# Search logs entered in previous 15 minutes

**URL:** <https://discuss.elastic.co/t/search-logs-entered-in-previous-15-minutes/133684>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [May 29, 2018, 12:43pm UTC](https://discuss.elastic.co/t/search-logs-entered-in-previous-15-minutes/133684 "2018-05-29T12:43:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![varun48](https://avatars.discourse-cdn.com/v4/letter/v/eb8c5e/32.png) [@varun48](https://discuss.elastic.co/u/varun48)\
**Post date:** [May 29, 2018, 12:43pm UTC](https://discuss.elastic.co/t/search-logs-entered-in-previous-15-minutes/133684/1 "2018-05-29T12:43:14Z")

</div>

I am new to Elasticsearch/Kibana.  
I am trying to create a watcher which searches **The system here is crashed** in logs entered in previous 15 minutes.  
I have created the following JSON as per my knowledge  
{  
"trigger": {  
"schedule": {  
"interval": "10m"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"\*"  
],  
"types": [],  
"body": {  
"query": {  
"bool": {  
"must": [  
{  
"query\_string": {  
"query": "The system here is crashed"  
}  
},  
{  
"range": {  
"msgSubmissionTime": {  
"gte": "now-15m"  
}  
}  
}  
]  
}  
},  
"\_source": [  
"message"  
],  
"sort": [  
{  
"@timestamp": {  
"order": "desc"  
}  
}  
]  
}  
}  
}  
},  
"condition": {  
"compare": {  
"ctx.payload.hits.total": {  
"gte": 0  
}  
}  
},  
"actions": {  
"send\_email": {  
"email": {  
"profile": "standard",  
"to": [  
"myemailid@mydomain.com"  
],  
"subject": "Hello World",  
"body": {  
"text": "{{ctx.payload.hits.total}} error logs found containing The system here is crashed"  
}  
}  
}  
}  
}  
But it does not seem to work as it it is showing **0 error logs found** in simulation.  
I am using `msgSubmissionTime` to search in logs entered in previous 15 minutes.  
Am I not using `range` correctly or any other mistake.  
There may be very basic mistake as I am new to this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 26, 2018, 12:58pm UTC](https://discuss.elastic.co/t/search-logs-entered-in-previous-15-minutes/133684/2 "2018-06-26T12:58:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [July 3, 2018, 8:42am UTC](https://discuss.elastic.co/t/search-logs-entered-in-previous-15-minutes/133684/3 "2018-07-03T08:42:20Z")

</div>

Hey,

sorry for the late response, just found this one.

Can you include the output of the [execute watch API](https://www.elastic.co/guide/en/elasticsearch/reference/6.3/watcher-api-execute-watch.html) for this one?

Also, please properly format any JSON snippet, as it makes reading way more easy. You can use markdown in here.

--Alex
