# Current Date in watcher

**URL:** <https://discuss.elastic.co/t/current-date-in-watcher/357681>\
**Category:** Elasticsearch\
**Created:** [April 18, 2024, 8:54am UTC](https://discuss.elastic.co/t/current-date-in-watcher/357681 "2024-04-18T08:54:40Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ashish25](https://avatars.discourse-cdn.com/v4/letter/a/67e7ee/32.png) [@ashish25](https://discuss.elastic.co/u/ashish25)\
**Post date:** [April 18, 2024, 8:54am UTC](https://discuss.elastic.co/t/current-date-in-watcher/357681/1 "2024-04-18T08:54:40Z")

</div>

Hi,

I have below index which will create everyday -

POST /test\_index-2024-04-17/\_doc  
{  
"field\_to\_check": "old\_value",  
"field\_to\_update": "old\_value"  
}

POST /test\_index-2024-04-18/\_doc  
{  
"field\_to\_check": "old\_value",  
"field\_to\_update": "old\_value"  
}

....

Now I want to create watcher on top of this index for some background work. I created watcher something like below but not able to change index based on current date.

PUT /\_watcher/watch/test\_watch  
{  
"trigger": {  
"schedule": {  
"interval": "10s"  
}  
},  
"input": {  
"search": {  
"request": {  
"indices": [  
**"test\_index-2024-04-17"**  
],  
"body": {  
"query": {  
"match": {  
"field\_to\_check": "old\_value"  
}  
}  
}  
}  
}  
},  
"condition": {  
"compare": {  
"ctx.payload.hits.total": {  
"gt": 0  
}  
}  
},  
"actions": {  
"log\_hits": {  
"logging" : {  
"text" : "Watcher triggered !!!"  
}  
}  
}  
}

Please help me in solving this issue.

---

<div class="post-metadata">

**Author:** ![GinkoLucas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ginkolucas/32/107055_2.png) [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Post date:** [April 18, 2024, 11:49am UTC](https://discuss.elastic.co/t/current-date-in-watcher/357681/2 "2024-04-18T11:49:00Z")

</div>

Hello, I didn't quite understand. What do you want to do with your Watcher? Does it have to work for all your indexes? One watcher per index?

---

<div class="post-metadata">

**Author:** ![ashish25](https://avatars.discourse-cdn.com/v4/letter/a/67e7ee/32.png) [@ashish25](https://discuss.elastic.co/u/ashish25)\
**Post date:** [April 18, 2024, 12:00pm UTC](https://discuss.elastic.co/t/current-date-in-watcher/357681/3 "2024-04-18T12:00:48Z")

</div>

I want one watcher only and whenever watcher will invoke, it will take that day index.  
Hope it help.

Something like **"test\_index-{now/d}"**

---

<div class="post-metadata">

**Author:** ![GinkoLucas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ginkolucas/32/107055_2.png) [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Post date:** [April 18, 2024, 12:05pm UTC](https://discuss.elastic.co/t/current-date-in-watcher/357681/4 "2024-04-18T12:05:38Z")

</div>

I don't know if it's possible to do this in the "index" section, but you could create a data view that groups all your indexes together, for example "test-index\*". Then you can use the query system and the condition to filter the right index.

---

<div class="post-metadata">

**Author:** ![ashish25](https://avatars.discourse-cdn.com/v4/letter/a/67e7ee/32.png) [@ashish25](https://discuss.elastic.co/u/ashish25)\
**Post date:** [April 18, 2024, 12:07pm UTC](https://discuss.elastic.co/t/current-date-in-watcher/357681/5 "2024-04-18T12:07:07Z")

</div>

can you please help me via some example?

---

<div class="post-metadata">

**Author:** ![GinkoLucas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ginkolucas/32/107055_2.png) [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Post date:** [April 18, 2024, 12:15pm UTC](https://discuss.elastic.co/t/current-date-in-watcher/357681/6 "2024-04-18T12:15:15Z")

</div>

There an example in the documentation : [Script query | Elasticsearch Guide [8.13] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-script-query.html)

> GET /\_search  
> {  
> "runtime\_mappings": {  
> "amount.signed": {  
> "type": "double",  
> "script": """  
> double amount = doc['amount'].value;  
> if (doc['type'].value == 'expense') {  
> amount \*= -1;  
> }  
> emit(amount);  
> """  
> }  
> },  
> "query": {  
> "bool": {  
> "filter": {  
> "range": {  
> "amount.signed": { "lt": 10 }  
> }  
> }  
> }  
> },  
> "fields": [{"field": "amount.signed"}]  
> }

In this example, the query uses a script as a filter.

The first part corresponds to a runtime field (a calculated field). You can modify this script to extract the date contained in the name of your index (the \_index field).  
The second part corresponds to the filter, in this case based on the value returned by the runtime field

I think this query could be simplified, by creating a runtime field directly in your dataview. This runtime field would return the date contained in your index name. Then, you could use this runtime field to filter your Watcher query.

---

<div class="post-metadata">

**Author:** ![GinkoLucas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ginkolucas/32/107055_2.png) [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Post date:** [April 18, 2024, 12:17pm UTC](https://discuss.elastic.co/t/current-date-in-watcher/357681/7 "2024-04-18T12:17:22Z")

</div>

So :

- create a data view that includes all your indexes (test-index\*)
- inside this dataview, create un runtime field that extracts the date contained in the index name, thanks to the \_index field
- then, run a query in your watcher based on this runtime field

I don't know if there are other solutions, but this is personally how I'd do it.
