# Watcher - Sending x number of emails per hit

**URL:** <https://discuss.elastic.co/t/watcher-sending-x-number-of-emails-per-hit/128931>\
**Category:** Elasticsearch\
**Created:** [April 20, 2018, 7:55pm UTC](https://discuss.elastic.co/t/watcher-sending-x-number-of-emails-per-hit/128931 "2018-04-20T19:55:17Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![pstobbe\_corett](https://avatars.discourse-cdn.com/v4/letter/p/f04885/32.png) [@pstobbe\_corett](https://discuss.elastic.co/u/pstobbe_corett)\
**Post date:** [April 20, 2018, 7:55pm UTC](https://discuss.elastic.co/t/watcher-sending-x-number-of-emails-per-hit/128931/1 "2018-04-20T19:55:17Z")

</div>

Hi,

I'm trying to setup a watcher so that based on the number on hits in my query send out that number of emails.  
It seems to me that this can't be done by simply looping around the email action so I have an idea but need help on the implementation.

My idea is to grab the top hit sorted by time (ascending), save that hit using an index action, and then send an email out for that hit. Also in the query will be a script query that will filter out hits that have already been alerted. ie. Comparing with doc created by index action on certain fields

What I am missing so far is getting the index action to create a doc based on my hit and then the compare script query. (I have removed my email address but i can confirm that that is working fine)

My first priority is for my hit to be created as a doc. Example below.

```
{
    "trigger": {
        "schedule": {
            "interval": "1m"
        }
    },
    "input": {
        "search": {
            "request": {
                "search_type": "query_then_fetch",
                "indices": [
                    "metricbeat*"
                ],
                "types": [],
                "body": {
                    "from": 0,
                    "size": 1,
                    "query": {
                        "bool": {
                            "filter": {
                                "bool": {
                                    "must": [
                                        {
                                            "range": {
                                                "@timestamp": {
                                                    "gte": "{{ctx.trigger.scheduled_time}}||-60m",
                                                    "lte": "{{ctx.trigger.scheduled_time}}",
                                                    "format": "strict_date_optional_time||epoch_millis"
                                                }
                                            }
                                        },
                                        {
                                            "range": {
                                                "system.cpu.total.pct": {
                                                    "gt": "0.2"
                                                }
                                            }
                                        }
                                    ]
                                }
                            }
                        }
                    },
                    "sort": {
                        "@timestamp": {
                            "order": "asc"
                        }
                    }
                }
            }
        }
    },
    "condition": {
        "compare": {
            "ctx.payload.hits.total": {
                "gte": 1
            }
        }
    },
    "actions": {
        "index_payload": {
            "index": {
                "index": "metricbeat-watcher",
                "doc_type": "doc"
            }
        },
        "send_email": {
            "email": {
                "profile": "standard",
                "to": [
                    ""
                ],
                "body": {
                    "text": "There are {{ctx.payload.hits.total}} documents in your index. Threshold is 1. {{ctx.payload.hits.hits.0._source.system.cpu.total.pct}}"
                }
            }
        }
    }
}

```

When I try to search for any documents on my index metricbeat-watcher I get zero hits so i'm thinking that some type of transform is needed in the index action? (i get over 1000 hits for hits total so no problem with that)

If anyone has any suggestions or alternative solutions that would be much appreciated.

Regards, Patrick

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 23, 2018, 1:19pm UTC](https://discuss.elastic.co/t/watcher-sending-x-number-of-emails-per-hit/128931/2 "2018-04-23T13:19:58Z")

</div>

Hey,

this is currently not possible with watcher, an action can only be executed once. A valid workaround would be to maybe send your data to logstash, process it using the http input and then use the [email output plugin](https://www.elastic.co/guide/en/logstash/6.2/plugins-outputs-email.html) to send an email?

--Alex

---

<div class="post-metadata">

**Author:** ![pstobbe\_corett](https://avatars.discourse-cdn.com/v4/letter/p/f04885/32.png) [@pstobbe\_corett](https://discuss.elastic.co/u/pstobbe_corett)\
**Post date:** [April 23, 2018, 1:45pm UTC](https://discuss.elastic.co/t/watcher-sending-x-number-of-emails-per-hit/128931/3 "2018-04-23T13:45:43Z")

</div>

Thanks Alex, i'll take a look at your suggestion! In my current example though I am only trying to execute each action once (index and email). Just wondering why my index action is not currently working or if my syntax is incorrect (is a transform required in an index action?).  
Snippet from above:

```
"index_payload": {
    "index": {
        "index": "metricbeat-watcher",
        "doc_type": "doc"
    }
}

```

Regards, Patrick

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 23, 2018, 2:07pm UTC](https://discuss.elastic.co/t/watcher-sending-x-number-of-emails-per-hit/128931/4 "2018-04-23T14:07:47Z")

</div>

please include the output of the [Execute Watch API](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/watcher-api-execute-watch.html) here for further debugging

---

<div class="post-metadata">

**Author:** ![pstobbe\_corett](https://avatars.discourse-cdn.com/v4/letter/p/f04885/32.png) [@pstobbe\_corett](https://discuss.elastic.co/u/pstobbe_corett)\
**Post date:** [April 23, 2018, 2:42pm UTC](https://discuss.elastic.co/t/watcher-sending-x-number-of-emails-per-hit/128931/5 "2018-04-23T14:42:45Z")

</div>

Hi Alex,

Of course!  
The output was too big to post here so I have shared the output at the link below.  
[Watch Output](https://goo.gl/3CDKK7)

Regards, Patrick

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 23, 2018, 2:56pm UTC](https://discuss.elastic.co/t/watcher-sending-x-number-of-emails-per-hit/128931/6 "2018-04-23T14:56:46Z")

</div>

hey Patrick,

that looks like a successful run.

A new document has been created as `metricbeat-watcher/doc/c-7h8mIB1iKSZXGXi6FM` and the email seems to have been sent successful as well.

You can see it in `watch_record.result.actions.0.index.response`.

Hope this helps.

--Alex

---

<div class="post-metadata">

**Author:** ![pstobbe\_corett](https://avatars.discourse-cdn.com/v4/letter/p/f04885/32.png) [@pstobbe\_corett](https://discuss.elastic.co/u/pstobbe_corett)\
**Post date:** [April 23, 2018, 3:06pm UTC](https://discuss.elastic.co/t/watcher-sending-x-number-of-emails-per-hit/128931/7 "2018-04-23T15:06:30Z")

</div>

Thanks Alex, you have been a great help! I think the issue was that I was just using the Discover page on Kibana and couldn't see results from there. I can see there have been multiple docs created using a GET request from the console.

Regards, Patrick

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 21, 2018, 3:06pm UTC](https://discuss.elastic.co/t/watcher-sending-x-number-of-emails-per-hit/128931/8 "2018-05-21T15:06:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
