# How to send a link with time that watcher check

**URL:** <https://discuss.elastic.co/t/how-to-send-a-link-with-time-that-watcher-check/152234>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [October 12, 2018, 12:02pm UTC](https://discuss.elastic.co/t/how-to-send-a-link-with-time-that-watcher-check/152234 "2018-10-12T12:02:43Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![\_Sergey](https://avatars.discourse-cdn.com/v4/letter/_/e68b1a/32.png) [@\_Sergey](https://discuss.elastic.co/u/_Sergey)\
**Post date:** [October 12, 2018, 12:02pm UTC](https://discuss.elastic.co/t/how-to-send-a-link-with-time-that-watcher-check/152234/1 "2018-10-12T12:02:43Z")

</div>

Hello all,  
We have watchers that send us the notifications with link to visualizations. Almost all watchers check period like "now-1h" or similar.

My question is: Is there any possible way that my watchers will send me links to those visualizations but with the time frame that this watcher has checked? Cause all our visualizations saved or unsaved with now-1h etc, but when I missed notification and then want to check those stats send in notification I will open that link and see period now-1h NOT those stats from that notification for that period when watcher find stats.

So I check link for visualization and see that it contains  
`https://kibana.......,**time:(from:'2018-09-13T00:00:00.000Z',mode:absolute,to:'2018-09-13T23:59:59.999Z'))**......`

I think I can use their smth from output like _""result": { "execution\_time":..."_ (so this can be used in  
`to:' {{ctx.execution_time}})` but I don't see in the same format _"result": { "execution\_time":_ **-1h** (for the part from...)

Can you advise if it can be done and how, thanks!

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 15, 2018, 7:22am UTC](https://discuss.elastic.co/t/how-to-send-a-link-with-time-that-watcher-check/152234/2 "2018-10-15T07:22:40Z")

</div>

Hey,

you need an absolute timestamp in there as `now` would always be dependent when the user is clicking on the dashboard. So the best way would be to use `ctx.execution_time` as an absolute value.

Hope this makes sense.

--Alex

---

<div class="post-metadata">

**Author:** ![\_Sergey](https://avatars.discourse-cdn.com/v4/letter/_/e68b1a/32.png) [@\_Sergey](https://discuss.elastic.co/u/_Sergey)\
**Post date:** [October 16, 2018, 10:20am UTC](https://discuss.elastic.co/t/how-to-send-a-link-with-time-that-watcher-check/152234/3 "2018-10-16T10:20:14Z")

</div>

Thanks Alex,

That's how I think to try to do. But I faced with situation:  
the link contains next (example if we use to check from now -1d to now):

> [https://kibana](https://kibana).......,time:(from:now-1d,mode:relative,to:now))&\_a=(filters...

From output I can take, as you also suggest, `{{ctx.execution_time}}` and put it instead of `now` (in output of watcher the format of `execution_time` is `2018-10-09T00:00:00.000Z`) (as I understand till execution time data was taken and check - so it is `now`).  
Then I can change ` mode:relative to -> mode:absolute`.  
But still confused how to change part `from:now-1d`.  
I know I can save the visualization with some time frame and share link to users and when they open will see my time frame (despite actually when they open it). So I thought it can be done in watcher somehow

---

<div class="post-metadata">

**Author:** ![\_Sergey](https://avatars.discourse-cdn.com/v4/letter/_/e68b1a/32.png) [@\_Sergey](https://discuss.elastic.co/u/_Sergey)\
**Post date:** [October 16, 2018, 10:35am UTC](https://discuss.elastic.co/t/how-to-send-a-link-with-time-that-watcher-check/152234/4 "2018-10-16T10:35:06Z")

</div>

**UPDATE**

Seems I found how to do it:

`"https://kibana.......,time:(from:'{{ctx.execution_time}}||-1d',mode:absolute,to:'{{ctx.execution_time}}'))&_a=(fil.....`

So I use here `from:'{{ctx.execution_time}}||-1d'` and the link that comes with alert works (time period in visualization doesn't change whether I open it in few sec or in few minutes later after alert)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 13, 2018, 10:35am UTC](https://discuss.elastic.co/t/how-to-send-a-link-with-time-that-watcher-check/152234/5 "2018-11-13T10:35:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
