# Wildcard suffix for indicies, aggregate for each index

**URL:** <https://discuss.elastic.co/t/wildcard-suffix-for-indicies-aggregate-for-each-index/316779>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [October 17, 2022, 12:20pm UTC](https://discuss.elastic.co/t/wildcard-suffix-for-indicies-aggregate-for-each-index/316779 "2022-10-17T12:20:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![daekblad](https://avatars.discourse-cdn.com/v4/letter/d/c2a13f/32.png) [@daekblad](https://discuss.elastic.co/u/daekblad)\
**Post date:** [October 17, 2022, 12:20pm UTC](https://discuss.elastic.co/t/wildcard-suffix-for-indicies-aggregate-for-each-index/316779/1 "2022-10-17T12:20:40Z")

</div>

Hi,

I have this watcher that checks for errors and sends an e-mail if any error is found. It's setup so that it checks a wildcard index patterns ("services-\*"). There are too many services so a wildcard is a must since we do not want to manage multiple watchers.

Anyway, the watcher sends an e-mail with the number of errors and an excerpt from a stacktrace once it's identified one or more errors.

This has served us well but I've started to think about how to modify the watcher in a way so that the e-mail body would include a list with each index and the numbers of errors, e.g.

```auto
18 errors found.
  * 9: service-name-1 (underlying index pattern would work)
  * 6: service-name-2
  * 3: service-name-42

```

Is that doable?

And for reference this is the current watcher in question:

```auto
{
  "trigger": {
    "schedule": {
      "interval": "1m"
    }
  },
  "throttle_period" : "1m",
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "services-*"
          //more wildcards here
        ],
        "rest_total_hits_as_int": true,
        "body": {
          "query": {
            "bool": {
              "must": [
                {
                  "query_string": {
                    "query": "level:Error"
                  }
                },
                {
                  "range": {
                    "@timestamp": {
                      "gte": "now-1m"
                    }
                  }
                }
              ]
            }
          },
          "_source": [
            "message"
          ],
          "sort": [
            {
              "@timestamp": {
                "order": "desc"
              }
            }
          ]
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "gt": 0
      }
    }
  },
  "actions": {
    "send_email": {
      "email": {
        "profile": "standard",
        "to": [
          "account@hostname"
        ],
        "subject": "Log watcher [{{ctx.metadata.name}}]",
        "body": {
          "text": """{{ctx.payload.hits.total}} errors found.

{{ctx.payload}}
"""
        }
      }
    }
  },
  "throttle_period_in_millis": 180000
}

```

---

<div class="post-metadata">

**Author:** ![daekblad](https://avatars.discourse-cdn.com/v4/letter/d/c2a13f/32.png) [@daekblad](https://discuss.elastic.co/u/daekblad)\
**Post date:** [October 18, 2022, 7:29pm UTC](https://discuss.elastic.co/t/wildcard-suffix-for-indicies-aggregate-for-each-index/316779/2 "2022-10-18T19:29:00Z")

</div>

I managed to fix it using aggregations, pretty neat. 🙂

```auto
{
  "trigger": {
    "schedule": {
      "interval": "1m"
    }
  },
  "throttle_period" : "1m",
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "services-*"
          //more wildcards here
        ],
        "rest_total_hits_as_int": true,
        "body": {
          "query": {
            "bool": {
              "must": [
                {
                  "query_string": {
                    "query": "level:Error"
                  }
                },
                {
                  "range": {
                    "@timestamp": {
                      "gte": "now-1m"
                    }
                  }
                }
              ]
            }
          },
          "aggs": {
            "by_index": {
              "terms": {
                "field": "_index",
                "size": "100"
              }
            }
          },
          "_source": [
            "message"
          ],
          "sort": [
            {
              "@timestamp": {
                "order": "desc"
              }
            }
          ]
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "gt": 0
      }
    }
  },
  "actions": {
    "send_email": {
      "email": {
        "profile": "standard",
        "to": [
          "account@hostname"
        ],
        "subject": "Log watcher [{{ctx.metadata.name}}]",
        "body": {
          "text": """{{ctx.payload.hits.total}} errors found.

{{#ctx.payload.aggregations.by_index.buckets}}
  {{doc_count}} error(s) in {{key}}
{{/ctx.payload.aggregations.by_index.buckets}}
"""
        }
      }
    }
  },
  "throttle_period_in_millis": 180000
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 15, 2022, 7:29pm UTC](https://discuss.elastic.co/t/wildcard-suffix-for-indicies-aggregate-for-each-index/316779/3 "2022-11-15T19:29:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
