# Alert on percentage

**URL:** <https://forum.opensearch.org/t/alert-on-percentage/1423>\
**Category:** Alerting\
**Created:** [August 28, 2019, 8:56am UTC](https://forum.opensearch.org/t/alert-on-percentage/1423 "2019-08-28T08:56:34Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tuckson](https://avatars.discourse-cdn.com/v4/letter/t/f14d63/32.png) [@Tuckson](https://forum.opensearch.org/u/Tuckson)\
**Post date:** [August 28, 2019, 8:56am UTC](https://forum.opensearch.org/t/alert-on-percentage/1423/1 "2019-08-28T08:56:34Z")

</div>

Hi,

Is it possible to take the count of 2 queries in a certain timeframe, calculate what percentage the one is from the other (let’s say, total nr of requests and number of unsuccessful requests) and then alert on that percentage?.

So basically I take a timeperiod, let’s say 5 mins. I count the nr. of documents and I count a subset of that. Then the percentage this subset is of the total is calculated and I alert if this exceeds a certain treshold. Hope I make clear what I intent to.

Have been looking at the kibana with some sample data, but it feels rather limited, so I suppose I need some workaround on this (Am not very familiair with kibana/ELK internals yet)?

THIA

---

<div class="post-metadata">

**Author:** ![Tuckson](https://avatars.discourse-cdn.com/v4/letter/t/f14d63/32.png) [@Tuckson](https://forum.opensearch.org/u/Tuckson)\
**Post date:** [September 27, 2019, 11:03am UTC](https://forum.opensearch.org/t/alert-on-percentage/1423/2 "2019-09-27T11:03:24Z")

</div>

Nobody? Would really appreciate some replies?

---

<div class="post-metadata">

**Author:** ![lucaswin-amzn](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/lucaswin-amzn/32/192_2.png) [@lucaswin-amzn](https://forum.opensearch.org/u/lucaswin-amzn)\
**Post date:** [October 29, 2019, 6:55pm UTC](https://forum.opensearch.org/t/alert-on-percentage/1423/3 "2019-10-29T18:55:38Z")

</div>

Hi @Tuckson,

This seems to be more a generic Elasticsearch DSL question than an alerting question. But here is my take:

In your response you would like to have 2 buckets, one for total number of requests and one for failed requests. You can do this by using a [terms aggregation query](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html).

If you store response code as a keyword for example you could do this:

```auto
{
    "aggs" : {
        "responses" : {
            "terms" : { "field" : "response_code" } 
        }
    }
}

```

This will give you something like:

```auto
{
    ...
    "aggregations" : {
        "responses" : {
            "buckets" : [ 
                {
                    "key" : "200",
                    "doc_count" : 6
                },
                {
                    "key" : "403",
                    "doc_count" : 3
                },
                {
                    "key" : "503",
                    "doc_count" : 2
                }
            ]
        }
    }
}

```

From here you can then use a [painless trigger script](http://ettea.aka.corp.amazon.com/opendist/docs/alerting/monitors/#sample-scripts) to get a percentage and trigger based on a threshold.

Or you could use something like the [percentiles aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-metrics-percentile-aggregation.html). Which would look like this:

```auto
{
    "size": 0,
    "aggs" : {
        "responses" : {
            "percentiles" : {
                "field" : "response_code" 
            }
        }
    }
}

```

But these results would be displayed in things like P99, P90, etc…

It is hard to answer your question fully without understanding your data architecture / sample documents.

Hope this helps!
