# Watcher alert on buckets data

**URL:** <https://discuss.elastic.co/t/watcher-alert-on-buckets-data/105041>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [October 24, 2017, 10:46am UTC](https://discuss.elastic.co/t/watcher-alert-on-buckets-data/105041 "2017-10-24T10:46:07Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [October 24, 2017, 10:46am UTC](https://discuss.elastic.co/t/watcher-alert-on-buckets-data/105041/1 "2017-10-24T10:46:08Z")

</div>

Hello all,  
Sorry if my question is "too basic", but I'm stuck.  
I'm implementing a prototype in order to detect fraudulent phone calls.  
I have made a query that given a time interval, returns the total duration of all the phone calls that have started and ended in such interval, by originator  
The query (probably it can be improved) returns the desired results and now I need to alert over the query results.

If the "grand\_total" is bigger than the duration of interval, then I need to raise an alert.  
Based on the approach explained in

> **[Implementing a Statistical Anomaly Detector in Elasticsearch - Part 3](https://www.elastic.co/blog/implementing-a-statistical-anomaly-detector-part-3)**
>
> In the final article of this three-part series, we build a fully automated anomaly detector using Watcher to send email alerts.

I have tried to extract the relevant data for my alert that is the "key" and the "grand\_total" without success.  
In the simulation I get the following error

**_"Watcher: [parse\_exception] could not parse input for watch [inlined]. expected an object representing input [extract], but found [START\_ARRAY] instead"_**  
Here is the code

{  
"trigger": {  
"schedule": {  
"interval": "30m"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"new\_sbc"  
],  
"types": [],  
"body": {  
"query": {  
"bool": {  
"filter": [  
{  
"terms": {  
"oper.keyword": [  
"START",  
"STOP"  
]  
}  
},  
{  
"range": {  
"@timestamp": {  
"gte": "2017-10-04T20:46:00.000Z",  
"lte": "2017-10-04T20:49:10.000Z"  
}  
}  
}  
]  
}  
},  
"aggs": {  
"origin": {  
"terms": {  
"field": "from.keyword",  
"size": 10000,  
"min\_doc\_count": 2  
},  
"aggs": {  
"call\_ref": {  
"terms": {  
"field": "call\_ref.keyword",  
"size": 10000,  
"min\_doc\_count": 2  
},  
"aggs": {  
"total\_duration": {  
"sum": {  
"field": "duration"  
}  
}  
}  
},  
"grand\_total": {  
"sum\_bucket": {  
"buckets\_path": "call\_ref\>total\_duration"  
}  
}  
}  
}  
}  
}  
}  
},  
"extract": [  
"aggregations.origin.buckets.key",  
"aggregations.origin.buckets.grand\_total"  
]  
},  
"condition": {  
"always": {}  
},  
"actions": {  
"my-logging-action": {  
"logging": {  
"level": "info",  
"text": "There are {{ctx.payload.aggregations}} documents in your index."  
}  
}  
}  
}

I know that the information is there but I don't realize how can I access to each bucket field, either in the condition section nor in a action section.  
If I remove the extract statement, doing a simulation I can see the buckets in the logging section.

{origin={doc\_count\_error\_upper\_bound=0, sum\_other\_doc\_count=0, buckets=[{doc\_count=7, call\_ref={doc\_count\_error\_upper\_bound=0, sum\_other\_doc\_count=0, buckets=[]}, **grand\_total={value=0.0}, key=3761582160** }, {doc\_count=7, call\_ref={doc\_count\_error\_upper\_bound=0, sum\_other\_doc\_count=0, buckets=[{doc\_count=2, total\_duration={value=5.0}, key=p65539t1507142822m18319c57997507s2}, {doc\_count=2, total\_duration={value=6.0}, key=p65539t1507142871m863070c57997494s2}, {doc\_count=2, total\_duration={value=235.0}, key=p65539t1507142906m435705c57997798s2}]}, **grand\_total={value=246.0}, key=376822289** }, ...............

Any help will be appreciated  
Regards  
Anna

---

<div class="post-metadata">

**Author:** ![lueneburger](https://avatars.discourse-cdn.com/v4/letter/l/f475e1/32.png) [@lueneburger](https://discuss.elastic.co/u/lueneburger)\
**Post date:** [October 24, 2017, 2:33pm UTC](https://discuss.elastic.co/t/watcher-alert-on-buckets-data/105041/2 "2017-10-24T14:33:24Z")

</div>

HI @Anabella_Cristaldi ,

I'm a little bit confused about this 🙂

so you don't actually want to build a statistical anomaly detector, you just used it as an example for your watch?  
I would try to remove the "extract" part and change the condition to something like:

..aggregations

```
  },
  "condition": {
    "compare": {
      "ctx.payload.aggregations.grand_total.value": {
        "lt": "{{ctx.payload.aggregations.buckets.key}}"
      }
    }
  },

```

....action

something like that and take a look here:  
[compare condition](https://www.elastic.co/guide/en/x-pack/current/condition-compare.html)

Cheers,  
Dirk

---

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [October 24, 2017, 3:00pm UTC](https://discuss.elastic.co/t/watcher-alert-on-buckets-data/105041/3 "2017-10-24T15:00:54Z")

</div>

Hi @lueneburger,

Yes, you are correct. I used the anomaly detector as an example for my watch.  
I removed the extract and tried the compare condition but still not working (ctx.payload.aggregations.grand\_total.value and ctx.payload.aggregations.buckets.key are evaluated to null).

What I need is to know how to loop over the buckets in the result, access to the bucket fields (grand\_total value for example) and compare against some threshold,

Another thing that is interesting in the anomaly detector example is that they first create a new index with the "interesting" values and then alert over document on that index; but first I need how to loop and access to the values in the result.

Thank you very much!  
Regards  
Ana

---

<div class="post-metadata">

**Author:** ![lueneburger](https://avatars.discourse-cdn.com/v4/letter/l/f475e1/32.png) [@lueneburger](https://discuss.elastic.co/u/lueneburger)\
**Post date:** [October 24, 2017, 3:20pm UTC](https://discuss.elastic.co/t/watcher-alert-on-buckets-data/105041/4 "2017-10-24T15:20:43Z")

</div>

Hi @Anabella_Cristaldi,

could you provide a Simulation Result without the extract, you copy & paste it here and mark all the output here and press Ctrl + Shift + C, then you will keep the format and its easier to read 🙂

Cheers,  
Dirk

---

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [October 25, 2017, 11:40am UTC](https://discuss.elastic.co/t/watcher-alert-on-buckets-data/105041/5 "2017-10-25T11:40:26Z")

</div>

Thanks @lueneburger for your suggestion of using Array Compare Condition. It worked like a charm.

```
"array_compare": {
  "ctx.payload.aggregations.origin.buckets": {
    "path": "grand_total.value",
    "gt": {
      "value": 340,
      "quantifier": "some"
    }
  }
}

```

},

I have also tried an script condition that worked ok.

"condition": {  
"script": {  
"source": "def status= false;def calls=ctx.payload.aggregations.origin;for (int i = 0; i \< calls.size(); ++i) {if (calls.buckets[i].grand\_total.value \> 346){ status=true;return status}} return false",  
"lang": "painless"  
}

Thanks!  
Regards  
Anna

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 22, 2017, 11:40am UTC](https://discuss.elastic.co/t/watcher-alert-on-buckets-data/105041/6 "2017-11-22T11:40:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
