# Watcher - Webhook action iterate through aggregated results and show it in json format

**URL:** <https://discuss.elastic.co/t/watcher-webhook-action-iterate-through-aggregated-results-and-show-it-in-json-format/74597>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [February 10, 2017, 5:03am UTC](https://discuss.elastic.co/t/watcher-webhook-action-iterate-through-aggregated-results-and-show-it-in-json-format/74597 "2017-02-10T05:03:48Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![meenu74](https://avatars.discourse-cdn.com/v4/letter/m/e5b9ba/32.png) [@meenu74](https://discuss.elastic.co/u/meenu74)\
**Post date:** [February 10, 2017, 5:03am UTC](https://discuss.elastic.co/t/watcher-webhook-action-iterate-through-aggregated-results-and-show-it-in-json-format/74597/1 "2017-02-10T05:03:48Z")

</div>

I am creating a watch which queries and aggregates the output. How do I loop through the aggregated results and create a json format and send through web hook. Tried various solutions but still stuck it. Any help will be appreciated.

PUT \_xpack/watcher/watch/iad\_watch  
{  
"trigger" : { "schedule" : { "interval" : "60s" }},  
"input" : {  
"search" : {  
"request" : {  
"body" : {  
"query" : {  
"bool" : {  
"must" : [

```
                             {"match" : {"type":"iad" }},
                             {"match" : {"priority":"ERROR" }}
                       ],
                       "filter" : {
                           "range" : {
                                    "@timestamp" : {
                                           "gte" : "now-1d",
                                           "lt" : "now"
                                    }
                           }
                       },
            ,
                  "size" :0,
                  "aggs": {
                    "analyst_name": {
                      "terms": {
                         "field": "iAnalyst.keyword"   
                        },
                    "aggs": {
                      "group_docs": {
                        "top_hits": {
                            "size": 1,
                            "sort": [
                            {
                              "@timestamp": {
                                "order": "desc"
                                }
                            }
                          ]
                        }
                    }
                  }
                }
            }
                     
             }
          }
      }
  }
}

```

},  
"condition" : {  
"compare" : { "ctx.payload.hits.total" : { "gt" : 0 }}  
},  
"actions" : {  
"iad\_webhook" : {  
"webhook" : {  
"auth" : {  
"basic" : {  
"username" : "admin",  
"password" : "admin"  
}  
},  
"method" : "POST",  
"host" : "172.18.187.151",  
"port" : 8161,  
"path" : "/api/message",  
"params" : {  
"destination" : "topic://TOPIC.IAD.WATCHER.ERRORS"  
},  
"headers" : {  
"Content-Type" : "application/json"  
},  
"body" : "{ "total\_errors" : {{ctx.payload.hits.total}}, "iAnalyst" : "{{ctx.payload.aggregate.analyst\_name.hits.hits.0.\_source.iAnalyst}}", "iAnalystHost" : "{{ctx.payload.aggregate.analyst\_name.hits.hits.0.\_source.host}}", "last\_error\_message" : "{{ctx.payload.aggregate.analyst\_name.hits.hits.0.\_source.message}}", "error\_datetime" : "{{ctx.payload.aggregate.analyst\_name.hits.hits.0.\_source.@timestamp}}" }"

```
       }
  }

```

}}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 10, 2017, 7:52am UTC](https://discuss.elastic.co/t/watcher-webhook-action-iterate-through-aggregated-results-and-show-it-in-json-format/74597/2 "2017-02-10T07:52:11Z")

</div>

Hey,

please take your time to properly format your messages in markdown. This makes it real hard to read.

You can loop through an list of items like this

```nohighlight
{{#ctx.payload.aggregate.analyst_name.hits.hits}}
Host: {{_source.host}} Message: {{_source.message}}
{{/ctx.payload.aggregate.analyst_name.hits.hits.}}

```

--Alex

---

<div class="post-metadata">

**Author:** ![meenu74](https://avatars.discourse-cdn.com/v4/letter/m/e5b9ba/32.png) [@meenu74](https://discuss.elastic.co/u/meenu74)\
**Post date:** [February 10, 2017, 3:38pm UTC](https://discuss.elastic.co/t/watcher-webhook-action-iterate-through-aggregated-results-and-show-it-in-json-format/74597/3 "2017-02-10T15:38:38Z")

</div>

Thanks Alexander Reelsen. Sorry about formatting. Are there tags to wrap the code.

I tried the recommendations as below. Not sure what I am missing, but I dont see any results

"actions" : {  
"log" : {  
"logging" : {  
"text" : "Encountered: {{ctx.payload.hits.total}} in the last hour on {{#ctx.payload.aggregations.analyst\_name.hits.hits}}{{\_source.host}}: {{\_source.message}}, {{/ctx.payload.aggregations.analyst\_name.hits.hits}}"

```
       }
  }

```

}

Below is the ouput of the search query I sent in my original post. I am trying to parse results from aggregations tags.

{  
"took": 17,  
"timed\_out": false,  
"\_shards": {  
},  
"hits": {  
"total": 67,  
"max\_score": 0,  
"hits": []  
},  
"aggregations": {  
"analyst\_name": {  
"doc\_count\_error\_upper\_bound": 0,  
"sum\_other\_doc\_count": 0,  
"buckets": [  
{  
"key": "mockb-1",  
"doc\_count": 66,  
"group\_docs": {  
"hits": {  
"total": 66,  
"max\_score": null,  
"hits": [  
{  
"\_index": "iad-2017.02.08",  
"\_type": "iad",  
"\_id": "AVob5Fd0epr-8jzLv2J3",  
"\_score": null,  
"\_source": {  
"method": "?",  
"thread": "analystDesktop-5637-MacBook-Pro.local6dd6-1",  
"message": "I am testing IAD error logging to logstash",  
"priority": "ERROR",  
"type": "iad",  
"path": "net.interactions.ianalyst.jms.IADMessageReceiver",  
"@timestamp": "2017-02-08T04:03:53.833Z",  
"file": "?:?",  
"iAnalyst": "mockb-1",  
"@version": "1",  
"host": "172.18.187.85:57938",  
"logger\_name": "net.interactions.ianalyst.jms.IADMessageReceiver",  
"class": "?",  
"timestamp": 1486526633765  
},  
"sort": [  
1486526633833  
]  
}  
]  
}  
}  
},  
{  
"key": "mockb-3",  
"doc\_count": 1,  
"group\_docs": {  
"hits": {  
"total": 1,  
"max\_score": null,  
"hits": [  
{  
"\_index": "iad-2017.02.07",  
"\_type": "iad",  
"\_id": "AVol6L7Repr-8jzL094Y",  
"\_score": null,  
"\_source": {  
"message": "I am testing IAD error logging to logstash",  
"priority": "ERROR",  
"type": "iad",  
"@timestamp": "2017-02-08T21:03:53.833Z",  
"iAnalyst": "mockb-3",  
"host": "172.18.187.85:57938"  
},  
"sort": [  
1486587833833  
]  
}  
]  
}  
}  
}  
]  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 10, 2017, 3:59pm UTC](https://discuss.elastic.co/t/watcher-webhook-action-iterate-through-aggregated-results-and-show-it-in-json-format/74597/4 "2017-02-10T15:59:15Z")

</div>

You can use [common markdown](http://commonmark.org/help/) to format your posts.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 10, 2017, 4:00pm UTC](https://discuss.elastic.co/t/watcher-webhook-action-iterate-through-aggregated-results-and-show-it-in-json-format/74597/5 "2017-02-10T16:00:10Z")

</div>

Also, please take your time and compare your script example with the path of the json data, you will find the buckets field missing for example.

---

<div class="post-metadata">

**Author:** ![meenu74](https://avatars.discourse-cdn.com/v4/letter/m/e5b9ba/32.png) [@meenu74](https://discuss.elastic.co/u/meenu74)\
**Post date:** [February 10, 2017, 6:28pm UTC](https://discuss.elastic.co/t/watcher-webhook-action-iterate-through-aggregated-results-and-show-it-in-json-format/74597/6 "2017-02-10T18:28:54Z")

</div>

Thanks Alexander. That was useful.  
Future reference on how to iterate the nested arrays in watcher using mustang

> "{ "total\_errors" : {{ctx.payload.hits.total}},{{#ctx.payload.aggregations.analyst\_name.buckets}}{{#group\_docs.hits.hits}} {"iAnalyst" : "{{\_source.iAnalyst}}", "iAnalystHost" : "{{\_source.host}}", "last\_error\_message" : "{{\_source.message}}", "error\_datetime" : "{{\_source.@timestamp}}"}, {{/group\_docs.hits.hits}}{{/ctx.payload.aggregations.analyst\_name.buckets}}"

---

<div class="post-metadata">

**Author:** ![kh7](https://avatars.discourse-cdn.com/v4/letter/k/b19c9b/32.png) [@kh7](https://discuss.elastic.co/u/kh7)\
**Post date:** [February 23, 2017, 9:31pm UTC](https://discuss.elastic.co/t/watcher-webhook-action-iterate-through-aggregated-results-and-show-it-in-json-format/74597/7 "2017-02-23T21:31:39Z")

</div>

Thanks, this was really helpful for me too. Is there a way to show all hits in the alert rather than just 10?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 24, 2017, 7:54am UTC](https://discuss.elastic.co/t/watcher-webhook-action-iterate-through-aggregated-results-and-show-it-in-json-format/74597/8 "2017-02-24T07:54:33Z")

</div>

please open new threads instead of appending to older ones.

You may want to check out `size` parameter of the `terms` aggregation

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 24, 2017, 7:54am UTC](https://discuss.elastic.co/t/watcher-webhook-action-iterate-through-aggregated-results-and-show-it-in-json-format/74597/9 "2017-03-24T07:54:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
