# Query hostname field with zero hit count

**URL:** <https://discuss.elastic.co/t/query-hostname-field-with-zero-hit-count/314240>\
**Category:** Kibana\
**Created:** [September 13, 2022, 2:47am UTC](https://discuss.elastic.co/t/query-hostname-field-with-zero-hit-count/314240 "2022-09-13T02:47:22Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![lchan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lchan/32/90857_2.png) [@lchan](https://discuss.elastic.co/u/lchan)\
**Post date:** [September 13, 2022, 2:47am UTC](https://discuss.elastic.co/t/query-hostname-field-with-zero-hit-count/314240/1 "2022-09-13T02:47:22Z")

</div>

Hi all,

I am trying to write a watcher alert if any host `hostname.keyword` has a 0 hit count in the last 1d.

This has asked numerous times but most of them is circulating around entire indices, not for the host field. Any pointer would be helpful.

Thanks!  
Leo

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 11, 2022, 2:47am UTC](https://discuss.elastic.co/t/query-hostname-field-with-zero-hit-count/314240/2 "2022-10-11T02:47:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
