# Watcher, Alert all result of the payload, not only the first

**URL:** <https://discuss.elastic.co/t/watcher-alert-all-result-of-the-payload-not-only-the-first/249831>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [September 24, 2020, 2:24pm UTC](https://discuss.elastic.co/t/watcher-alert-all-result-of-the-payload-not-only-the-first/249831 "2020-09-24T14:24:25Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Incauto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incauto/32/60149_2.png) [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Post date:** [September 24, 2020, 2:24pm UTC](https://discuss.elastic.co/t/watcher-alert-all-result-of-the-payload-not-only-the-first/249831/1 "2020-09-24T14:24:26Z")

</div>

Im am quering a incident index..this index may contain documents separated by miliseconds, this is the query I have:

```auto
          "query": {
            "bool": {
              "must": [
                {
                  "match": {
                    "message": "down"
                  }
                }
              ],
              "filter": [
                {
                  "range": {
                    "@timestamp": {
                      "gte": "now-1m",
                      "lt": "now"
                    }
                  }
                }
              ]
            }
          }

```

This query may return sometime many incidentes, but watcher only return the first result of the payload

Is there a way to alert all the results on the payload?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 28, 2020, 8:16am UTC](https://discuss.elastic.co/t/watcher-alert-all-result-of-the-payload-not-only-the-first/249831/2 "2020-09-28T08:16:50Z")

</div>

You can change the number of results using the [size parameter](https://www.elastic.co/guide/en/elasticsearch/reference/7.9/paginate-search-results.html) - however if there are thousands of results this will not work either.

Maybe if you add some context, we can see if we can achieve your problem. Try explaining your problem without mentioning any technology/queries/etc 🙂

---

<div class="post-metadata">

**Author:** ![Incauto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incauto/32/60149_2.png) [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Post date:** [October 13, 2020, 9:02pm UTC](https://discuss.elastic.co/t/watcher-alert-all-result-of-the-payload-not-only-the-first/249831/3 "2020-10-13T21:02:15Z")

</div>

Hi @spinscale, sorry for the late reply,  
I get syslogs from many machines, I got to alert whenever a syslog message contains the string: "down", so in the range of one minute, could be many matches of the string "down",  
but it seems that watcher only get me the first match it finds.

Thanks!

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 14, 2020, 7:41am UTC](https://discuss.elastic.co/t/watcher-alert-all-result-of-the-payload-not-only-the-first/249831/4 "2020-10-14T07:41:15Z")

</div>

You are typically not interested in single `down` events, but rather in grouping those, for example ten `down` events from a single node do not matter, but the nodename is important.

You may want to take a look at [aggregations](https://www.elastic.co/guide/en/elasticsearch/reference/7.9/search-aggregations.html) to properly solve this.

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 11, 2020, 7:41am UTC](https://discuss.elastic.co/t/watcher-alert-all-result-of-the-payload-not-only-the-first/249831/5 "2020-11-11T07:41:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
