please take your time to read the docs about the execute watch API, as it states that you need to wrap your watch into a watch field in the execute watch api, as this API takes more parameters.
Thank you so much for the info, could please help me to get this condition alone. Condition is to execute a watch ,when a unique count of event_data.TargetUserName has more than 4 entries in 24 hours, i dont know if i should use cardinality or what function.
please take your time to properly debug the search first. You will see that the hitcount is not what you are after, but the distiinct count somewhere deep in the aggs field.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.