Elastic version: 6.3.0
How to define the query time range of advanced watches?
For example, the last 5 minutes.
{
"trigger": {
"schedule": {
"interval": "15s"
}
},
"input": {
"search": {
"request": {
"search_type": "query_then_fetch",
"indices": [
"gateway*"
],
"types": [],
"body": {
"size": 0,
"query": {
"match": {
"level": "ERROR"
}
}
}
}
}
},
"condition": {
"compare": {
"ctx.payload.hits.total": {
"gte": 10
}
}
},
"actions": {
"email_administrator": {
"email": {
"profile": "standard",
"priority": "high",
"to": [
"admin@local.com"
],
"subject": "test",
"body": {
"text": "{{ctx.payload}}"
}
}
}
}
}