# Alerting ignore a specific time period

**URL:** https://discuss.elastic.co/t/alerting-ignore-a-specific-time-period/82050
**Category:** Elasticsearch
**Created:** [April 11, 2017, 8:53pm UTC](https://discuss.elastic.co/t/alerting-ignore-a-specific-time-period/82050 "2017-04-11T20:53:33Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Ryan\_Groten](https://avatars.discourse-cdn.com/v4/letter/r/f9ae1b/32.png) [@Ryan\_Groten](https://discuss.elastic.co/u/Ryan_Groten)
#### Post date: [April 11, 2017, 8:53pm UTC](https://discuss.elastic.co/t/alerting-ignore-a-specific-time-period/82050/1 "2017-04-11T20:53:33Z")

</div>

Is it possible to tell Watcher to either not run or suppress actions during a specific time period daily? For example, I want to run the watch every 30 minutes, but don't execute the action from 6PM - 7PM daily?

---

<div class="post-metadata">

### Author: ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)
#### Post date: [April 12, 2017, 8:37am UTC](https://discuss.elastic.co/t/alerting-ignore-a-specific-time-period/82050/2 "2017-04-12T08:37:32Z")

</div>

Hey,

I am sure you could use a fancy cron expression for that (I would have to look those up as well, not a cron wizard, sorry). Alternatively, if the input is not too resource intensive, you could check the `ctx.trigger.scheduled` time in the condition and just return false to not trigger any action.

Hope that helps!

--Alex

---

<div class="post-metadata">

### Author: ![Ryan\_Groten](https://avatars.discourse-cdn.com/v4/letter/r/f9ae1b/32.png) [@Ryan\_Groten](https://discuss.elastic.co/u/Ryan_Groten)
#### Post date: [April 12, 2017, 2:16pm UTC](https://discuss.elastic.co/t/alerting-ignore-a-specific-time-period/82050/3 "2017-04-12T14:16:59Z")

</div>

I didn't even consider cron, I was focusing on the trigger interval built into the watch itself. I'll look into that, thanks!

---

<div class="post-metadata">

### Author: ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)
#### Post date: [April 12, 2017, 2:40pm UTC](https://discuss.elastic.co/t/alerting-ignore-a-specific-time-period/82050/4 "2017-04-12T14:40:10Z")

</div>

If cron doesn't work for your use-case, I did something similar in this webinar [1]: during business hours, look at running processes, and send a slack message if steam\_osx is running.

On that page is a link to a gist with the watches I used [2], and I used a script condition to check the hour of the day[3]. The script condition there used Groovy (in ES 2.x) , so you'll need to update it to use Painless if you're using 5.0+, but the idea is the same.

[1] [https://www.elastic.co/webinars/getting-started-with-alerting-for-elasticsearch](https://www.elastic.co/webinars/getting-started-with-alerting-for-elasticsearch)  
[2] [https://gist.github.com/skearns64/773dfd64c51d3007baf489be83549e0c#file-watcher\_webinar\_examples-2016-07-28-txt-L120](https://gist.github.com/skearns64/773dfd64c51d3007baf489be83549e0c#file-watcher_webinar_examples-2016-07-28-txt-L120)  
[3] [https://gist.github.com/skearns64/773dfd64c51d3007baf489be83549e0c#file-watcher\_webinar\_examples-2016-07-28-txt-L195](https://gist.github.com/skearns64/773dfd64c51d3007baf489be83549e0c#file-watcher_webinar_examples-2016-07-28-txt-L195)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 10, 2017, 2:50pm UTC](https://discuss.elastic.co/t/alerting-ignore-a-specific-time-period/82050/5 "2017-05-10T14:50:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
