# How to set a time range in the watcher?

**URL:** <https://discuss.elastic.co/t/how-to-set-a-time-range-in-the-watcher/93679>\
**Category:** Elasticsearch\
**Created:** [July 19, 2017, 2:53am UTC](https://discuss.elastic.co/t/how-to-set-a-time-range-in-the-watcher/93679 "2017-07-19T02:53:46Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![KeithTt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keithtt/32/29447_2.png) [@KeithTt](https://discuss.elastic.co/u/KeithTt)\
**Post date:** [July 19, 2017, 2:53am UTC](https://discuss.elastic.co/t/how-to-set-a-time-range-in-the-watcher/93679/1 "2017-07-19T02:53:46Z")

</div>

Can I set a time range about watcher?

Is there a guide for this setting?

I found a sample here:

[https://www.elastic.co/guide/en/x-pack/5.x/watching-meetup-data.html](https://www.elastic.co/guide/en/x-pack/5.x/watching-meetup-data.html)

Here is my configuration:

```auto
PUT _xpack/watcher/watch/error_fzf
{
  "metadata" : { 
    "color" : "red"
  },
  "trigger" : { 
    "schedule" : { 
      "interval" : "1m" 
    }
  },
  "input" : {
    "search" : {
      "request" : {
        "indices" : [ 
          "kibana-nginx-access-*",
          "zixun-nginx-access-*"
        ],
        "body" : {
          "size": 0,
          "query" : {
            "bool": {
              "filter": [
                {
                  "range": {
                    "@timestamp": {
                      "gte": "now-3m"
                    }
                  },
                  "match": {
                    "message": "404"
                  }
                }               
              ]
            }
          }
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "gt": 0
      }
    }
  },
  "actions": {
    "send_email": {
      "throttle_period": "3m",
      "email": {
        "from": "shengyongp@oupeng.com", 
        "to": [
          "PeiShengyong shengyongp@oupeng.com",
          "DuanWei weiduan@oupeng.com"
        ],  
        "subject": "Watcher Notification from {{ctx.payload.hits.hits.0._source.beat.name}}",
        "body": {
          "text": "Found {{ctx.payload.hits.total}} 404 errors in the logs"
        }
      }
    }
  }
}

```

BUT, it don't send notification...............is there anything wrong or missed something?

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [July 20, 2017, 2:08pm UTC](https://discuss.elastic.co/t/how-to-set-a-time-range-in-the-watcher/93679/2 "2017-07-20T14:08:26Z")

</div>

Hello,

The documentation you seek is found [here](https://www.elastic.co/guide/en/x-pack/current/input-search.html)

Also, we have a [public github repo](https://github.com/elastic/examples/tree/master/Alerting/Sample%20Watches) that has a bunch of example watches.

At first blush - your setting of `range` of `@timestamp` to be `"gte": "now-3m"` looks correct. Are you sure, however, that there are actually some 404 errors your logs in the last 3 minutes?

---

<div class="post-metadata">

**Author:** ![KeithTt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keithtt/32/29447_2.png) [@KeithTt](https://discuss.elastic.co/u/KeithTt)\
**Post date:** [July 21, 2017, 10:14am UTC](https://discuss.elastic.co/t/how-to-set-a-time-range-in-the-watcher/93679/3 "2017-07-21T10:14:02Z")

</div>

> [@richcollier](#):
>
> The documentation you seek is found here

I am sorry, I don't find the info about time range in the link, which section do you mean?

> [@richcollier](#):
>
> Are you sure, however, that there are actually some 404 errors your logs in the last 3 minutes?

I am sure there are some 404 errors in the log, and I have never received a notification...

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [July 21, 2017, 12:06pm UTC](https://discuss.elastic.co/t/how-to-set-a-time-range-in-the-watcher/93679/4 "2017-07-21T12:06:25Z")

</div>

Sorry for the misunderstanding - I thought originally you were looking for information on the search input for a Watch. If you're looking for information on options for the `range` query, [you can find it here](https://www.elastic.co/guide/en/elasticsearch/reference/5.4/query-dsl-range-query.html) - it is a core feature of the elasticsearch query DSL, not just a feature of a watch.

Taking a harder look at your setup, you should modify your query clause to look like this:

```auto
          "query": {
            "bool": {
              "filter": [
                {
                  "range": {
                    "@timestamp": {
                      "gte": "now-3m"
                    }
                  }
                },
                {
                  "term": {
                    "message": "404"
                  }
                }
              ]
            }
          }

```

In other words, do a `term` filter.

Another thing to double check is that your time field in your index truly is `@timestamp` instead of other possibilities (like just plain `timestamp`)

Finally, to take any possible setup issues related to the email notification out of the picture, you can add the following logging action in addition to the email:

```auto
  "actions": {
    "log": {
      "logging": {
        "level": "info",
        "text": "Watcher Notification from {{ctx.payload.hits.hits.0._source.beat.name}} - Found {{ctx.payload.hits.total}} 404 errors in the logs"
      }
    },
    "send_email": {
      "throttle_period_in_millis": 180000,
      "email": {
        "profile": "standard",
        "from": "shengyongp@oupeng.com",
        "to": [
          "PeiShengyong shengyongp@oupeng.com",
          "DuanWei weiduan@oupeng.com"
        ],
        "subject": "Watcher Notification from {{ctx.payload.hits.hits.0._source.beat.name}}",
        "body": {
          "text": "Found {{ctx.payload.hits.total}} 404 errors in the logs"
        }
      }
    }
  },

```

So that the text of the watch results simply show up in the elasticsearch.log file.

Hope that helps!

---

<div class="post-metadata">

**Author:** ![KeithTt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keithtt/32/29447_2.png) [@KeithTt](https://discuss.elastic.co/u/KeithTt)\
**Post date:** [July 24, 2017, 3:29am UTC](https://discuss.elastic.co/t/how-to-set-a-time-range-in-the-watcher/93679/5 "2017-07-24T03:29:32Z")

</div>

hi rich,

I found there are many error in my ES log:

```auto
[2017-07-24T11:27:03,007][ERROR][o.e.x.w.i.s.ExecutableSimpleInput] [uy-s-169] failed to execute [search] input for watch [error_fzf], reason [[range] malformed query, expected [END_OBJECT] but found [FIELD_NAME]]

```

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [July 24, 2017, 1:44pm UTC](https://discuss.elastic.co/t/how-to-set-a-time-range-in-the-watcher/93679/6 "2017-07-24T13:44:09Z")

</div>

Hi,

If you haven't changed your query clause to what I recommend, you will get this error because there is a syntax problem in your query clause. You are not properly making an array of clauses in the `filter` section. You have to look close at the matching {} brackets to see.

Please modify it to the following and you'll be fine:

```auto
          "query": {
            "bool": {
              "filter": [
                {
                  "range": {
                    "timestamp": {
                      "gte": "now-3m"
                    }
                  }
                },
                {
                  "match": {
                    "message": "404"
                  }
                }
              ]
            }
          }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 21, 2017, 1:44pm UTC](https://discuss.elastic.co/t/how-to-set-a-time-range-in-the-watcher/93679/7 "2017-08-21T13:44:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
