# Stop Watcher after first alert

**URL:** <https://discuss.elastic.co/t/stop-watcher-after-first-alert/142204>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [July 30, 2018, 3:09pm UTC](https://discuss.elastic.co/t/stop-watcher-after-first-alert/142204 "2018-07-30T15:09:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![TheNmaptomyHeartBeat](https://avatars.discourse-cdn.com/v4/letter/t/47e85d/32.png) [@TheNmaptomyHeartBeat](https://discuss.elastic.co/u/TheNmaptomyHeartBeat)\
**Post date:** [July 30, 2018, 3:09pm UTC](https://discuss.elastic.co/t/stop-watcher-after-first-alert/142204/1 "2018-07-30T15:09:55Z")

</div>

Is there a way to stop watcher sending alerts after the first one?

so it only send alerts for new errors.

I tried adding a second conditions so its not only just checking for a payload grater than 1 but for ctx.execution\_time \< now-15s.

But the watcher doesn't like it when I try to add two conditions. Maybe I'm doing it wrong do I need to add a Boolean?

Time throttling does not work in this situation. Below is my watcher.

```auto
{
  "trigger": {
    "schedule": {
      "interval": "10s"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "filebeat-*"
        ],
        "types": [],
        "body": {
          "query": {
            "bool": {
              "must": [
                {
                  "range": {
                    "@timestamp": {
                      "gte": "now-15s"
                    }
                  }
                },
                {
                  "match": {
                    "source": "/foo/bar"
                  }
                },
                {
                  "match": {
                    "foos": "foo"
                  }
                },
                {
                  "match": {
                    "foo": "foo"
                  }
                },
                {
                  "match": {
                    "foo": "foo"
                  }
                }
              ]
            }
          }
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "gt": 1
      }
    }
  },
  "actions": {
    "notify-slack": {
      "throttle_period_in_millis": 2000,
      "wmail": {
        "message": {
          "to": [
            "foo"
          ],
          "text": "foofoofoofoofoofoofoofoofoofoovfoofoofoofoofoofoo"
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 1, 2018, 12:10pm UTC](https://discuss.elastic.co/t/stop-watcher-after-first-alert/142204/2 "2018-08-01T12:10:51Z")

</div>

you can have more than one condition when using a script condition and writing a painless script. Another approach would be to query not only the last 15 seconds, but also the 15 second window before that and if that one was already true, you could decide not to execute this time. Note that this may miss an execution though.

---

<div class="post-metadata">

**Author:** ![TheNmaptomyHeartBeat](https://avatars.discourse-cdn.com/v4/letter/t/47e85d/32.png) [@TheNmaptomyHeartBeat](https://discuss.elastic.co/u/TheNmaptomyHeartBeat)\
**Post date:** [August 3, 2018, 3:27pm UTC](https://discuss.elastic.co/t/stop-watcher-after-first-alert/142204/4 "2018-08-03T15:27:33Z")

</div>

I ended up useing the example from [here](https://discuss.elastic.co/t/how-do-i-setup-watcher-to-only-alert-on-new-messages/27330/2?u=thenmaptomyheartbeat). I filtered anything more than 25s and while setting the interval of the watcher to 20s.

It does only send one notification for that record before it leaves that 5 second window.

I have noticed that this is isn't perfect. It does miss a couple of records but for the most part it works to a satisfactory level.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 31, 2018, 3:27pm UTC](https://discuss.elastic.co/t/stop-watcher-after-first-alert/142204/5 "2018-08-31T15:27:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
