# Alerts for missing results during the last week

**URL:** <https://discuss.elastic.co/t/alerts-for-missing-results-during-the-last-week/322085>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [December 28, 2022, 10:47am UTC](https://discuss.elastic.co/t/alerts-for-missing-results-during-the-last-week/322085 "2022-12-28T10:47:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![adiad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adiad/32/106046_2.png) [@adiad](https://discuss.elastic.co/u/adiad)\
**Post date:** [December 28, 2022, 10:47am UTC](https://discuss.elastic.co/t/alerts-for-missing-results-during-the-last-week/322085/1 "2022-12-28T10:47:53Z")

</div>

Hi  
Would it be possible to create a watcher using two different overlapping time ranges and get the delta (subtract the results and get only those that are missing)

I'm trying to create an alert that checks my last week's results and compares them to my last month's results and finds what I missed

```auto

{
  "trigger": {
    "schedule": {
      "daily": {
        "at": [
          "08:00"
        ]
      }
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "my_index"
        ],
        "rest_total_hits_as_int": true,
        "body": {
          "size": 0,
          "query": {
            "bool": {
              "must": [
                {
                  "query_string": {
                    "query": "alert: my_alerts"
                  }
                },
                {
                  "range": {
                    "collection_date": {
                      "gte":" **now-<should be 7 and 30>d/d**", "lte": "now/d"
                    }
                  }
                }
              ]
            }
          },
          "aggs": {
            "aggregations": {
              "terms": {
                "size": 10000,
                "field": "category.keyword"
              }
            }
          }
        }
      }
    }
  },

```

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [January 2, 2023, 12:19am UTC](https://discuss.elastic.co/t/alerts-for-missing-results-during-the-last-week/322085/2 "2023-01-02T00:19:23Z")

</div>

Seems like the best way to do this is to use a [chain input](https://www.elastic.co/guide/en/elasticsearch/reference/current/input-chain.html) and have the first query be for the older timeframe, and the second query is for the newer timeframe.

Or alternatively, you could do two different filter aggregations (each with a different time range) and then use a bucket\_selector aggregation to expose only the terms that are in one of the time ranges, but not the other. See example here:

> <https://gist.github.com/richcollier/b21d7acaf27990775c2c033555e44260>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 30, 2023, 12:20am UTC](https://discuss.elastic.co/t/alerts-for-missing-results-during-the-last-week/322085/3 "2023-01-30T00:20:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
