# Ctx.trigger.triggered\_time math and formatting

**URL:** <https://discuss.elastic.co/t/ctx-trigger-triggered-time-math-and-formatting/328501>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting, painless\
**Created:** [March 24, 2023, 9:43pm UTC](https://discuss.elastic.co/t/ctx-trigger-triggered-time-math-and-formatting/328501 "2023-03-24T21:43:12Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![ffmdsuperit](https://avatars.discourse-cdn.com/v4/letter/f/bb73d2/32.png) [@ffmdsuperit](https://discuss.elastic.co/u/ffmdsuperit)\
**Post date:** [March 24, 2023, 9:43pm UTC](https://discuss.elastic.co/t/ctx-trigger-triggered-time-math-and-formatting/328501/1 "2023-03-24T21:43:12Z")

</div>

I have a Watcher that filters on a timestamp range. I'd like to capture the searched timestamp range by saving something like "Start": "ctx.trigger.triggered\_time - 23m" and "End": "ctx.trigger.triggered\_time - 22m" into a variable so I can then use that start and end time in an alert message. I'd also like to make sure the times are in my current timezone.

I've been reading a bit on Watch script payload transforms but I'm not sure where in the Watcher to do this or how to properly do the math. I'd really appreciate some help.

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [March 28, 2023, 1:23pm UTC](https://discuss.elastic.co/t/ctx-trigger-triggered-time-math-and-formatting/328501/2 "2023-03-28T13:23:52Z")

</div>

take a look at this example:

> <https://gist.github.com/richcollier/6b2afca5918ed3beac93d9c2fb8a00c7>

---

<div class="post-metadata">

**Author:** ![ffmdsuperit](https://avatars.discourse-cdn.com/v4/letter/f/bb73d2/32.png) [@ffmdsuperit](https://discuss.elastic.co/u/ffmdsuperit)\
**Post date:** [March 28, 2023, 3:01pm UTC](https://discuss.elastic.co/t/ctx-trigger-triggered-time-math-and-formatting/328501/3 "2023-03-28T15:01:24Z")

</div>

@richcollier thank you that is helpful. I THINK I have adapted that to exactly what I need, but the Watcher UI is complaining about the action with error "Unknown action type provided for action "my-logging-action"." Is there a prerequisite I need to do before this will work?

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [March 28, 2023, 3:35pm UTC](https://discuss.elastic.co/t/ctx-trigger-triggered-time-math-and-formatting/328501/4 "2023-03-28T15:35:03Z")

</div>

Watcher `actions` can be only of the following type:

- [`email`](https://www.elastic.co/guide/en/elasticsearch/reference/master/actions-email.html)
- [`webhook`](https://www.elastic.co/guide/en/elasticsearch/reference/master/actions-webhook.html)
- [`index`](https://www.elastic.co/guide/en/elasticsearch/reference/master/actions-index.html)
- [`logging`](https://www.elastic.co/guide/en/elasticsearch/reference/master/actions-logging.html)
- [`slack`](https://www.elastic.co/guide/en/elasticsearch/reference/master/actions-slack.html)
- [`pagerduty`](https://www.elastic.co/guide/en/elasticsearch/reference/master/actions-pagerduty.html)
- [`jira`](https://www.elastic.co/guide/en/elasticsearch/reference/master/actions-jira.html)

However, they can be named anything. You can see in my example, the type is `logging` but the name is `my-logging-action`. There, of course, is also a `transform` in there as well.

Check your code to make sure your syntax is correct. Or, try your Watch in DevTools console to make sure the Watcher UI isn't the problem.

---

<div class="post-metadata">

**Author:** ![ffmdsuperit](https://avatars.discourse-cdn.com/v4/letter/f/bb73d2/32.png) [@ffmdsuperit](https://discuss.elastic.co/u/ffmdsuperit)\
**Post date:** [March 28, 2023, 3:50pm UTC](https://discuss.elastic.co/t/ctx-trigger-triggered-time-math-and-formatting/328501/6 "2023-03-28T15:50:06Z")

</div>

I tried running it through the Dev tool but get this:

```auto
{
  "error": {
    "root_cause": [
      {
        "type": "parse_exception",
        "reason": "could not parse action [_inlined_/my-logging-action]. unknown action type [send_email]"
      }
    ],
    "type": "parse_exception",
    "reason": "could not parse action [_inlined_/my-logging-action]. unknown action type [send_email]"
  },
  "status": 400
}

```

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [March 28, 2023, 4:54pm UTC](https://discuss.elastic.co/t/ctx-trigger-triggered-time-math-and-formatting/328501/7 "2023-03-28T16:54:00Z")

</div>

Just post your `actions` section here for review

---

<div class="post-metadata">

**Author:** ![ffmdsuperit](https://avatars.discourse-cdn.com/v4/letter/f/bb73d2/32.png) [@ffmdsuperit](https://discuss.elastic.co/u/ffmdsuperit)\
**Post date:** [March 28, 2023, 5:34pm UTC](https://discuss.elastic.co/t/ctx-trigger-triggered-time-math-and-formatting/328501/8 "2023-03-28T17:34:35Z")

</div>

Thank you.

```auto
"actions": {
      "my-logging-action": {
        "transform": {
          "script": """
          def payload = ctx.payload; 
          DateFormat df = new SimpleDateFormat("yyyy-MM-dd'T'HH:mm:ss.SSS'Z'"); 
          ctx.payload.from = df.format(Date.from(Instant.ofEpochMilli(ctx.execution_time.getMillis() - (23*60*1000) )));
          ctx.payload.to = df.format(Date.from(Instant.ofEpochMilli(ctx.execution_time.getMillis() - (22*60*1000) )));
          return payload
          """
        },
        "send_email": {
          "throttle_period_in_millis": 1200000,
          "email": {
            "profile": "standard",
            "to": [
              "alerts@mycompany.org"
            ],
            "subject": "Alert - Transaction Count Too Low",
            "body": {
              "text": "Expected minium is 7 transactions, but {{ctx.payload.hits.total}} were found between {{ctx.payload.from}} and {{ctx.payload.to}}."
            }
          }
        }
      }
    }

```

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [March 28, 2023, 6:24pm UTC](https://discuss.elastic.co/t/ctx-trigger-triggered-time-math-and-formatting/328501/9 "2023-03-28T18:24:59Z")

</div>

it should look like this:

```auto
    "actions": {
      "send_email": {
        "throttle_period_in_millis": 1200000,
        "transform": {
          "script": """
          def payload = ctx.payload; 
          DateFormat df = new SimpleDateFormat("yyyy-MM-dd'T'HH:mm:ss.SSS'Z'"); 
          ctx.payload.from = df.format(Date.from(Instant.ofEpochMilli(ctx.execution_time.getMillis() - (23*60*1000) )));
          ctx.payload.to = df.format(Date.from(Instant.ofEpochMilli(ctx.execution_time.getMillis() - (22*60*1000) )));
          return payload
          """
        },
        "email": {
          "profile": "standard",
          "to": [
            "alerts@mycompany.org"
          ],
          "subject": "Alert - Transaction Count Too Low",
          "body": {
            "text": "Expected minium is 7 transactions, but {{ctx.payload.hits.total}} were found between {{ctx.payload.from}} and {{ctx.payload.to}}."
          }
        }
      }
    }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 25, 2023, 6:25pm UTC](https://discuss.elastic.co/t/ctx-trigger-triggered-time-math-and-formatting/328501/10 "2023-04-25T18:25:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
