# Timestamp range in watcher doesn't work

**URL:** <https://discuss.elastic.co/t/timestamp-range-in-watcher-doesnt-work/114436>\
**Category:** Elasticsearch\
**Created:** [January 8, 2018, 12:01am UTC](https://discuss.elastic.co/t/timestamp-range-in-watcher-doesnt-work/114436 "2018-01-08T00:01:58Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![saradac](https://avatars.discourse-cdn.com/v4/letter/s/3be4f8/32.png) [@saradac](https://discuss.elastic.co/u/saradac)\
**Post date:** [January 8, 2018, 12:01am UTC](https://discuss.elastic.co/t/timestamp-range-in-watcher-doesnt-work/114436/1 "2018-01-08T00:01:58Z")

</div>

Hello,

I added the watcher in Kibana manually. I am not sure where to add mappings to enable \_timestamp.

Below is my watcher: Which return's nothing. All I added is  
"range": {  
"\_timestamp": {  
"gt": "now-5m"  
}  
}

> {  
> "trigger": {  
> "schedule": {  
> "interval": "5m"  
> }  
> },  
> "input": {  
> "search": {  
> "request": {  
> "search\_type": "query\_then\_fetch",  
> "indices": ,  
> "types": ,  
> "body": {  
> "size": 5,  
> "query": {  
> "bool": {  
> "must": [  
> {  
> "range": {  
> "\_timestamp": {  
> "gt": "now-5m"  
> }  
> }  
> },  
> {  
> "terms": {  
> "appName.keyword": [  
> "fuse-file-management-general"  
> ]  
> }  
> },  
> {  
> "terms": {  
> "level.keyword": [  
> "ERROR",  
> "INFO"  
> ]  
> }  
> }  
> ]  
> }  
> }  
> }  
> }  
> }  
> },  
> "condition": {  
> "compare": {  
> "ctx.payload.hits.total": {  
> "gte": 10  
> }  
> }  
> },  
> "actions": {  
> "email\_admin": {  
> "email": {  
> "profile": "standard",  
> "attachments": {  
> "log.json": {  
> "data": {  
> "format": "json"  
> }  
> }  
> },  
> "priority": "high",  
> "to": [  
> "[saradac@x.com](mailto:saradac@x.com)"  
> ],  
> "subject": "{{ctx.payload.hits.hits.0.\_source.level}} | {{ctx.payload.hits.hits.0.\_source.hostname}}",  
> "body": {  
> "html": " **ELK Monitoring**   
> Issue with Application : {{ctx.payload.hits.hits.0.\_source.appName}}   
> Error Message :   
> {{ctx.payload.hits.hits.0.\_source.json\_message}}"  
> }  
> }  
> }  
> }  
> }

---

<div class="post-metadata">

**Author:** ![jpcarey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpcarey/32/46668_2.png) [@jpcarey](https://discuss.elastic.co/u/jpcarey)\
**Post date:** [January 8, 2018, 2:24am UTC](https://discuss.elastic.co/t/timestamp-range-in-watcher-doesnt-work/114436/2 "2018-01-08T02:24:50Z")

</div>

What version are you using? For the target indices, did you check that \_timestamp is a valid date field (`GET /indexname/_mapping/fields/_timestamp`)?

\_timestamp was a 2.x deprecated mapping feature that would make elasticsearch insert a timestamp when the document was created or updated. It was removed in 5.x. Where you possibly thinking of @timestamp, the common field logstash and beats use?

I’d also recommend you set the indices the watch will be searching on.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 5, 2018, 2:25am UTC](https://discuss.elastic.co/t/timestamp-range-in-watcher-doesnt-work/114436/3 "2018-02-05T02:25:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
