# Expected behaviour of an unconditional watch

**URL:** <https://discuss.elastic.co/t/expected-behaviour-of-an-unconditional-watch/136055>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [June 15, 2018, 8:56am UTC](https://discuss.elastic.co/t/expected-behaviour-of-an-unconditional-watch/136055 "2018-06-15T08:56:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![crickes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/crickes/32/18009_2.png) [@crickes](https://discuss.elastic.co/u/crickes)\
**Post date:** [June 15, 2018, 8:56am UTC](https://discuss.elastic.co/t/expected-behaviour-of-an-unconditional-watch/136055/1 "2018-06-15T08:56:26Z")

</div>

Hi,

Similar to the example in the [docs](https://www.elastic.co/guide/en/x-pack/6.2/condition-always.html), I have created a watch to email a status report once every 24 hours, at 8am. When the watch fires at the specified time, its stays in the 'firing' state and never returns to the 'OK' state. As it's an unconditional watch, I expect it to fire once every 24 hours, but I dodn't expect it to report it in a state of firing all the time, but only when it is actually sending the email defined in the actions, and return to OK once finished.  
Also if someone were to come along and ACK the watch, as the state never changes, it will always remain ACKed and therefore never fire again as I believe the logic needs to see a state change in the conditional in order to reset the ACK. Once the watch has been ACKed, I don't see any way on un-ACKing it and therefore never fires again.

Has anyone else done this and how do you get around the stcuk firing and potential stuck ACKed states, when using an 'ALWAYS' condition?

TIA

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 22, 2018, 2:12pm UTC](https://discuss.elastic.co/t/expected-behaviour-of-an-unconditional-watch/136055/2 "2018-06-22T14:12:18Z")

</div>

Hey,

just to be sure we are talking about the same thing, before I say something wrong. Can you show, what status in the JSON you are referring to? Or are you referring to the watcher UI in kibana?

having an always `true` condition does mean, that an acked watch cannot be unacked, until it is deleted and stored again.

--Alex

---

<div class="post-metadata">

**Author:** ![crickes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/crickes/32/18009_2.png) [@crickes](https://discuss.elastic.co/u/crickes)\
**Post date:** [June 22, 2018, 3:06pm UTC](https://discuss.elastic.co/t/expected-behaviour-of-an-unconditional-watch/136055/3 "2018-06-22T15:06:45Z")

</div>

It was the status on the Watcher UI in Kibana I was referring to. I will just have to make sure no one ACKs the watch.

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 20, 2018, 3:06pm UTC](https://discuss.elastic.co/t/expected-behaviour-of-an-unconditional-watch/136055/4 "2018-07-20T15:06:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
