Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- {
- "watch_id": "_inlined_",
- "node": "eirBuokFRHGabbD0At450w",
- "state": "executed",
- "status": {
- "state": {
- "active": true,
- "timestamp": "2018-10-11T08:38:50.224Z"
- },
- "last_checked": "2018-10-11T08:38:50.224Z",
- "last_met_condition": "2018-10-11T08:38:50.224Z",
- "actions": {
- "log": {
- "ack": {
- "timestamp": "2018-10-11T08:38:50.224Z",
- "state": "ackable"
- },
- "last_execution": {
- "timestamp": "2018-10-11T08:38:50.224Z",
- "successful": true
- },
- "last_successful_execution": {
- "timestamp": "2018-10-11T08:38:50.224Z",
- "successful": true
- }
- }
- },
- "execution_state": "executed",
- "version": -1
- },
- "trigger_event": {
- "type": "manual",
- "triggered_time": "2018-10-11T08:38:50.224Z",
- "manual": {
- "schedule": {
- "scheduled_time": "2018-10-11T08:38:50.224Z"
- }
- }
- },
- "input": {
- "search": {
- "request": {
- "search_type": "query_then_fetch",
- "indices": [
- "clog-*"
- ],
- "types": [],
- "body": {
- "size": 0,
- "query": {
- "bool": {
- "must": [
- {
- "query_string": {
- "query": "source_affiliate: ukmail AND _exists_:hdr_xredir",
- "analyze_wildcard": false
- }
- },
- {
- "range": {
- "@timestamp": {
- "gte": "now-1h"
- }
- }
- }
- ],
- "filter": [],
- "should": [],
- "must_not": []
- }
- },
- "aggs": {
- "forward_address": {
- "terms": {
- "field": "rcptto_list.keyword",
- "size": 1000,
- "min_doc_count": 11
- },
- "aggs": {
- "senders": {
- "terms": {
- "field": "hdr_xredir.keyword",
- "size": 100
- }
- }
- }
- }
- }
- }
- }
- }
- },
- "condition": {
- "script": {
- "source": "boolean trigger = false;ArrayList offenders = new ArrayList();for (int i = 0; i < ctx.payload.aggregations.forward_address.buckets.size();i++){offenders.add(i);trigger=true}return trigger;",
- "lang": "painless",
- "params": {
- "rcpt_to": 11,
- "xredir": 10
- }
- }
- },
- "metadata": {
- "xpack": {
- "type": "json"
- }
- },
- "result": {
- "execution_time": "2018-10-11T08:38:50.224Z",
- "execution_duration": 1514,
- "input": {
- "type": "search",
- "status": "success",
- "payload": {
- "_shards": {
- "total": 240,
- "failed": 0,
- "successful": 240,
- "skipped": 220
- },
- "hits": {
- "hits": [],
- "total": 25891,
- "max_score": 0
- },
- "took": 1507,
- "timed_out": false,
- "aggregations": {
- "forward_address": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": [
- {
- "doc_count": 38,
- "senders": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": [
- {
- "doc_count": 4,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 4,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 3,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 3,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 3,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 3,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 3,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 2,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- }
- ]
- },
- "key": "foo@bar.com"
- },
- {
- "doc_count": 34,
- "senders": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": [
- {
- "doc_count": 34,
- "key": "foo@bar.com"
- }
- ]
- },
- "key": "foo@bar.com"
- },
- {
- "doc_count": 26,
- "senders": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": [
- {
- "doc_count": 4,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 3,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 3,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 2,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 2,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 2,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 2,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- }
- ]
- },
- "key": "foo@bar.com"
- },
- {
- "doc_count": 25,
- "senders": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": [
- {
- "doc_count": 13,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 7,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 5,
- "key": "foo@bar.com"
- }
- ]
- },
- "key": "foo@bar.com"
- },
- {
- "doc_count": 24,
- "senders": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": [
- {
- "doc_count": 24,
- "key": "foo@bar.com"
- }
- ]
- },
- "key": "foo@bar.com"
- },
- {
- "doc_count": 24,
- "senders": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": [
- {
- "doc_count": 3,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 2,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 2,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 2,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 2,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- }
- ]
- },
- "key": "foo@bar.com"
- },
- {
- "doc_count": 23,
- "senders": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": [
- {
- "doc_count": 23,
- "key": "foo@bar.com"
- }
- ]
- },
- "key": "foo@bar.com"
- },
- {
- "doc_count": 20,
- "senders": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": [
- {
- "doc_count": 20,
- "key": "foo@bar.com"
- }
- ]
- },
- "key": "foo@bar.com"
- },
- {
- "doc_count": 20,
- "senders": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": [
- {
- "doc_count": 4,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 3,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 2,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 2,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- }
- ]
- },
- "key": "foo@bar.com"
- },
- {
- "doc_count": 19,
- "senders": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": [
- {
- "doc_count": 19,
- "key": "foo@bar.com"
- }
- ]
- },
- "key": "foo@bar.com"
- },
- {
- "doc_count": 17,
- "senders": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": [
- {
- "doc_count": 17,
- "key": "foo@bar.com"
- }
- ]
- },
- "key": "foo@bar.com"
- },
- {
- "doc_count": 15,
- "senders": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": [
- {
- "doc_count": 15,
- "key": "foo@bar.com"
- }
- ]
- },
- "key": "foo@bar.com"
- },
- {
- "doc_count": 14,
- "senders": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": [
- {
- "doc_count": 14,
- "key": "foo@bar.com"
- }
- ]
- },
- "key": "foo@bar.com"
- },
- {
- "doc_count": 14,
- "senders": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": [
- {
- "doc_count": 14,
- "key": "foo@bar.com"
- }
- ]
- },
- "key": "foo@bar.com"
- },
- {
- "doc_count": 13,
- "senders": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": [
- {
- "doc_count": 3,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 3,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 2,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 2,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- }
- ]
- },
- "key": "foo@bar.com"
- },
- {
- "doc_count": 13,
- "senders": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": [
- {
- "doc_count": 6,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- }
- ]
- },
- "key": "foo@bar.com"
- },
- {
- "doc_count": 12,
- "senders": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": [
- {
- "doc_count": 12,
- "key": "foo@bar.com"
- }
- ]
- },
- "key": "foo@bar.com"
- },
- {
- "doc_count": 12,
- "senders": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": [
- {
- "doc_count": 12,
- "key": "foo@bar.com"
- }
- ]
- },
- "key": "foo@bar.com"
- },
- {
- "doc_count": 12,
- "senders": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": [
- {
- "doc_count": 12,
- "key": "foo@bar.com"
- }
- ]
- },
- "key": "foo@bar.com"
- },
- {
- "doc_count": 12,
- "senders": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": [
- {
- "doc_count": 5,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 2,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 2,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- }
- ]
- },
- "key": "foo@bar.com"
- },
- {
- "doc_count": 12,
- "senders": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": [
- {
- "doc_count": 9,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 3,
- "key": "foo@bar.com"
- }
- ]
- },
- "key": "foo@bar.com"
- },
- {
- "doc_count": 11,
- "senders": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": [
- {
- "doc_count": 11,
- "key": "foo@bar.com"
- }
- ]
- },
- "key": "foo@bar.com"
- },
- {
- "doc_count": 11,
- "senders": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": [
- {
- "doc_count": 6,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 4,
- "key": "foo@bar.com"
- },
- {
- "doc_count": 1,
- "key": "foo@bar.com"
- }
- ]
- },
- "key": "foo@bar.com"
- },
- {
- "doc_count": 11,
- "senders": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": [
- {
- "doc_count": 11,
- "key": "foo@bar.com"
- }
- ]
- },
- "key": "foo@bar.com"
- },
- {
- "doc_count": 11,
- "senders": {
- "doc_count_error_upper_bound": 0,
- "sum_other_doc_count": 0,
- "buckets": [
- {
- "doc_count": 11,
- "key": "foo@bar.com"
- }
- ]
- },
- "key": "foo@bar.com"
- }
- ]
- }
- }
- },
- "search": {
- "request": {
- "search_type": "query_then_fetch",
- "indices": [
- "clog-*"
- ],
- "types": [],
- "body": {
- "size": 0,
- "query": {
- "bool": {
- "must": [
- {
- "query_string": {
- "query": "source_affiliate: ukmail AND _exists_:hdr_xredir",
- "analyze_wildcard": false
- }
- },
- {
- "range": {
- "@timestamp": {
- "gte": "now-1h"
- }
- }
- }
- ],
- "filter": [],
- "should": [],
- "must_not": []
- }
- },
- "aggs": {
- "forward_address": {
- "terms": {
- "field": "rcptto_list.keyword",
- "size": 1000,
- "min_doc_count": 11
- },
- "aggs": {
- "senders": {
- "terms": {
- "field": "hdr_xredir.keyword",
- "size": 100
- }
- }
- }
- }
- }
- }
- }
- }
- },
- "condition": {
- "type": "script",
- "status": "success",
- "met": true
- },
- "actions": [
- {
- "id": "log",
- "type": "logging",
- "status": "success",
- "logging": {
- "logged_text": "There are documents in your index. Threshold is 10, trigger is "
- }
- }
- ]
- },
- "messages": []
- }
Add Comment
Please, Sign In to add comment