# Math on triggered time in Kibana watcher

**URL:** <https://discuss.elastic.co/t/math-on-triggered-time-in-kibana-watcher/126019>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [March 29, 2018, 5:42am UTC](https://discuss.elastic.co/t/math-on-triggered-time-in-kibana-watcher/126019 "2018-03-29T05:42:38Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Preetiv](https://avatars.discourse-cdn.com/v4/letter/p/a698b9/32.png) [@Preetiv](https://discuss.elastic.co/u/Preetiv)\
**Post date:** [March 29, 2018, 5:42am UTC](https://discuss.elastic.co/t/math-on-triggered-time-in-kibana-watcher/126019/1 "2018-03-29T05:42:38Z")

</div>

I need to get the watcher's triggered time and subtract a random time (e.g. 5mins from it)  
I am trying something on the following lines but with no success.  
Input:

```auto
  "transform": {
    "script": {
      "source": "return ['time' : '{{ctx.trigger.triggered_time}}||-5m']",
      "lang": "painless"
    }

```

This literally prints out the string.  
Output:

```auto
    "transform": {
      "type": "script",
      "status": "success",
      "payload": {
        "time": "{{ctx.trigger.triggered_time}}||-5m"
      }
    },

```

Isn't transform the right place to do it? Or am I just doing it wrong?  
if `{{ctx.trigger.triggered_time}}` is returned as is (without any math on it), it returns the correct time.  
Please assist.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 29, 2018, 8:28am UTC](https://discuss.elastic.co/t/math-on-triggered-time-in-kibana-watcher/126019/2 "2018-03-29T08:28:08Z")

</div>

date math is only supported in index names, how about this

```auto
    "transform": {
      "script": {
        "source": "return Instant.ofEpochMilli(ctx.trigger.triggered_time.getMillis()).plusSeconds(300)",
        "lang": "painless"
      }
    },

```

---

<div class="post-metadata">

**Author:** ![Preetiv](https://avatars.discourse-cdn.com/v4/letter/p/a698b9/32.png) [@Preetiv](https://discuss.elastic.co/u/Preetiv)\
**Post date:** [March 29, 2018, 5:24pm UTC](https://discuss.elastic.co/t/math-on-triggered-time-in-kibana-watcher/126019/3 "2018-03-29T17:24:50Z")

</div>

Thanks Alex. Your solution was perfect!  
Where can I find the documentation on all these arithmetic functions? Also I am trying to extract substring in my next task. I would appreciate if you could point to some string manipulation functions' documentation as well.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 30, 2018, 9:01am UTC](https://discuss.elastic.co/t/math-on-triggered-time-in-kibana-watcher/126019/4 "2018-03-30T09:01:59Z")

</div>

Checking out the painless docs are a good start [https://www.elastic.co/guide/en/elasticsearch/reference/6.2/modules-scripting-painless.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/modules-scripting-painless.html)

Together with [https://github.com/elastic/elasticsearch/tree/master/modules/lang-painless/src/main/resources/org/elasticsearch/painless/spi](https://github.com/elastic/elasticsearch/tree/master/modules/lang-painless/src/main/resources/org/elasticsearch/painless/spi) - which allows you to see which methods are available as well.

Hope this helps!

--Alex

---

<div class="post-metadata">

**Author:** ![Preetiv](https://avatars.discourse-cdn.com/v4/letter/p/a698b9/32.png) [@Preetiv](https://discuss.elastic.co/u/Preetiv)\
**Post date:** [March 30, 2018, 5:14pm UTC](https://discuss.elastic.co/t/math-on-triggered-time-in-kibana-watcher/126019/5 "2018-03-30T17:14:39Z")

</div>

Thanks Alex. Much appreciated!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 27, 2018, 5:15pm UTC](https://discuss.elastic.co/t/math-on-triggered-time-in-kibana-watcher/126019/6 "2018-04-27T17:15:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
