# How do I setup watcher to only alert on new messages?

**URL:** <https://discuss.elastic.co/t/how-do-i-setup-watcher-to-only-alert-on-new-messages/27330>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [August 13, 2015, 1:34pm UTC](https://discuss.elastic.co/t/how-do-i-setup-watcher-to-only-alert-on-new-messages/27330 "2015-08-13T13:34:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dmccuk](https://avatars.discourse-cdn.com/v4/letter/d/3d9bf3/32.png) [@dmccuk](https://discuss.elastic.co/u/dmccuk)\
**Post date:** [August 13, 2015, 1:34pm UTC](https://discuss.elastic.co/t/how-do-i-setup-watcher-to-only-alert-on-new-messages/27330/1 "2015-08-13T13:34:10Z")

</div>

I've been working through setting up watcher to alert on events it finds in the logs. I set up a watcher like below and every 20 seconds (in the example) it will send an email if it finds a match. But it won't stop. It will keep sending emails every 20 seconds. So, as far as I can tell, you get two options with watcher:

1. Use throttling to set a time on the length of time between emails
2. Add an /\_ack? to the watch and it will ignore future matches until the condition becomes "ok" and then it will send emails the next time it see the match (sort of what i want)

I need and option 3 and it's probably possible to set it up. I'm just not sure how to yet.

1. Alert/email on matches in the logs. Then stop sending emails because there is nothing new (ignoring the ones it's already found). Then if you get a new event, send another email but don't include the previous matches. Is this possible?

This is my watch:

```
 curl -XPUT 'http://localhost:9200/_watcher/watch/my_event_to_match' -d '{
  "trigger" : {
    "schedule" : { "interval" : "20s" }
  },
  "input" : {
    "search" : {
      "request" : {
        "indices" : ["logstash-2015.08.13"],
        "body" : {
          "query" : {
            "match" : { "message": "my_event_to_match" }
          }
        }
      }
    }
  },
  "condition" : {
    "compare" : { "ctx.payload.hits.total" : { "gt" : 0 }} #<-- do I need this condition?
  },
  "actions" : {
    "send_email" : {
      "email" : {
        "to" : "me@me.com ",
        "subject" : "my_event_to_match Warning from Watcher",
        "body" : "my_event_to_match MESSAGE: Please see attached",
        "attach_data" : true
      }
    }
  }
}'

```

This is what I'm using to implement the acknowledgement:

```
curl -XPUT http://localhost:9200/_watcher/watch/my_event_to_match/_ack?

```

I also use this line to list out all the watches I'm currently running:

```
curl -s -XGET 'http://localhost:9200/.watches/_search' -d {} | python -m json.tool | grep _id

```

Can anyone give me some pointers on setting up the watch to only alert on "new" events only and ignore ones it's already found.

Thanks in advance.

Dennis

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [August 13, 2015, 2:31pm UTC](https://discuss.elastic.co/t/how-do-i-setup-watcher-to-only-alert-on-new-messages/27330/2 "2015-08-13T14:31:13Z")

</div>

Hi Dennis,

Your query is currently setup to search across _all time_, so once you have one record in the system that matches, you will get a match every time the query executes. You can use simple date math in the query portion to filter just to recent documents.

Here's a slightly modified watch I used in the recent [Watcher Webinar](https://www.elastic.co/webinars/watcher-practical-alerting-for-elasticsearch). Note the way the query section is written - I filter the results to just the results that occurred in the last 25 seconds. In this case, I setup a slightly larger time range for my query than I do for my trigger interval, just to make sure I don't miss anything that might have been in-flight on it's way into ES.

```json
PUT _watcher/watch/twitter_watcher_mention
{
  "trigger": {
    "schedule": {
      "interval": "20s"
    }
  },
  "input": {
    "search": {
      "request": {
        "indices": ["logstash-*"],
        "body": {
          "query": {
            "filtered": {
              "query": {
                "match_phrase": {"message": "my_event_to_match"}
              },
              "filter": {
                "bool": {
                  "must": [
                    {
                      "range": {
                        "@timestamp": {
                          "gte": "now-25s"
                        }
                      }
                    }
                  ]
                }
              }
            }
          }
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "gt": 0
      }
    }
  },
  "actions": {
    "log" : {
       "logging" : {
         "text" : "There were {{ctx.payload.hits.total}} Tweets at {{ctx.execution_time}}"
       }
     }
  }
}

```

---

<div class="post-metadata">

**Author:** ![dmccuk](https://avatars.discourse-cdn.com/v4/letter/d/3d9bf3/32.png) [@dmccuk](https://discuss.elastic.co/u/dmccuk)\
**Post date:** [August 13, 2015, 4:06pm UTC](https://discuss.elastic.co/t/how-do-i-setup-watcher-to-only-alert-on-new-messages/27330/3 "2015-08-13T16:06:29Z")

</div>

@skearns - that's working now. Thanks for sharing the code.

Just one more quick question, when it comes to doing matche or match\_phrase (with some examples below), will they just work or need to be formatted in a particular way?

Examples:

[Hardware Error]  
fn[lr][fr].\*LINEPROTO-5-UPDOWN.\*down  
LINK-5-CHANGED.\*reset

Are wildcards \* allowed and []. Do you need to ignore with \ ?

Thanks for you help,

Dennis

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:48pm UTC](https://discuss.elastic.co/t/how-do-i-setup-watcher-to-only-alert-on-new-messages/27330/4 "2017-07-06T13:48:59Z")

</div>


