# Querying Watches with Specific Alert Condition States

**URL:** <https://discuss.elastic.co/t/querying-watches-with-specific-alert-condition-states/376948>\
**Category:** Kibana\
**Tags:** elastic-stack-monitoring, elastic-stack-alerting\
**Created:** [April 9, 2025, 8:43am UTC](https://discuss.elastic.co/t/querying-watches-with-specific-alert-condition-states/376948 "2025-04-09T08:43:57Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Santiago\_Carnicero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/santiago_carnicero/32/138980_2.png) [@Santiago\_Carnicero](https://discuss.elastic.co/u/Santiago_Carnicero)\
**Post date:** [April 9, 2025, 8:43am UTC](https://discuss.elastic.co/t/querying-watches-with-specific-alert-condition-states/376948/1 "2025-04-09T08:43:57Z")

</div>

Dear Elasticsearch Community,

I'm implementing a monitoring dashboard that needs to display all active watches that have met their alerting conditions within a specific time window but have not returned to a normal state. Essentially, I need to identify watches that are currently in an ERROR state.

## Current Implementation Challenge

Based on the Watcher API documentation, I understand that only `_id` and `metadata.*` fields are queryable or sortable. This presents a challenge when trying to filter watches server-side using criteria like:

- `status.state`: "active"
- `status.execution_state`: "executed" OR "acknowledged"
- `status.last_checked`: \>= "now-24h"
- `status.actions.last_execution.status`: "executed\_with\_errors"

Currently, I'm implementing this by:

1. Fetching all watches using `GET /_watcher/watch/_all`
2. Applying the filtering logic in my application code

## My Question

Is there a more efficient way to query watches based on their execution state and alerting conditions directly through the API? I'm looking for a solution that:

1. Doesn't require fetching all watches and filtering client-side
2. Can specifically identify watches that met conditions but haven't cleared
3. Allows filtering by time window (e.g., watches that triggered in the last X hours)

Does Elasticsearch provide any advanced querying capabilities for watches that I might have overlooked? Or are there best practices for efficiently monitoring watch states at scale?

Thank you for your time and expertise.

Regards, Santiago
