# Create dynamic date variable/constant to use in watch

**URL:** <https://discuss.elastic.co/t/create-dynamic-date-variable-constant-to-use-in-watch/115062>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [January 11, 2018, 10:50am UTC](https://discuss.elastic.co/t/create-dynamic-date-variable-constant-to-use-in-watch/115062 "2018-01-11T10:50:37Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Viorel\_Florian](https://avatars.discourse-cdn.com/v4/letter/v/58956e/32.png) [@Viorel\_Florian](https://discuss.elastic.co/u/Viorel_Florian)\
**Post date:** [January 11, 2018, 10:50am UTC](https://discuss.elastic.co/t/create-dynamic-date-variable-constant-to-use-in-watch/115062/1 "2018-01-11T10:50:37Z")

</div>

I am trying to create a metadata field of type date to use in input, condition, action :  
`"metadata": { "range_start" : "now-10m" }`  
In the input it seems to have the desired.

In the action I am trying to use range\_start as so:  
`from:{{ctx.metadata.range_start}},mode:absolute,to:{{ctx.trigger.triggered_time}}`  
but the result is:  
`(from:now-10m,mode:absolute,to:2018-01-11T10:38:27.509Z)`  
instead of:  
`(from:2018-01-11T10:28:27.509Z,mode:absolute,to:2018-01-11T10:38:27.509Z)`

Any help is appreciated!

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [January 15, 2018, 1:53pm UTC](https://discuss.elastic.co/t/create-dynamic-date-variable-constant-to-use-in-watch/115062/2 "2018-01-15T13:53:27Z")

</div>

Hey,

this `now` expansion is done at query time on the Elasticsearch side, when the query is sent to Elasticsearch, not when the watch is executed.

Can you maybe explain in words, what exactly you are after and which part needs to be more dynamic than `now-10m` here and why?

Thank you!

--Alex

---

<div class="post-metadata">

**Author:** ![Viorel\_Florian](https://avatars.discourse-cdn.com/v4/letter/v/58956e/32.png) [@Viorel\_Florian](https://discuss.elastic.co/u/Viorel_Florian)\
**Post date:** [January 15, 2018, 3:25pm UTC](https://discuss.elastic.co/t/create-dynamic-date-variable-constant-to-use-in-watch/115062/3 "2018-01-15T15:25:15Z")

</div>

> [@spinscale](#):
>
> , not when the watch is execu

Hi @spinscale,  
I am trying to

1. include the value of "execution\_time" and the value of "now-10m" in the email notification action.
2. Ultimately I am trying to include a URL that will open Kibana to the search results that triggered the watch  
Any help is appreciated.  
Regards,  
Vio

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [January 16, 2018, 11:48am UTC](https://discuss.elastic.co/t/create-dynamic-date-variable-constant-to-use-in-watch/115062/4 "2018-01-16T11:48:42Z")

</div>

Hey,

you can try using a script `transform` in your email action and calculate the time difference using a painless script. This is on top of my head, but should give you a first hint

```auto
        "transform" : {
          "script" : {
            "source" : "def payload = ctx.payload ; ctx.payload.tenminsago = Instant.ofEpochMilli(ctx.execution_time.getMillis() - (10 * 60 * 1000) ); return payload"
          }
        },

```

this converts a joda time into a java time object and substracts the number of milliseconds.

hope that helps.

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 13, 2018, 11:48am UTC](https://discuss.elastic.co/t/create-dynamic-date-variable-constant-to-use-in-watch/115062/5 "2018-02-13T11:48:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
