# Set up error transaction percentage alert email

**URL:** <https://discuss.elastic.co/t/set-up-error-transaction-percentage-alert-email/282210>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [August 23, 2021, 10:29am UTC](https://discuss.elastic.co/t/set-up-error-transaction-percentage-alert-email/282210 "2021-08-23T10:29:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![helloworld3112](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/helloworld3112/32/127579_2.png) [@helloworld3112](https://discuss.elastic.co/u/helloworld3112)\
**Post date:** [August 23, 2021, 10:29am UTC](https://discuss.elastic.co/t/set-up-error-transaction-percentage-alert-email/282210/1 "2021-08-23T10:29:13Z")

</div>

Hi all,  
I have data with the following structure:  
 ![1](https://us1.discourse-cdn.com/elastic/original/3X/3/1/3155d7c6dde3dff258c84065ea66d69ec3e57201.png)

I need an alert email every 30 seconds to count the number of each Name have ErrorCode in list [001, 002, 003] and the percentage of each Name to the total (all of ErrorCode) in the following format:

```auto
- Name: NAME1 --- error 10/116 (8.6%)
- Name: NAME2 --- error 4/8 (50%)
- Name: NAME3 --- error 17/30 (56.6%)
- Name: NAME4 --- error 26/100 (26%)

```

I have grouped Name and ErrorCode:

```auto
"query": {
            "bool": {
              "must": [
                {
                  "terms": {
                    "Name": [
                      "000",
                      "001",
                      "002",
                      "003",
                      "004",
                      "005",
                      "006",
                      "007",
                      "008",
                      "009",
	              "010"
                    ]
                  }
                }
              ],
              "filter": {
                "range": {
                  "@timestamp": {
                    "from": "{{ctx.trigger.scheduled_time}}||-5m",
                    "to": "{{ctx.trigger.triggered_time}}"
                  }
                }
              }
            }
          },
          "aggs": {
            "group_by_name": {
              "terms": {
                "field": "Name.keyword"
              },
              "aggs": {
                "group_by_errorcode": {
                  "filter": {
                    "terms": {
                      "Code": [
                        "001",
                        "002",
                        "003"
                      ]
                    }
                  }
                }
              }
            }
          }

```

Here is the returned result:

```auto
"aggregations": {
          "group_by_Name": {
            "doc_count_error_upper_bound": 46,
            "sum_other_doc_count": 2659,
            "buckets": [
              {
                "doc_count": 5331,
                "key": "Name1",
                "group_by_Error": {
                  "doc_count": 5331
                }
              },
              {
                "doc_count": 2286,
                "key": "Name2",
                "group_by_Error": {
                  "doc_count": 1036
                }
              },
              {
                "doc_count": 1710,
                "key": "Name3",
                "group_by_Error": {
                  "doc_count": 1
                }
              }

```

I have config watcher and can receive mail:

```auto
"body": {
          "html": "{{#ctx.payload.aggregations.group_by_name.buckets}}<br>- Name <b>{{key}}</b> error {{#group_by_error }}{{doc_count}}/{{/group_by_error}}{{doc_count}}</br>{{/ctx.payload.aggregations.group_by_name.buckets}}"
        }

```

The structure of the email I received:

```auto
- Name: NAME1 --- error 10/116
- Name: NAME2 --- error 4/8
- Name: NAME3 --- error 17/30
- Name: NAME4 --- error 26/100

```

How can I calculate the percentage based on the calculated data?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 25, 2021, 9:18am UTC](https://discuss.elastic.co/t/set-up-error-transaction-percentage-alert-email/282210/2 "2021-08-25T09:18:37Z")

</div>

This can be done using a [script transform](https://www.elastic.co/guide/en/elasticsearch/reference/7.14/transform-script.html)

---

<div class="post-metadata">

**Author:** ![helloworld3112](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/helloworld3112/32/127579_2.png) [@helloworld3112](https://discuss.elastic.co/u/helloworld3112)\
**Post date:** [August 26, 2021, 2:24am UTC](https://discuss.elastic.co/t/set-up-error-transaction-percentage-alert-email/282210/3 "2021-08-26T02:24:46Z")

</div>

Hi @spinscale, I did it with bucket\_script:

```auto
"success_percent": {
                  "bucket_script": {
                    "buckets_path": {
                      "error": "group_by_count_err",
                      "total": "group_by_count_all"
                    },
                    "script": "params.error/ params.total* 100",
                    "format": "0.00"
                  }
}

```

But I get all NAME values, how can I set the warning threshold for each NAME. For example: NAME 1: 80%, NAME 2: 20%... If the percentage is greater than the threshold, the NAME value will appear in the alert email.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 26, 2021, 7:56am UTC](https://discuss.elastic.co/t/set-up-error-transaction-percentage-alert-email/282210/4 "2021-08-26T07:56:07Z")

</div>

Again, this could be done in a script transform, scripting gives you the freedom to only include a part of your aggregation results that break a certain threshold 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 23, 2021, 7:56am UTC](https://discuss.elastic.co/t/set-up-error-transaction-percentage-alert-email/282210/5 "2021-09-23T07:56:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
