# How to define the query time range of advanced watches?

**URL:** <https://discuss.elastic.co/t/how-to-define-the-query-time-range-of-advanced-watches/153397>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [October 22, 2018, 12:12pm UTC](https://discuss.elastic.co/t/how-to-define-the-query-time-range-of-advanced-watches/153397 "2018-10-22T12:12:45Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![wujiaxin159](https://avatars.discourse-cdn.com/v4/letter/w/e68b1a/32.png) [@wujiaxin159](https://discuss.elastic.co/u/wujiaxin159)\
**Post date:** [October 22, 2018, 12:12pm UTC](https://discuss.elastic.co/t/how-to-define-the-query-time-range-of-advanced-watches/153397/1 "2018-10-22T12:12:45Z")

</div>

Elastic version: 6.3.0  
How to define the query time range of advanced watches?  
For example, the last 5 minutes.

```
{
  "trigger": {
    "schedule": {
      "interval": "15s"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "gateway*"
        ],
        "types": [],
        "body": {
          "size": 0,
          "query": {
            "match": {
              "level": "ERROR"
            }
          }
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "gte": 10
      }
    }
  },
  "actions": {
    "email_administrator": {
      "email": {
        "profile": "standard",
        "priority": "high",
        "to": [
          "admin@local.com"
        ],
        "subject": "test",
        "body": {
          "text": "{{ctx.payload}}"
        }
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![tianshu\_Peng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tianshu_peng/32/36807_2.png) [@tianshu\_Peng](https://discuss.elastic.co/u/tianshu_Peng)\
**Post date:** [October 23, 2018, 2:59am UTC](https://discuss.elastic.co/t/how-to-define-the-query-time-range-of-advanced-watches/153397/2 "2018-10-23T02:59:37Z")

</div>

try this query:

```auto
{
  "query": {
    "bool": {
      "filter": [
        {
          "range": {
            "@timestamp": {
              "from": "now-5m",
              "to": "now"
            }
          }
        },
        {
          "match": {
            "level": "ERROR"
          }
        }
      ]
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![wujiaxin159](https://avatars.discourse-cdn.com/v4/letter/w/e68b1a/32.png) [@wujiaxin159](https://discuss.elastic.co/u/wujiaxin159)\
**Post date:** [October 23, 2018, 7:22am UTC](https://discuss.elastic.co/t/how-to-define-the-query-time-range-of-advanced-watches/153397/3 "2018-10-23T07:22:51Z")

</div>

Thank you. I found it in the official website.

```
"input" : {
    "search" : {
      "request" : {
        "indices" : [
          "logstash*"
        ],
        "body" : {
          "query" : {
            "bool" : {
              "must" : {
                "match": {
                   "response": 404
                }
              },
              "filter" : {
                "range": {
                  "@timestamp": {
                    "from": "{{ctx.trigger.scheduled_time}}||-5m",
                    "to": "{{ctx.trigger.triggered_time}}"
                  }
                }
              }
            }
          }
        }
      }
    }
  }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 20, 2018, 7:22am UTC](https://discuss.elastic.co/t/how-to-define-the-query-time-range-of-advanced-watches/153397/4 "2018-11-20T07:22:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
