# How to deploy alert on incoming events

**URL:** <https://discuss.elastic.co/t/how-to-deploy-alert-on-incoming-events/267920>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [March 21, 2021, 10:06pm UTC](https://discuss.elastic.co/t/how-to-deploy-alert-on-incoming-events/267920 "2021-03-21T22:06:57Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![\_omar](https://avatars.discourse-cdn.com/v4/letter/_/87869e/32.png) [@\_omar](https://discuss.elastic.co/u/_omar)\
**Post date:** [March 21, 2021, 10:06pm UTC](https://discuss.elastic.co/t/how-to-deploy-alert-on-incoming-events/267920/1 "2021-03-21T22:06:57Z")

</div>

Hi  
I'm a new user of 'elastic', and need to deploy an alert that notify each event with 'geoip.country\_name' tag value distinct than 'peru'. The alert have to be in real time, like the mostly siem solutions do, so far i got:

```auto
> PUT _watcher/watch/alert_geoip_watch
> {
> "trigger" : { "schedule" : { "interval" : "3m" }},
> "input" : {
> "search" : {
> "request" : {
> "indices" : ["logstash*"],
> "body" : {
> "query" : {
> "bool" : {
> "must" : { "exists": { "field": "geoip.country_name" } },
> "filter": { "range": { "@timestamp": { "gte": "now-3m" } } },
> "must_not": { "term": { "geoip.country_name": "peru" } }
> }
> }
> }
> }
> }
> },
> "condition" : {
> "compare" : { "ctx.payload.hits.total" : { "gt" : 0 }}
> },
> "actions": { }
> }

```

That 'Watcher' rule works, but I'm not sure that is a real time, because its trigger every 3 min and look on "now-3m" period. Any suggest?

---

<div class="post-metadata">

**Author:** ![Felix\_Roessel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felix_roessel/32/41623_2.png) [@Felix\_Roessel](https://discuss.elastic.co/u/Felix_Roessel)\
**Post date:** [March 22, 2021, 5:44am UTC](https://discuss.elastic.co/t/how-to-deploy-alert-on-incoming-events/267920/2 "2021-03-22T05:44:20Z")

</div>

To get it near real time you can reduce the interval between each execution of course.  
But if you would like to use this rule as part of your Elastic based SIEM I would recommend doing that kind of job with the detection engine in Kibana.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2021, 5:44am UTC](https://discuss.elastic.co/t/how-to-deploy-alert-on-incoming-events/267920/3 "2021-04-19T05:44:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
