# Trigger an alert on a condition

**URL:** <https://discuss.elastic.co/t/trigger-an-alert-on-a-condition/217103>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [January 30, 2020, 4:54am UTC](https://discuss.elastic.co/t/trigger-an-alert-on-a-condition/217103 "2020-01-30T04:54:54Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![shappy123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shappy123/32/51133_2.png) [@shappy123](https://discuss.elastic.co/u/shappy123)\
**Post date:** [January 30, 2020, 4:54am UTC](https://discuss.elastic.co/t/trigger-an-alert-on-a-condition/217103/1 "2020-01-30T04:54:54Z")

</div>

Hi

I want to trigger an email alert based on this condition :

that if in the log this --- "," **RequestPath":"/documentService/v1/Document/uploadLink** -----

doesnt appear in the logs for next 12 hours so should send an email alert.

Can anyone please assist, as i am new to JSON so would be great that if someone can guide me what exactly to write as well.

Cheers

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [January 30, 2020, 2:43pm UTC](https://discuss.elastic.co/t/trigger-an-alert-on-a-condition/217103/2 "2020-01-30T14:43:17Z")

</div>

So, the first thing in order to get a watch up and running is come up with a query that will answer your question - even before you start writing a watch.

Once you got that, you wrap that watch into a search input and then come up with the watch condition and an logger action - once that works, create an email action.

it's important to go step by step.

Have you managed to write a decent query already? If not, please explain in more detail what the issue is, as otherwise it will be hard to help.

---

<div class="post-metadata">

**Author:** ![shappy123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shappy123/32/51133_2.png) [@shappy123](https://discuss.elastic.co/u/shappy123)\
**Post date:** [January 31, 2020, 4:46am UTC](https://discuss.elastic.co/t/trigger-an-alert-on-a-condition/217103/3 "2020-01-31T04:46:04Z")

</div>

i tried this as per following : (fields.RequestPath = /documentService/v1/Document/uploadLink ) in Kibana logs for more than 12 hours?

means if we didnt receive the request path (/documentService/v1/Document/uploadLink) or the "uploadlink" word in our logs in next 12 hours so then fire an alert.

i tried this but dont think is the right one, can you please have a look...

{  
"trigger": {  
"schedule": {  
"interval": "12h"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"logs"  
],  
"rest\_total\_hits\_as\_int": true,  
"body": {  
"query": {  
"bool": {  
"must": [  
{  
"match": {  
"RequestPath": "/documentService/v1/Document/uploadLink"  
}  
},  
{  
"range": {  
"\_timestamp": {  
"gte": "now-12h",  
"lte": "now"  
}  
}  
}  
]  
}  
}  
}  
}  
}  
},  
"condition": {  
"always": {}  
},  
"actions": {  
"email\_users": {  
"email": {  
"profile": "standard",  
"to": [  
"'bravo alpha [abc@abc.com](mailto:abc@abc.com)'"  
],  
"subject": " executed",  
"body": {  
"html": " test123"  
}  
}  
}  
}  
}

thnx

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [January 31, 2020, 9:06am UTC](https://discuss.elastic.co/t/trigger-an-alert-on-a-condition/217103/4 "2020-01-31T09:06:10Z")

</div>

why do you think this query is not the right one? Is it returning the results that you expect or not? If not, what is wrong with this query?

---

<div class="post-metadata">

**Author:** ![shappy123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shappy123/32/51133_2.png) [@shappy123](https://discuss.elastic.co/u/shappy123)\
**Post date:** [January 31, 2020, 10:10pm UTC](https://discuss.elastic.co/t/trigger-an-alert-on-a-condition/217103/5 "2020-01-31T22:10:36Z")

</div>

Hi,

The problem with this query is it fire an alert for example if the upload link "word" is either present or not in the logs, it will just fire.

The condition I am trying to apply is for example in the query of next 12 hours if the "word" upload link doesn't appear in the logs it should fire an event but in my script either the upload link is presnet or not present in the logs it will still fire an alert.

So my goal is to find a condition that if this word doesn't appear in the logs for x number of hours in the logs just shoot an alert.

Does it make sense?

Thanks

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 3, 2020, 3:07pm UTC](https://discuss.elastic.co/t/trigger-an-alert-on-a-condition/217103/6 "2020-02-03T15:07:52Z")

</div>

try the `must_not` part of a `bool` query.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 2, 2020, 3:10pm UTC](https://discuss.elastic.co/t/trigger-an-alert-on-a-condition/217103/7 "2020-03-02T15:10:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
