# Trigger on bucket count

**URL:** <https://forum.opensearch.org/t/trigger-on-bucket-count/1526>\
**Category:** Alerting\
**Created:** [September 13, 2019, 3:30pm UTC](https://forum.opensearch.org/t/trigger-on-bucket-count/1526 "2019-09-13T15:30:09Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![asikarwar](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/asikarwar/32/286_2.png) [@asikarwar](https://forum.opensearch.org/u/asikarwar)\
**Post date:** [September 13, 2019, 3:30pm UTC](https://forum.opensearch.org/t/trigger-on-bucket-count/1526/1 "2019-09-13T15:30:10Z")

</div>

Hello,

Please suggest how can i write a trigger condition where it will check count for each host and not total.  
**Alert Criterion:** I want to trigger an alert if a computer has **\> 20 doc count**.

**So instead of this**  
`ctx.results[0].hits.total.value > 400`  
**I need to access doc\_count for each computer**  
something like the following:  
`ctx.results[0].aggregations.group_by_host.buckets.doc_count > 400`  
But the above throw error:

```auto
{
  "type" : "script_exception",
  "reason" : "runtime error",
  "script_stack" : [
    "ctx.results[0].aggregations.group_by_host.buckets.doc_count > 400",
    " ^---- HERE"
  ],
  "script" : "ctx.results[0].aggregations.group_by_host.buckets.doc_count > 400",
  "lang" : "painless",
  "caused_by" : {
    "type" : "illegal_argument_exception",
    "reason" : "Illegal list shortcut value [doc_count]."
  }
}

```

Following is the response from extraction query which i am using for trigger action how can i access **doc\_count** which i under **buckets** so it will only qualify

{  
“\_shards”: {  
“total”: 198,  
“failed”: 0,  
“successful”: 198,  
“skipped”: 52  
},  
“hits”: {  
“hits”: ,  
“total”: {  
“value”: 496,  
“relation”: “eq”  
},  
“max\_score”: null  
},  
“took”: 11,  
“timed\_out”: false,  
“aggregations”: {  
“group\_by\_host”: {  
“doc\_count\_error\_upper\_bound”: 0,  
“sum\_other\_doc\_count”: 0,  
“buckets”: [  
{  
“doc\_count”: 494,  
“key”: “Computer1”  
},  
{  
“doc\_count”: 2,  
“key”: “Computer2”  
}  
]  
},  
“event\_count”: {  
“value”: 496  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![kris](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/kris/32/2208_2.png) [@kris](https://forum.opensearch.org/u/kris)\
**Post date:** [February 7, 2023, 5:17pm UTC](https://forum.opensearch.org/t/trigger-on-bucket-count/1526/2 "2023-02-07T17:17:54Z")

</div>


