# Tunning Watcher

**URL:** <https://discuss.elastic.co/t/tunning-watcher/47958>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [April 20, 2016, 7:47pm UTC](https://discuss.elastic.co/t/tunning-watcher/47958 "2016-04-20T19:47:23Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![mario\_carmona](https://avatars.discourse-cdn.com/v4/letter/m/e9c0ed/32.png) [@mario\_carmona](https://discuss.elastic.co/u/mario_carmona)\
**Post date:** [April 20, 2016, 7:47pm UTC](https://discuss.elastic.co/t/tunning-watcher/47958/1 "2016-04-20T19:47:23Z")

</div>

I have created the below watcher that looks in my proxy index, it currently works however I would like to tune it.  
Would like to only send events to the SIEM that exceed 20 hits for "deviceAction:TCP\_AUTH\_REDIRECT" from a single source IP within a specified time, lets say 10 minutes. I am new to creating watchers, any ideas on how I can make this happen or if this is even possible?

{  
"trigger": {  
"schedule": {  
"interval": "1h"  
}   
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": "xxxxxx",  
"body": {  
"query": {  
"filtered": {  
"query": {  
"query\_string": {  
"query": "deviceAction:TCP\_AUTH\_REDIRECT"  
}  
}  
}  
},  
"filter":{  
"bool": {  
"must": [  
{  
"range": {  
"@timestamp": {  
"gte": "now-1h"  
}  
}  
}  
],  
"must\_not": []  
}  
}  
}  
}  
}  
},  
"condition": {  
"compare": { "ctx.payload.hits.total":{  
"gt": 0  
}  
} },  
"actions": {  
"cefpost": {  
"webhook": {  
"scheme": "http",  
"host": "yyyyyy",  
"port": zzzzz,  
"method": "post",  
"path": "/WatcherToSyslogWebservice/post",  
"params": {  
"watch\_id": "{{ctx.watch\_id}}",  
"priority": "5"  
},  
"headers": {  
"Content-Type": "application/json"  
},  
"body": "{{ctx.payload.hits}}"  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 21, 2016, 4:02pm UTC](https://discuss.elastic.co/t/tunning-watcher/47958/2 "2016-04-21T16:02:45Z")

</div>

Hey,

so the main question here is, how to create a query, that reflects what you need. From what I understand you need to search for all documents

- that have a timestamp from `now-10m`
- that are `deviceAction:TCP_AUTH_REDIRECT`

for those documents you need to aggregate on their sourceIp. And when you find aggregates, that have a count higher than 20 hits, those need to be returned. This works with the `min_doc_count` parameter of the `terms` aggregation. Also make sure you read the terms agg docs, especially the [approximation part](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#search-aggregations-bucket-terms-aggregation-approximate-counts)

Based on that info you can then run your watch.

Hope this helps.

--Alex

---

<div class="post-metadata">

**Author:** ![mario\_carmona](https://avatars.discourse-cdn.com/v4/letter/m/e9c0ed/32.png) [@mario\_carmona](https://discuss.elastic.co/u/mario_carmona)\
**Post date:** [June 9, 2016, 8:11pm UTC](https://discuss.elastic.co/t/tunning-watcher/47958/3 "2016-06-09T20:11:24Z")

</div>

So trying again to get this watch to work. My ultimate goal now is to look through all source IP addresses, gather a list of all srcIPs for a period of time (let's say 15 minutes) that have more than X (maybe 150) number of "TCP\_AUTH\_REDIRECT" in the proxy logs "deviceAction" field.

Now, look through that list of srcIPs and if they have at least one successful GET (successful means you'll see a "TCP\_NC\_MISS" or "TUNNELED" in the "deviceAction" field then exclude those IPs. Those left are sources that I want to review/display.

Here is my watcher:

{  
"trigger": {  
"schedule": {  
"interval": "15m"  
}   
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": "myindex",  
"body": {  
"size": 0,  
"query": {  
"filtered": {  
"query": {  
"query\_string": {  
"query": "deviceAction:TCP\_AUTH\_REDIRECT"  
}  
},  
"filter":{  
"bool": {  
"must": [  
{  
"range": {  
"@timestamp": {  
"gte": "now-15m"  
}  
}  
}  
],  
"must\_not": [  
{"term":{"requestUrlHost":"[api.bing.com](http://api.bing.com)"}}  
],  
"filter": {  
"range": {  
"@timestamp": {  
"from": "{{ctx.trigger.scheduled\_time}}||-15m",  
"to": "{{ctx.trigger.triggered\_time}}"  
}  
}  
}  
}  
}  
}  
},  
"aggs": {  
"aggrs": {  
"terms": {  
"field": "sourceAddress",  
"min\_doc\_count": 150  
}  
}  
}

```
		}
	}
		}
		},

```

"condition": {  
"script": "ctx.payload.hits.total \> 1"  
},

"actions": {  
"cefpost": {  
"webhook": {  
"scheme": "http",  
"host": "xxxxx",  
"port": 8080,  
"method": "post",  
"path": "/WatcherToSyslogWebservice/post",  
"params": {  
"watch\_id": "{{ctx.watch\_id}}",  
"priority": "5"  
},  
"headers": {  
"Content-Type": "application/json"  
},  
"body": ""  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 10, 2016, 7:14am UTC](https://discuss.elastic.co/t/tunning-watcher/47958/4 "2016-06-10T07:14:53Z")

</div>

Hey,

First, can you use code blocks for better readability, see this [markdown documentation](http://commonmark.org/help/) for help.

And second and as already written in my last post: Is the query actually returning the data you need? If so, where is the current issue? If not, lets focus on that first.

--Alex

---

<div class="post-metadata">

**Author:** ![mario\_carmona](https://avatars.discourse-cdn.com/v4/letter/m/e9c0ed/32.png) [@mario\_carmona](https://discuss.elastic.co/u/mario_carmona)\
**Post date:** [June 10, 2016, 7:29pm UTC](https://discuss.elastic.co/t/tunning-watcher/47958/5 "2016-06-10T19:29:29Z")

</div>

That is what I need help with, I think I need to build a multiple query but can't figure out how to do it....

Watcher should look through all my data, within a specified amount of time, say 15m, if it sees in the field deviceAction multiple TCP\_AUTH\_REDIRECT, lets now say 10 consecutive and at no point does it see in the deviceAction field TCP\_NC\_MISS or TUNNELED then I want it to be reported to me.

Currently my the query only reports sources that have more than 150 TCP\_AUTH\_REDIRECT in the deviceAction field within a 15 min window. Need to figure out a way to not report those that have a TCP\_NC\_MISS or TUNNELED within the same specified time window, they could still have 150 TCP\_AUTH\_REDIRECTS but won't report because TCP\_NC\_MISS or TUNNELED was seen.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 13, 2016, 7:11am UTC](https://discuss.elastic.co/t/tunning-watcher/47958/6 "2016-06-13T07:11:34Z")

</div>

Hey,

you might be better off asking this in the Elasticsearch forum, as there are much more people to help you. Keep in mind, that Elasticsearch searches on a per document base, when asking (and maybe come up with a concrete example, like some example documents). You might change your indexing strategy/document modeling strategy to support this. You might be able to use a terms aggregation to get all the deviceAction fields during that time grouped per IP to actually exclude a certain ip/set of documents that have been indexed.

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:45pm UTC](https://discuss.elastic.co/t/tunning-watcher/47958/7 "2017-07-06T13:45:03Z")

</div>


