# Not able to create Kibana alert on Json log due to match all is not working and time is coming as string

**URL:** https://discuss.elastic.co/t/not-able-to-create-kibana-alert-on-json-log-due-to-match-all-is-not-working-and-time-is-coming-as-string/300036
**Category:** Kibana
**Tags:** elastic-stack-alerting
**Created:** [March 18, 2022, 11:33am UTC](https://discuss.elastic.co/t/not-able-to-create-kibana-alert-on-json-log-due-to-match-all-is-not-working-and-time-is-coming-as-string/300036 "2022-03-18T11:33:01Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![riya9](https://avatars.discourse-cdn.com/v4/letter/r/b5a626/32.png) [@riya9](https://discuss.elastic.co/u/riya9)
#### Post date: [March 18, 2022, 11:33am UTC](https://discuss.elastic.co/t/not-able-to-create-kibana-alert-on-json-log-due-to-match-all-is-not-working-and-time-is-coming-as-string/300036/1 "2022-03-18T11:33:01Z")

</div>

Hi All , I am looking to create alert on Json log to match on any of the 3 job name with failed condition to check this condition every 70 min .

the alert is not working because of 2 reason.`Preformatted text`  
1)the scheduled time on which I am trying to put range is not working ,as this time field is string in the Index .  
2)if i run without the range and it returns me josn log with other job name which was failed so somehow the match combination is also not working :

would be grateful for any suggestion .

below is my query :

```auto
{
    "size": 100,
    "query": {
        "bool": {
            "filter": [
                {
                    "match_all": {
                        "boost": 1
                    }
                },
                {
                    "bool": {
                        "should": [
                            {
                                "match_phrase": {
                                    "LOGS.NAME.keyword": {
                                        "query": "TASK_110067",
                                        "slop": 0,
                                        "zero_terms_query": "NONE",
                                        "boost": 1
                                    }
                                }
                            },
                            {
                                "match_phrase": {
                                    "LOGS.NAME.keyword": {
                                        "query": "TASK_14404",
                                        "slop": 0,
                                        "zero_terms_query": "NONE",
                                        "boost": 1
                                    }
                                }
                            },
                            {
                                "match_phrase": {
                                    "LOGS.NAME.keyword": {
                                        "query": "TASK_1440",
                                        "slop": 0,
                                        "zero_terms_query": "NONE",
                                        "boost": 1
                                    }
                                }
                            }
                        ],
                        "adjust_pure_negative": true,
                        "minimum_should_match": "1",
                        "boost": 1
                    }
                },
                {
                    "match_phrase": {
                        "LOGS.STATE.keyword": {
                            "query": "FAILED",
                            "slop": 0,
                            "zero_terms_query": "NONE",
                            "boost": 1
                        }
                    }
                },
                {
                    "range": {
                        "LOGS.SCHEDULED_TIME.keyword": {
                            "from": "now-70m",
                            "to": "now",
                            "include_lower": true,
                            "include_upper": true,
                            "format": "epoch_millis",
                            "boost": 1
                        }
                    }
                }
            ],
            "adjust_pure_negative": true,
            "boost": 1
        }
    },
    "_source": {
        "includes": [],
        "excludes": []
    },
    "stored_fields": "*",
    "docvalue_fields": [],
    "script_fields": {},
    "aggregations": {}
}

```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 15, 2022, 11:33am UTC](https://discuss.elastic.co/t/not-able-to-create-kibana-alert-on-json-log-due-to-match-all-is-not-working-and-time-is-coming-as-string/300036/2 "2022-04-15T11:33:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
