# Watcher aggregation transform painless question

**URL:** https://discuss.elastic.co/t/watcher-aggregation-transform-painless-question/317697
**Category:** Elasticsearch
**Tags:** painless
**Created:** [October 28, 2022, 3:44pm UTC](https://discuss.elastic.co/t/watcher-aggregation-transform-painless-question/317697 "2022-10-28T15:44:42Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![joe0228](https://avatars.discourse-cdn.com/v4/letter/j/91b2a8/32.png) [@joe0228](https://discuss.elastic.co/u/joe0228)
#### Post date: [October 28, 2022, 3:44pm UTC](https://discuss.elastic.co/t/watcher-aggregation-transform-painless-question/317697/1 "2022-10-28T15:44:42Z")

</div>

Trying to get the result from bucket\_script to use in the transform section - specifically v = params.value

//  
{  
"trigger": {  
"schedule": {  
"intervel": "15m"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": ["index-name"],  
"rest\_total\_hits\_as\_int": true,  
"body": {  
"size":0,  
"query": {  
"bool": {  
"must":[  
A COUPLE of QUERY strings that work to get us the data we need]  
}  
},  
"aggs": {  
"hosts": {  
"terms": {  
"field": "date-field", ------ one of our fields ------  
"order": {"\_count": "desc"}  
},  
"aggs": {  
"timeseries": {  
"auto\_date\_histogram": {  
"field": "timestamp",  
"buckets": 1  
},  
"aggs": {  
"numerator": {  
"filter": {  
"bool": {  
"must": [  
{  
"query\_string": {  
"query": " data from 1 of our fields"  
}  
}  
],  
"filter": ,  
"should": ,  
"must\_not":   
}  
},  
"aggs": {  
"metric": {  
"max": {  
"field": "value"  
}  
}  
}  
},  
"denominator": {  
"filter": {  
"bool": {  
"must": [  
{  
"query\_string": {  
"query": " data from 1 of our fields"  
}  
}  
],  
"filter": ,  
"should": ,  
"must\_not":   
}  
},  
"aggs": {  
"metric": {  
"max": {  
"field": "value"  
}  
}  
}  
},  
"percentage": {  
"bucket\_script": {  
"buckets\_path": {  
"numerator": "numerator\>metric",  
"denominator": "denominator\>metric"  
},  
"script": "params.numerator / params.denominator \* 100"  
}  
}  
}  
}  
}  
}  
}  
}  
}  
}  
},  
"conditions": {  
"always": ()  
},  
"actions": {  
"logstash\_webhook": {  
"foreach": "ctx.payload.docs",  
"max\_iterations": 500,  
"webhook": {  
SOME PORT-Host information  
"body": "{{#toJson}}ctx.payload{{toJson}}"  
}  
}  
},  
"transform": {  
"script": {  
"source": "def docs={}; for(bucket in ctx.payload.aggregations.hosts.buckets){ def color\_1='green';def val\_1=1; def v= params.value; def tt\_1 = 'Memory Usage is'+v;  
if(Double.parseDouble(v)\>70){ color\_1='yellow'; val\_1=2; }if(Double.parseDouble(v)\>=80){color\_1='red'; val\_1=3; } return ['docs': docs];",  
"lang": "painless"  
}  
}  
}

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 25, 2022, 3:44pm UTC](https://discuss.elastic.co/t/watcher-aggregation-transform-painless-question/317697/2 "2022-11-25T15:44:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
