# Watch - Unique count

**URL:** <https://discuss.elastic.co/t/watch-unique-count/122669>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [March 6, 2018, 8:35am UTC](https://discuss.elastic.co/t/watch-unique-count/122669 "2018-03-06T08:35:49Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [March 6, 2018, 8:35am UTC](https://discuss.elastic.co/t/watch-unique-count/122669/1 "2018-03-06T08:35:49Z")

</div>

Hi All,

Could any one help me to get this watch done.

I was trying to execute a watch for the condition,when a unique count of event\_data.TargetUserName has more than 4 entries in 24 hours

```auto

{

"trigger": {

 "schedule": {

  "interval": "24h"

 }

},

"input": {

 "search": {

  "request": {

   "indices": [

    "winlogbeat-*"

   ],

   "body": {

    "size": 0,

    "query": {

     "bool": {

      "filter": [

       {

        "range": {

         "@timestamp": {

          "gte": "now-24h"

         }

        }

       },

   "aggs" : {

   "type_count" : {

     "cardinality" : {

       "field" : "event_data.TargetUserName"

     }

   }

 },

"condition": {

 "compare": {

  "ctx.payload.hits.total": {

   "gt": 4

  }

 }

},

"actions": {

 "send_email": {

  "email": {

   "profile": "standard",

   "to": [

    "my email"

   ],

   "subject": "Unique count exceeded

   "body": {

    "text": "Unique count exceeded"

   }

  }

 }

},

"throttle_period_in_millis": 900000

}

```

but it says invalid json

Thanks,  
Raj

---

<div class="post-metadata">

**Author:** ![None123455555](https://avatars.discourse-cdn.com/v4/letter/n/7ea924/32.png) [@None123455555](https://discuss.elastic.co/u/None123455555)\
**Post date:** [March 8, 2018, 11:00am UTC](https://discuss.elastic.co/t/watch-unique-count/122669/2 "2018-03-08T11:00:44Z")

</div>

while scanning your post i noticed the line:

> "subject": "Unique count exceeded

youre missing a quote and a comma at the end of this line

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [March 8, 2018, 5:27pm UTC](https://discuss.elastic.co/t/watch-unique-count/122669/3 "2018-03-08T17:27:06Z")

</div>

Thank you for the reply, but I couldn't execute this , should i use cardinality for unique count and please help me to get watch execute

{  
"error": {  
"root\_cause": [  
{  
"type": "parse\_exception",  
"reason": "could not parse watch execution request. unexpected object field [trigger]"  
}  
],  
"type": "parse\_exception",  
"reason": "could not parse watch execution request. unexpected object field [trigger]"  
},  
"status": 400  
}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 8, 2018, 6:24pm UTC](https://discuss.elastic.co/t/watch-unique-count/122669/4 "2018-03-08T18:24:40Z")

</div>

please take your time to read the docs about the [execute watch API](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/watcher-api-execute-watch.html), as it states that you need to wrap your watch into a `watch` field in the execute watch api, as this API takes more parameters.

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [March 9, 2018, 8:34am UTC](https://discuss.elastic.co/t/watch-unique-count/122669/5 "2018-03-09T08:34:03Z")

</div>

Thank you so much for the info, could please help me to get this condition alone. Condition is to execute a watch , **when a unique count of event\_data.TargetUserName has more than 4 entries in 24 hours** , i dont know if i should use cardinality or what function.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 15, 2018, 9:03pm UTC](https://discuss.elastic.co/t/watch-unique-count/122669/6 "2018-03-15T21:03:27Z")

</div>

please take your time to properly debug the search first. You will see that the hitcount is not what you are after, but the distiinct count somewhere deep in the `aggs` field.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 12, 2018, 9:03pm UTC](https://discuss.elastic.co/t/watch-unique-count/122669/7 "2018-04-12T21:03:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
