# Watcher applying aggregations on all the documents, Need to apply aggregrations only from Now -2m to Now

**URL:** <https://discuss.elastic.co/t/watcher-applying-aggregations-on-all-the-documents-need-to-apply-aggregrations-only-from-now-2m-to-now/186698>\
**Category:** Elasticsearch\
**Created:** [June 20, 2019, 1:35pm UTC](https://discuss.elastic.co/t/watcher-applying-aggregations-on-all-the-documents-need-to-apply-aggregrations-only-from-now-2m-to-now/186698 "2019-06-20T13:35:35Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vsalunkhe](https://avatars.discourse-cdn.com/v4/letter/v/eada6e/32.png) [@vsalunkhe](https://discuss.elastic.co/u/vsalunkhe)\
**Post date:** [June 20, 2019, 1:35pm UTC](https://discuss.elastic.co/t/watcher-applying-aggregations-on-all-the-documents-need-to-apply-aggregrations-only-from-now-2m-to-now/186698/1 "2019-06-20T13:35:35Z")

</div>

Hi,

I am trying to implement watcher to monitor the the elastic stack components:  
3 elasticsearch servers  
2 logstash servers  
1 kibana server

I need to aggregate the Filesystem Use Percent for each of the components for last two minutes and check whether the highest value is greater than say 49 percent.

But the aggregation is performed on over all documents so I am getting the highest and same value each time and not the highest value in last two minutes.

The watcher is..

{  
"trigger": {  
"schedule": {  
"interval": "10h"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"metricbeat\*"  
],  
"types": ,  
"body": {  
"size": 1,  
"query": {  
"bool": {  
"should": [  
{  
"match\_phrase": {  
"beat.hostname": "elsearchdv1"  
}  
},  
{  
"match\_phrase": {  
"beat.hostname": "elsearchdv2"  
}  
},  
{  
"match\_phrase": {  
"beat.hostname": "elsearchdv3"  
}  
},  
{  
"match\_phrase": {  
"beat.hostname": "logstashdv"  
}  
},  
{  
"match\_phrase": {  
"beat.hostname": "logstashdv2"  
}  
},  
{  
"match\_phrase": {  
"beat.hostname": "kibanadv"  
}  
}  
],  
"minimum\_should\_match": 1  
}  
},  
"aggs": {  
"range": {  
"date\_range": {  
"field": "@timestamp",  
"ranges": [  
{  
"to": "now-2m"  
},  
{  
"from": "now"  
}  
]  
}  
},  
"host": {  
"terms": {  
"field": "beat.hostname",  
"size": 10,  
"order": {  
"pct": "desc"  
}  
},  
"aggs": {  
"pct": {  
"max": {  
"field": "system.filesystem.used.pct",  
"script": {  
"source": "doc['system.filesystem.used.pct'].value \*100",  
"lang": "painless"  
}  
}  
}  
}  
}  
}  
}  
}  
}  
},  
"condition": {  
"compare": {  
"ctx.payload.aggregations.host.buckets.0.pct.value": {  
"gt": 49  
}  
}  
},  
"actions": {  
"send\_email": {  
"email": {  
"profile": "standard",  
"to": [  
"mail\_id.com"  
],  
"subject": "High FS Usage",  
"body": {  
"html": "{{ctx.payload}}"  
}  
}  
}  
}  
}

The output is.....  
{\_shards={total=50, failed=0, successful=50, skipped=0}, hits={hits=[{\_index=metricbeat-6.7.1-2019.06.20, \_type=doc, \_source={@timestamp=2019-06-19T19:00:07.742Z, system={network={in={bytes=8417351752231, dropped=375874, errors=0, packets=6010897628}, name=eth0, out={bytes=5720247058228, dropped=0, packets=1297085121, errors=0}}}, beat={hostname=elsearchdv1, name=elsearchdv1, version=6.7.1}, host={os={codename=Maipo, name=Red Hat Enterprise Linux Server, family=, version=7.6 (Maipo), platform=rhel}, containerized=true, name=elsearchdv1, id=c0c14a6b5a364b5eae58d506fdd61dca, architecture=x86\_64}, metricset={rtt=266, module=system, name=network}, event={duration=266760, dataset=system.network}}, \_id=M7QccWsB9ckpm5avTSGq, \_score=6.07065}], total=51347588, max\_score=6.07065}, took=1794, timed\_out=false, aggregations={host={doc\_count\_error\_upper\_bound=0, sum\_other\_doc\_count=0, buckets=[{pct={value=100.0}, doc\_count=254135, key=logstashdv}, {pct={value=100.0}, doc\_count=254953, key=logstashdv2}, {pct={value=73.2}, doc\_count=221815, key=elsearchdv3}, {pct={value=71.1}, doc\_count=217809, key=elsearchdv1}, {pct={value=70.0}, doc\_count=220226, key=elsearchdv2}, {pct={value=42.9}, doc\_count=50178650, key=kibanadv}]}, range={buckets=[{doc\_count=51347588, to\_as\_string=2019-06-20T13:34:18.219Z, to=1.561037658219E12, key=_-2019-06-20T13:34:18.219Z}, {from\_as\_string=2019-06-20T13:32:18.219Z, doc\_count=12456, from=1.561037538219E12, key=2019-06-20T13:32:18.219Z-_}]}}}

---

<div class="post-metadata">

**Author:** ![martinr\_ubi](https://avatars.discourse-cdn.com/v4/letter/m/b5e925/32.png) [@martinr\_ubi](https://discuss.elastic.co/u/martinr_ubi)\
**Post date:** [June 21, 2019, 12:14pm UTC](https://discuss.elastic.co/t/watcher-applying-aggregations-on-all-the-documents-need-to-apply-aggregrations-only-from-now-2m-to-now/186698/2 "2019-06-21T12:14:52Z")

</div>

Hi,

In the bool child of your query, you need to filter on a time range, the one you're interested in.

See the example here for many ways to do it:

> **[elastic/examples](https://github.com/elastic/examples/tree/master/Alerting/Sample%2520Watches)**
>
> Home for Elasticsearch examples available to everyone. It's a great way to get started. - elastic/examples

Maybe even try to start from one of them and change it into what you want piece by piece to learn more quickly by examples. Many aspects of ES queries are at play here and they all have their meanings. The time range your interested in doesn't go in the aggs part of your query. The different examples will cover much of those cases.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 19, 2019, 12:15pm UTC](https://discuss.elastic.co/t/watcher-applying-aggregations-on-all-the-documents-need-to-apply-aggregrations-only-from-now-2m-to-now/186698/3 "2019-07-19T12:15:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
