# Duplicate notifcations getting created in Slack for one watcher alert trigger

**URL:** <https://discuss.elastic.co/t/duplicate-notifcations-getting-created-in-slack-for-one-watcher-alert-trigger/157946>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [November 22, 2018, 10:39pm UTC](https://discuss.elastic.co/t/duplicate-notifcations-getting-created-in-slack-for-one-watcher-alert-trigger/157946 "2018-11-22T22:39:05Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![marvnz](https://avatars.discourse-cdn.com/v4/letter/m/fbc32d/32.png) [@marvnz](https://discuss.elastic.co/u/marvnz)\
**Post date:** [November 22, 2018, 10:39pm UTC](https://discuss.elastic.co/t/duplicate-notifcations-getting-created-in-slack-for-one-watcher-alert-trigger/157946/1 "2018-11-22T22:39:05Z")

</div>

I have created the following advanced watch, that should create one slack notification when triggered but it is creating 2 notifications every time it is triggered:

```
{

```

"trigger": {  
"schedule": {  
"interval": "15m"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"metricbeat-\*"  
],  
"types": ,  
"body": {  
"size": 0,  
"query": {  
"bool": {  
"filter": [  
{  
"match": {  
"fields.env": "prod"  
}  
},  
{  
"range": {  
"@timestamp": {  
"lte": "now",  
"gte": "now-{{ctx.metadata.window}}"  
}  
}  
}  
]  
}  
},  
"aggs": {  
"average\_swap": {  
"avg": {  
"field": "system.memory.swap.used.pct"  
}  
}  
}  
}  
}  
}  
},  
"condition": {  
"compare": {  
"ctx.payload.aggregations.average\_swap.value": {  
"gte": "{{ctx.metadata.threshold}}"  
}  
}  
},  
"actions": {  
"notify-slack": {  
"throttle\_period\_in\_millis": 300000,  
"slack": {  
"account": "monitoring",  
"message": {  
"from": "ElasticSearch Watcher",  
"to": [  
"#monitoring",  
"@everyone"  
],  
"text": "Elastic Metricbeat Server starting to swap",  
"attachments": [  
{  
"color": "danger",  
"title": "EC2 Instance using swap",  
"text": " EC2 Instance is starting to use swap memory, currently percentage is {{ctx.payload.aggregations.average\_swap.value}} 😅"  
}  
]  
}  
}  
}  
},  
"metadata": {  
"threshold": 1,  
"window": "15m"  
}  
}

 ![14%20AM](https://us1.discourse-cdn.com/elastic/original/3X/a/a/aa1e6b3d3541500273c229d9981d7833c0618b4f.png)

As I am using an aggregation, I only get one value to run a condition on, so not sure why I am getting 2 notifications in Slack.

Any ideas?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 27, 2018, 8:57am UTC](https://discuss.elastic.co/t/duplicate-notifcations-getting-created-in-slack-for-one-watcher-alert-trigger/157946/2 "2018-11-27T08:57:35Z")

</div>

which Elasticsearch version are you using?

---

<div class="post-metadata">

**Author:** ![marvnz](https://avatars.discourse-cdn.com/v4/letter/m/fbc32d/32.png) [@marvnz](https://discuss.elastic.co/u/marvnz)\
**Post date:** [November 27, 2018, 9:12am UTC](https://discuss.elastic.co/t/duplicate-notifcations-getting-created-in-slack-for-one-watcher-alert-trigger/157946/3 "2018-11-27T09:12:38Z")

</div>

We are running 6.5.0 in Elastic Cloud

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 27, 2018, 9:19am UTC](https://discuss.elastic.co/t/duplicate-notifcations-getting-created-in-slack-for-one-watcher-alert-trigger/157946/4 "2018-11-27T09:19:56Z")

</div>

can you include the execution time of the context in the text to check if these are really from one run?

like `"text": " EC2 Instance is starting to use swap memory, currently percentage is {{ctx.payload.aggregations.average_swap.value}} :sweat_smile:" {{ctx.trigger.triggered_time}}`

Can you also include the output of the watch history?

```auto
GET .watcher-history-*/_search
{
  "query": {
    "bool": {
      "filter": [
        {
          "term": {
            "watch_id": "my_watch"
          }
        }
      ]
    }
  },
  "sort": [
    {
      "trigger_event.triggered_time": {
        "order": "desc"
      }
    }
  ]
}

```

Thanks!

---

<div class="post-metadata">

**Author:** ![marvnz](https://avatars.discourse-cdn.com/v4/letter/m/fbc32d/32.png) [@marvnz](https://discuss.elastic.co/u/marvnz)\
**Post date:** [November 27, 2018, 9:27am UTC](https://discuss.elastic.co/t/duplicate-notifcations-getting-created-in-slack-for-one-watcher-alert-trigger/157946/5 "2018-11-27T09:27:33Z")

</div>

Watcher History index for that day has gone so can't show that:

 ![26%20PM](https://us1.discourse-cdn.com/elastic/original/3X/1/c/1c855f0821535af86dd7e0dce828a9213587cd13.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 25, 2018, 9:27am UTC](https://discuss.elastic.co/t/duplicate-notifcations-getting-created-in-slack-for-one-watcher-alert-trigger/157946/6 "2018-12-25T09:27:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
