# Advanced Watcher to send alert of condition has been met for more than 1 hour

**URL:** <https://discuss.elastic.co/t/advanced-watcher-to-send-alert-of-condition-has-been-met-for-more-than-1-hour/349247>\
**Category:** Kibana\
**Created:** [December 13, 2023, 11:15am UTC](https://discuss.elastic.co/t/advanced-watcher-to-send-alert-of-condition-has-been-met-for-more-than-1-hour/349247 "2023-12-13T11:15:00Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![ChrisKelly](https://avatars.discourse-cdn.com/v4/letter/c/13edae/32.png) [@ChrisKelly](https://discuss.elastic.co/u/ChrisKelly)\
**Post date:** [December 13, 2023, 11:15am UTC](https://discuss.elastic.co/t/advanced-watcher-to-send-alert-of-condition-has-been-met-for-more-than-1-hour/349247/1 "2023-12-13T11:15:00Z")

</div>

I want to create an advanced Watcher that will only send an alert email out if my conditions have been met more over an hour.

Essentially, I am monitoring specific servers and watching if their CPU exceeds 50%. If it goes above 50% but drops again in the next couple of minutes that's fine but if it exceeds 50% for more than an hour we see problems on those servers.  
How can I configure my watcher so it only sends an alert if the CPU goes above 50% for more than an hour?

---

<div class="post-metadata">

**Author:** ![GinkoLucas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ginkolucas/32/107055_2.png) [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Post date:** [December 13, 2023, 12:57pm UTC](https://discuss.elastic.co/t/advanced-watcher-to-send-alert-of-condition-has-been-met-for-more-than-1-hour/349247/2 "2023-12-13T12:57:02Z")

</div>

Hello,

I think that in the "Input" section, you could get the lowest CPU level received in the hour.

Sets your condition to something like: minCPU \> 50

And then adjust your action according to what you want

---

<div class="post-metadata">

**Author:** ![ChrisKelly](https://avatars.discourse-cdn.com/v4/letter/c/13edae/32.png) [@ChrisKelly](https://discuss.elastic.co/u/ChrisKelly)\
**Post date:** [December 13, 2023, 2:11pm UTC](https://discuss.elastic.co/t/advanced-watcher-to-send-alert-of-condition-has-been-met-for-more-than-1-hour/349247/3 "2023-12-13T14:11:56Z")

</div>

In the input isn't the problem, it's the time range, and condition that is the issue.

---

<div class="post-metadata">

**Author:** ![GinkoLucas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ginkolucas/32/107055_2.png) [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Post date:** [December 13, 2023, 2:28pm UTC](https://discuss.elastic.co/t/advanced-watcher-to-send-alert-of-condition-has-been-met-for-more-than-1-hour/349247/4 "2023-12-13T14:28:15Z")

</div>

The time range must be defined in your input, like this:

`{ "range": { "@timestamp": { "gte": "now", "lte": "now - 1h" } }}`

And for the condition, it depends on the input request. If you follow my example, you should be able to retrieve the value of the smallest percentage (during the time range you specify, as in my example)

---

<div class="post-metadata">

**Author:** ![ChrisKelly](https://avatars.discourse-cdn.com/v4/letter/c/13edae/32.png) [@ChrisKelly](https://discuss.elastic.co/u/ChrisKelly)\
**Post date:** [December 13, 2023, 3:24pm UTC](https://discuss.elastic.co/t/advanced-watcher-to-send-alert-of-condition-has-been-met-for-more-than-1-hour/349247/5 "2023-12-13T15:24:33Z")

</div>

That will only tell me if the CPU has gone above 50% within the last hour, not if the CPU has been above 50% for the whole hour.

---

<div class="post-metadata">

**Author:** ![GinkoLucas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ginkolucas/32/107055_2.png) [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Post date:** [December 13, 2023, 3:31pm UTC](https://discuss.elastic.co/t/advanced-watcher-to-send-alert-of-condition-has-been-met-for-more-than-1-hour/349247/6 "2023-12-13T15:31:18Z")

</div>

Not at all. If you get the smallest value during the last hour, and this is greater than 50%, then your CPU was necessarily above 50% during the last hour.

I'm talking about the smallest percentage, not the largest.

---

<div class="post-metadata">

**Author:** ![ChrisKelly](https://avatars.discourse-cdn.com/v4/letter/c/13edae/32.png) [@ChrisKelly](https://discuss.elastic.co/u/ChrisKelly)\
**Post date:** [December 13, 2023, 3:37pm UTC](https://discuss.elastic.co/t/advanced-watcher-to-send-alert-of-condition-has-been-met-for-more-than-1-hour/349247/7 "2023-12-13T15:37:08Z")

</div>

How do I get the smallest percentage from the last hour?

---

<div class="post-metadata">

**Author:** ![GinkoLucas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ginkolucas/32/107055_2.png) [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Post date:** [December 13, 2023, 4:02pm UTC](https://discuss.elastic.co/t/advanced-watcher-to-send-alert-of-condition-has-been-met-for-more-than-1-hour/349247/8 "2023-12-13T16:02:33Z")

</div>

You can use something like this :

```auto
  "aggs" : {
        "mincpu" : {
            "range" : {
                "field" : "@timestamp",
                "ranges" : [
                    { "from" : "now-1h", "to" : "now" }
                ]
            },
            "aggs" : {
                "minpercent" : { "min" : { "field" : "MyPercentage" } }
            }
        }
    }
}
```

---

<div class="post-metadata">

**Author:** ![ChrisKelly](https://avatars.discourse-cdn.com/v4/letter/c/13edae/32.png) [@ChrisKelly](https://discuss.elastic.co/u/ChrisKelly)\
**Post date:** [December 14, 2023, 11:56am UTC](https://discuss.elastic.co/t/advanced-watcher-to-send-alert-of-condition-has-been-met-for-more-than-1-hour/349247/9 "2023-12-14T11:56:10Z")

</div>

I have been testing the aggregations above but I can't seem to add the server name so I know which server exceeded the limit. How can I add another aggregation for server name?

---

<div class="post-metadata">

**Author:** ![GinkoLucas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ginkolucas/32/107055_2.png) [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Post date:** [December 14, 2023, 1:08pm UTC](https://discuss.elastic.co/t/advanced-watcher-to-send-alert-of-condition-has-been-met-for-more-than-1-hour/349247/10 "2023-12-14T13:08:02Z")

</div>

Try Terms aggregation : [Terms aggregation | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#search-aggregations-bucket-terms-aggregation-order)

An example in the documentation :

```auto
{
  "aggs": {
    "genres": {
      "terms": {
        "field": "genre",
        "order": { "max_play_count": "desc" }
      },
      "aggs": {
        "max_play_count": { "max": { "field": "play_count" } }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 11, 2024, 1:08pm UTC](https://discuss.elastic.co/t/advanced-watcher-to-send-alert-of-condition-has-been-met-for-more-than-1-hour/349247/11 "2024-01-11T13:08:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
