single Watch (assuming you have an ML job running on the data of interest).

You could, for example, in the `input` section of the watch, define a search that is over a long period of time:

```auto
 "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          ".ml-anomalies-*"
        ],
        "types": [],
        "body": {
          "size": 0,
          "query": {
            "bool": {
              "filter": [
                {
                  "term": {
                    "job_id": "myjobname"
                  }
                },
                {
                  "range": {
                    "timestamp": {
                      "gte": "now-90d"
                    }
                  }
                },
...

```

Then, in the `condition` section of the watch, specify how the condition is met:

```auto
    "condition": {
      "compare": {
        "ctx.payload.hits.total": {
          "gt": 3
        }
      }
    },

```

The above would be `true` if any 3 anomalies are seen in the last 90 days for an ML job named `myjobname`. Of course, you could add search criteria to only consider anomalies of certain types (`bucket`, `record`, `influencer`, etc.) or of a certain score (either `anomaly_score` or `record_score`).

See this blog for more information on scoring: [https://www.elastic.co/blog/machine-learning-anomaly-scoring-elasticsearch-how-it-works](https://www.elastic.co/blog/machine-learning-anomaly-scoring-elasticsearch-how-it-works)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 12, 2019, 11:51am UTC](https://discuss.elastic.co/t/send-an-email-alert-after-3-major-critical-anomalies-for-a-given-time-range/190470/4 "2019-08-12T11:51:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
