# Simple watcher syntax help

**URL:** <https://discuss.elastic.co/t/simple-watcher-syntax-help/245426>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [August 18, 2020, 1:21pm UTC](https://discuss.elastic.co/t/simple-watcher-syntax-help/245426 "2020-08-18T13:21:39Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Fredrik\_Cronholm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fredrik_cronholm/32/74091_2.png) [@Fredrik\_Cronholm](https://discuss.elastic.co/u/Fredrik_Cronholm)\
**Post date:** [August 18, 2020, 1:21pm UTC](https://discuss.elastic.co/t/simple-watcher-syntax-help/245426/1 "2020-08-18T13:21:39Z")

</div>

Hi!  
I trying my first watcher, and being a newbie I have trouble with the basics.  
I'd like to filter out the events for the last 10 minutes, but somewhere I have made (I suppose) a simple syntax error. Anyone can point me in the right direction?

```auto
       PUT _watcher/watch/log_critical_watch
    {
      "trigger" : {
        "schedule" : { "interval" : "60s" } 
      },
      "input" : {
        "search" : {
          "request" : {
            "indices" : ["business"],
            "body" : {
              "query" : {
                 "match" : { "value.ACTIVITY_DETECTION_STATUS.keyword": "Major" },
                  "filter":{ "range": { "value.MEASUREMENT_START_TIMESTAMP":{"gte": "now-10m/m","lte":"now/m" }}}
              }
              }
            }
          }
        }
      }

```

---

<div class="post-metadata">

**Author:** ![Fredrik\_Cronholm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fredrik_cronholm/32/74091_2.png) [@Fredrik\_Cronholm](https://discuss.elastic.co/u/Fredrik_Cronholm)\
**Post date:** [August 18, 2020, 1:48pm UTC](https://discuss.elastic.co/t/simple-watcher-syntax-help/245426/2 "2020-08-18T13:48:07Z")

</div>

Fixed it 🙂

```auto
PUT _watcher/watch/log_error_watch
{
  "trigger" : {
    "schedule" : { "interval" : "60s" } 
  },
  "input" : {
    "search" : {
      "request" : {
        "indices" : ["business"],
        "body" : {
          "query" : {
               "bool": { 
      "must": [
        { "match": { "value.ACTIVITY_DETECTION_STATUS.keyword": "Major"}}
        ],
      "filter": [ 
        { "range": { "value.MEASUREMENT_START_TIMESTAMP":{"gte": "now-10m/m","lte":"now/m" }}}
      ]
    }
          }
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 15, 2020, 1:48pm UTC](https://discuss.elastic.co/t/simple-watcher-syntax-help/245426/3 "2020-09-15T13:48:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
