# Kibana Watcher Advanced query is not working as expected

**URL:** <https://discuss.elastic.co/t/kibana-watcher-advanced-query-is-not-working-as-expected/253617>\
**Category:** Kibana\
**Created:** [October 28, 2020, 8:42pm UTC](https://discuss.elastic.co/t/kibana-watcher-advanced-query-is-not-working-as-expected/253617 "2020-10-28T20:42:22Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![fredrick.bb](https://avatars.discourse-cdn.com/v4/letter/f/7bcc69/32.png) [@fredrick.bb](https://discuss.elastic.co/u/fredrick.bb)\
**Post date:** [October 28, 2020, 8:42pm UTC](https://discuss.elastic.co/t/kibana-watcher-advanced-query-is-not-working-as-expected/253617/1 "2020-10-28T20:42:22Z")

</div>

Hello

I'm finding hard time to have working query to execute Kibana Watcher. I feel my condition and query is correct but it didn't execute as per the condition. Could you confirm what is wrong in this?

```
{
  "trigger": {
    "schedule": {
      "interval": "5m"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "*Index*"
        ],
        "rest_total_hits_as_int": true,
        "body": {
          "size": 1,
          "query": {
            "bool": {
              "must": [],
              "filter": [
                {
                  "bool": {
                    "filter": [
                      {
                        "bool": {
                          "should": [
                            {
                              "match": {
                                "APPLICATION_NAME": "order"
                              }
                            }
                          ],
                          "minimum_should_match": 1
                        }
                      },
                      {
                        "bool": {
                          "filter": [
                            {
                              "bool": {
                                "should": [
                                  {
                                    "match": {
                                      "PARTITION": 3
                                    }
                                  }
                                ],
                                "minimum_should_match": 1
                              }
                            },
                            {
                              "bool": {
                                "should": [
                                  {
                                    "match_phrase": {
                                      "message": "orderXmlReceived"
                                    }
                                  }
                                ],
                                "minimum_should_match": 1
                              }
                            },
                            {
                              "range": {
                                "@timestamp": {
                                  "lte": "now-5m/m"
                                }
                              }
                            }
                          ]
                        }
                      }
                    ]
                  }
                }
              ],
              "should": [],
              "must_not": []
            }
          }
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "eq": 0
      }
    }
  },
  "actions": {
    "email_administrator": {
      "throttle_period_in_millis": 900000,
      "email": {
        "profile": "standard",
        "priority": "high",
        "to": [
          "myemail@gmail.com"
        ],
        "subject": "Order Partition 0 ",
        "body": {
          "text": "Please check with support team"
        }
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![Iker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iker/32/91708_2.png) [@Iker](https://discuss.elastic.co/u/Iker)\
**Post date:** [October 29, 2020, 6:11am UTC](https://discuss.elastic.co/t/kibana-watcher-advanced-query-is-not-working-as-expected/253617/2 "2020-10-29T06:11:16Z")

</div>

A couple things in your watcher.

1. The range for the filter if pretty deep in the query, try with it at the base, correct me if i'm wrong but I think that you try to use "gte" instead of ""lte", otherwise you are going to receive a lot of notifications.
2. The condition fires when there is no documents that match the conditions, with your query there is the possibility that never happens (Cause you are using lte).

---

<div class="post-metadata">

**Author:** ![fredrick.bb](https://avatars.discourse-cdn.com/v4/letter/f/7bcc69/32.png) [@fredrick.bb](https://discuss.elastic.co/u/fredrick.bb)\
**Post date:** [October 29, 2020, 2:41pm UTC](https://discuss.elastic.co/t/kibana-watcher-advanced-query-is-not-working-as-expected/253617/3 "2020-10-29T14:41:40Z")

</div>

Thanks for you response @Iker .

My requirement itself, on those three fields for a given period of time in the given indices if there are no documents found, then email action should be triggered.

In my case the same code when I change condition from 'eq' to 'gte' It triggered email which is fine because there were documents. Which confirmed that my condition worked.  
But during the real crisis time, when I check 'eq' : 0 and for no document It didn't trigger action.

I have given range as below, which means it should check past 5 mins from now.  
"range": {  
"@timestamp": {  
"lte": "now-5m/m"  
}  
}  
During the crisis, the watcher didn't trigger the action. Where can go and see the time range of search in the result json.

---

<div class="post-metadata">

**Author:** ![Iker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iker/32/91708_2.png) [@Iker](https://discuss.elastic.co/u/Iker)\
**Post date:** [October 29, 2020, 3:31pm UTC](https://discuss.elastic.co/t/kibana-watcher-advanced-query-is-not-working-as-expected/253617/4 "2020-10-29T15:31:19Z")

</div>

To check for no documents with eq:0 you have to use gte, because the range that you specifies, checks All the documents with timestamp less than or equal to now-5m, so always is gonna be some documents, it checks from the start of the universe to now-5m, use "gte": "now-5m" to check for the last past five minutes

---

<div class="post-metadata">

**Author:** ![fredrick.bb](https://avatars.discourse-cdn.com/v4/letter/f/7bcc69/32.png) [@fredrick.bb](https://discuss.elastic.co/u/fredrick.bb)\
**Post date:** [October 30, 2020, 1:42pm UTC](https://discuss.elastic.co/t/kibana-watcher-advanced-query-is-not-working-as-expected/253617/5 "2020-10-30T13:42:23Z")

</div>

Thanks @Iker. Above solution fixed my problem

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 27, 2020, 1:42pm UTC](https://discuss.elastic.co/t/kibana-watcher-advanced-query-is-not-working-as-expected/253617/6 "2020-11-27T13:42:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
