# Watcher - email on condition that doc\_count is less than certain value

**URL:** <https://discuss.elastic.co/t/watcher-email-on-condition-that-doc-count-is-less-than-certain-value/306583>\
**Category:** Elasticsearch\
**Created:** [June 7, 2022, 3:43pm UTC](https://discuss.elastic.co/t/watcher-email-on-condition-that-doc-count-is-less-than-certain-value/306583 "2022-06-07T15:43:11Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![abidub](https://avatars.discourse-cdn.com/v4/letter/a/d07c76/32.png) [@abidub](https://discuss.elastic.co/u/abidub)\
**Post date:** [June 7, 2022, 3:43pm UTC](https://discuss.elastic.co/t/watcher-email-on-condition-that-doc-count-is-less-than-certain-value/306583/1 "2022-06-07T15:43:11Z")

</div>

Hi,

I have created a watcher that checks various target servers to see if 3 files are present at each target location.  
I have a number of locations to check.  
As the email alert must alert at a specific time, I have grouped these checks into 1 watcher.  
I only want an email to be sent if there are less than 3 files at a particular target location.

Here is my (sanitised) query:

```auto
GET /auditbeat-*/_search/
{
  "size": 0,
  "query": {
    "bool": {
      "filter": [
        {
          "range": {
            "file.ctime": {
              "gte": "now-6d/d",
              "lte": "now/d"
            }
          }
        },
                {
                  "bool": {
                    "minimum_should_match": 1,
                    "should": [
                      {
                        "query_string": {
                          "query": "(host.hostname: host123) AND (event.action: created) AND (file.path: *regex1*)"
                        }
                      },
                      {
                        "query_string": {
                          "query": "(host.hostname: host123) AND (event.action: created) AND (file.path: *regex2*)"
                        }
                      },
                      {
                        "query_string": {
                          "query": "(host.hostname: host123) AND (event.action: created) AND (file.path: *regex3*)"
                        }
                      }
                    ]
                  }
                }
              ]
            }
          },
          "sort": {
            "file.path": "desc"
          },
          "aggs": {
            "filegroup": {
              "filters": {
                "filters": [
                  {
					"query_string": {
					  "query": "(host.hostname: host123) AND (event.action: created) AND (file.path: *regex1*)"
					}
				  },
				  {
					"query_string": {
					  "query": "(host.hostname: host123) AND (event.action: created) AND (file.path: *regex2*)"
					}
				  },
				  {
					"query_string": {
					  "query": "(host.hostname: host123) AND (event.action: created) AND (file.path: *regex3*)"
					}
				  }
                ]
              },
              "aggs": {
                "host_name": {
                  "terms": {
                    "field": "host.hostname",
                    "size": 1
                  }
                },
                "server_tag": {
                  "terms": {
                    "field": "tags",
                    "size": 1
                  }
                },
                "filename": {
                  "terms": {
                    "field": "file.path",
                    "size": 100,
                    "order": {
                      "_key": "desc"
                    }
                  }
                }
              }
            }
          }
}

```

and my (sanitised) results look like this

````auto
"aggregations" : {
    "filegroup" : {
      "buckets" : [
        {
          "doc_count" : 3,
          "filename" : {
            "doc_count_error_upper_bound" : 0,
            "sum_other_doc_count" : 0,
            "buckets" : [
              {
                "key" : """myfilename1.txt""",
                "doc_count" : 1
              },
              {
                "key" : """myfilename2.txt""",
                "doc_count" : 1
              },
              {
                "key" : """myfilename3.txt""",
                "doc_count" : 1
              }
            ]
          },
          "server_tag" : {
            "doc_count_error_upper_bound" : 0,
            "sum_other_doc_count" : 3,
            "buckets" : [
              {
                "key" : "MyServerTag",
                "doc_count" : 3
              }
            ]
          },
          "host_name" : {
            "doc_count_error_upper_bound" : 0,
            "sum_other_doc_count" : 0,
            "buckets" : [
              {
                "key" : "myserverhostname",
                "doc_count" : 3
              }
            ]
          }
        },```

````

I would like an email to alert if any of the filters returns less than 3 files. In the email, I will provide details to the user of the hostname and server tag. They do not require an alert if the correct number of files exist.

Can I use filegroup.buckets.doc\_count in a condition within the email action to achieve this? I have tried so many different ways, but getting null or ctx error when simulating an alert.

My watcher email syntax looks like this (extract):

````auto
"actions": {
    "email_1": {
      "condition": {
        "compare" : { "ctx.payload.aggregations.filegroup.doc_count" : { "lt" : 3 } }
      },
      "foreach": "ctx.payload.aggregations.filegroup.buckets",
      "max_iterations": 500,
      "email": {
        "profile": "standard",
        "priority": "high",```

````

I have tried a few variations on the condition within the email action.

Any advice would be appreciated, perhaps I have the approach completely wrong.

Thank you

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [June 8, 2022, 8:52am UTC](https://discuss.elastic.co/t/watcher-email-on-condition-that-doc-count-is-less-than-certain-value/306583/2 "2022-06-08T08:52:11Z")

</div>

I have not read the whole query but the condition seems to be

```auto
"compare" : { "ctx.payload.aggregations.filegroup.buckets.doc_count" : { "lt" : 3 }

```

---

<div class="post-metadata">

**Author:** ![abidub](https://avatars.discourse-cdn.com/v4/letter/a/d07c76/32.png) [@abidub](https://discuss.elastic.co/u/abidub)\
**Post date:** [June 9, 2022, 8:47pm UTC](https://discuss.elastic.co/t/watcher-email-on-condition-that-doc-count-is-less-than-certain-value/306583/3 "2022-06-09T20:47:46Z")

</div>

Hi Tomo, thank you for that - I think I’ve tried that or something very similar, but I will double check to be 100% sure!

---

<div class="post-metadata">

**Author:** ![abidub](https://avatars.discourse-cdn.com/v4/letter/a/d07c76/32.png) [@abidub](https://discuss.elastic.co/u/abidub)\
**Post date:** [June 14, 2022, 10:50am UTC](https://discuss.elastic.co/t/watcher-email-on-condition-that-doc-count-is-less-than-certain-value/306583/4 "2022-06-14T10:50:54Z")

</div>

FYI the doc\_count returned 'null'

I am trying with the array\_compare now on the email action, but the alert is emailing for each of the queries, rather than just the one that fails.

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [June 14, 2022, 2:30pm UTC](https://discuss.elastic.co/t/watcher-email-on-condition-that-doc-count-is-less-than-certain-value/306583/5 "2022-06-14T14:30:58Z")

</div>

How about

```auto
"compare" : { "ctx.payload.aggregations.filegroup.buckets[0].doc_count" : { "lt" : 3 }

```

?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 12, 2022, 2:31pm UTC](https://discuss.elastic.co/t/watcher-email-on-condition-that-doc-count-is-less-than-certain-value/306583/6 "2022-07-12T14:31:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
