# Increment date field watcher

**URL:** <https://discuss.elastic.co/t/increment-date-field-watcher/308190>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting, painless\
**Created:** [June 26, 2022, 5:57pm UTC](https://discuss.elastic.co/t/increment-date-field-watcher/308190 "2022-06-26T17:57:26Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cheroufa](https://avatars.discourse-cdn.com/v4/letter/c/ec9cab/32.png) [@Cheroufa](https://discuss.elastic.co/u/Cheroufa)\
**Post date:** [June 26, 2022, 5:57pm UTC](https://discuss.elastic.co/t/increment-date-field-watcher/308190/1 "2022-06-26T17:57:26Z")

</div>

hello team,

i want to increment date field """ {{ctx.payload.second.time}} + 30m """ in watcher but i don't know how to do it, any idea ?

my code :

"input": {  
"chain": {  
"inputs": [  
{  
"first": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"index-1-_"  
],  
"rest\_total\_hits\_as\_int": true,  
"body": {  
"size": 2,  
"query": {  
"bool": {  
"should": [  
{  
"term": {  
"a.keyword": "__**"  
}  
},  
{  
"term": {  
"n.keyword": " **_** _"  
}  
}  
],  
"minimum\_should\_match": 2  
}  
},  
"sort": [  
{  
"date": {  
"order": "desc"  
}  
}  
]  
}  
}  
}  
}  
},  
{  
"second": {  
"transform": {  
"script": {  
"source": "return ['time' : ctx.payload.first.hits.hits.0.\_source.date]",  
"lang": "painless"  
}  
}  
}  
},  
{  
"third": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"index-2-_"  
],  
"rest\_total\_hits\_as\_int": true,  
"body": {  
"size": 1,  
"query": {  
"bool": {  
"must": [  
{  
"term": {  
"c.keyword": "**"  
}  
},  
{  
"term": {  
"en.keyword": "\*_**"  
}  
},  
{  
"term": {  
"order\_file\_type.keyword": "**_"  
}  
},  
{  
"range": {  
"metadata.ingested": {  
"gte": "{{ctx.payload.second.time}}"  
"lte":"{{ctx.payload.second.time}} + 30"  
}  
}  
}  
]  
}  
},  
"aggs": {  
"1": {  
"cardinality": {  
"field": "filename.keyword"  
}  
}  
}  
}  
}  
}  
}  
}  
]  
}  
},

thanks for help.

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [June 27, 2022, 11:48am UTC](https://discuss.elastic.co/t/increment-date-field-watcher/308190/2 "2022-06-27T11:48:54Z")

</div>

Requires use of `||` like this (also see [docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/common-options.html#date-math):

```auto
"range": {
"metadata.ingested": {
"gte": "{{ctx.payload.second.time}}"
"lte":"{{ctx.payload.second.time}}|| + 30m"
}

```

---

<div class="post-metadata">

**Author:** ![Cheroufa](https://avatars.discourse-cdn.com/v4/letter/c/ec9cab/32.png) [@Cheroufa](https://discuss.elastic.co/u/Cheroufa)\
**Post date:** [June 27, 2022, 12:19pm UTC](https://discuss.elastic.co/t/increment-date-field-watcher/308190/3 "2022-06-27T12:19:09Z")

</div>

it does'nt work with your solution.

i use this script :

```
      "script": {		
      "source": """
                String datetime = ctx.payload.first.hits.hits.0._source['@timestamp'];
                return [
                  'from' : datetime,
                  'to' : ZonedDateTime.parse(datetime).plusMinutes(30)
                ]""",
              "lang": "painless"
           }

```

it works for : @timestamp = "2022-06-27T05:15:04.986Z"  
but not for a other field : ctx.payload.first.hits.hits.0.\_source.dateField  
dateField = "2022-06-27T05:15:04.986+0000"

is it due to the date format ?

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [June 27, 2022, 12:45pm UTC](https://discuss.elastic.co/t/increment-date-field-watcher/308190/5 "2022-06-27T12:45:58Z")

</div>

If your field that you want to do date math on is of type `date` then it will work. What is the mapping type for the field `dateField`?

edit: changed bad grammar

---

<div class="post-metadata">

**Author:** ![Cheroufa](https://avatars.discourse-cdn.com/v4/letter/c/ec9cab/32.png) [@Cheroufa](https://discuss.elastic.co/u/Cheroufa)\
**Post date:** [June 27, 2022, 1:03pm UTC](https://discuss.elastic.co/t/increment-date-field-watcher/308190/6 "2022-06-27T13:03:15Z")

</div>

dateField is of type date too

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [June 27, 2022, 2:39pm UTC](https://discuss.elastic.co/t/increment-date-field-watcher/308190/7 "2022-06-27T14:39:40Z")

</div>

You can see an example of this kind of date math [here](https://gist.github.com/richcollier/7e5603c366b9fcece6f1a8b1b3cf4d3f) on line 57

You must have a problem elsewhere. Is the code at the top your actual Watch definition?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 25, 2022, 2:39pm UTC](https://discuss.elastic.co/t/increment-date-field-watcher/308190/8 "2022-07-25T14:39:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
