# Help me writing watcher Query

**URL:** <https://discuss.elastic.co/t/help-me-writing-watcher-query/270103>\
**Category:** Endpoint Security\
**Created:** [April 14, 2021, 11:22am UTC](https://discuss.elastic.co/t/help-me-writing-watcher-query/270103 "2021-04-14T11:22:39Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![abhishek\_s1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abhishek_s1/32/85080_2.png) [@abhishek\_s1](https://discuss.elastic.co/u/abhishek_s1)\
**Post date:** [April 14, 2021, 11:22am UTC](https://discuss.elastic.co/t/help-me-writing-watcher-query/270103/1 "2021-04-14T11:22:39Z")

</div>

Hello,

We are defining an activity of user to be suspicious if he logs in after very long period (1 month).

So, I need to find if there exists a log entry or request with some username whose last request was \>= 1 month ago.

My log looks like this

```auto
10.0.0.10 - username [21/Sep/2020:04:27:18 +0000] "GET /svn/repos HTTP/1.1" 200 289

```

Please help me with watcher query.

---

<div class="post-metadata">

**Author:** ![Felix\_Roessel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felix_roessel/32/41623_2.png) [@Felix\_Roessel](https://discuss.elastic.co/u/Felix_Roessel)\
**Post date:** [April 16, 2021, 5:23am UTC](https://discuss.elastic.co/t/help-me-writing-watcher-query/270103/2 "2021-04-16T05:23:46Z")

</div>

Why not creating a threshold based rule in the detection engine?

---

<div class="post-metadata">

**Author:** ![abhishek\_s1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abhishek_s1/32/85080_2.png) [@abhishek\_s1](https://discuss.elastic.co/u/abhishek_s1)\
**Post date:** [April 16, 2021, 5:34am UTC](https://discuss.elastic.co/t/help-me-writing-watcher-query/270103/3 "2021-04-16T05:34:07Z")

</div>

Hello @Felix_Roessel  
I'm very much new to alerts & detections,

Can you please tell me the difference between a watcher query & threshold based rule in the detection engine?

> [@Felix\_Roessel](#):
>
> Why not creating a threshold based rule in the detection engine?

If this is the better solution, can you please help me creating one, as per my requirement?

---

<div class="post-metadata">

**Author:** ![Felix\_Roessel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felix_roessel/32/41623_2.png) [@Felix\_Roessel](https://discuss.elastic.co/u/Felix_Roessel)\
**Post date:** [April 16, 2021, 11:28am UTC](https://discuss.elastic.co/t/help-me-writing-watcher-query/270103/4 "2021-04-16T11:28:14Z")

</div>

The detection engine is the inbuild feature to detect security related threats. There are many advantages using this type of detection, e.g. that you can follow up immediatly and put the created alert in an investigation status.  
Watcher is a very generic way of doing alerting. Thats powerful but comes with complexity in setting it up.

To build your requirement in the detection engine navigate to Detections under Elastic Security (\>v7.9) and click on manage detection rules.  
There you are able to create a new rule. Choose threshold rule.  
In the query bar you filter for every log in events thats older than 30d (now-30d) .. don't have the exact query by hand but you will get it. Its easy.  
Now you just need to add the group by field which is your user.name and threshold \> 0 .

After creating that rule you will get an alert everytime someone was active one month ago. Is that want you want to achieve?

---

<div class="post-metadata">

**Author:** ![Felix\_Roessel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felix_roessel/32/41623_2.png) [@Felix\_Roessel](https://discuss.elastic.co/u/Felix_Roessel)\
**Post date:** [April 16, 2021, 11:30am UTC](https://discuss.elastic.co/t/help-me-writing-watcher-query/270103/5 "2021-04-16T11:30:14Z")

</div>

Thinking more about it you probably want to observe the durartion between two logs of the same user.  
For that you need to use a transform first to calculate time between two events of the same user.

---

<div class="post-metadata">

**Author:** ![abhishek\_s1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abhishek_s1/32/85080_2.png) [@abhishek\_s1](https://discuss.elastic.co/u/abhishek_s1)\
**Post date:** [April 16, 2021, 11:47am UTC](https://discuss.elastic.co/t/help-me-writing-watcher-query/270103/6 "2021-04-16T11:47:39Z")

</div>

Hello @Felix_Roessel

> [@Felix\_Roessel](#):
>
> you probably want to observe the durartion between two logs of the same user.

You are right & I need to alert if that duration exceeds a month.

> [@Felix\_Roessel](#):
>
> you need to use a transform first to calculate time between two events of the same user

How to write & use transforms?

Thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 14, 2021, 11:47am UTC](https://discuss.elastic.co/t/help-me-writing-watcher-query/270103/7 "2021-05-14T11:47:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
