# Watcher 7.8 Do I have to modify the range of my query to match the timezone?

**URL:** <https://discuss.elastic.co/t/watcher-7-8-do-i-have-to-modify-the-range-of-my-query-to-match-the-timezone/274103>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [May 26, 2021, 5:50pm UTC](https://discuss.elastic.co/t/watcher-7-8-do-i-have-to-modify-the-range-of-my-query-to-match-the-timezone/274103 "2021-05-26T17:50:17Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ElasticLiver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticliver/32/64869_2.png) [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Post date:** [May 26, 2021, 5:50pm UTC](https://discuss.elastic.co/t/watcher-7-8-do-i-have-to-modify-the-range-of-my-query-to-match-the-timezone/274103/1 "2021-05-26T17:50:17Z")

</div>

Hi, I have create an alert whenever match a field, and Im having problems to make it work. the query works well in devs tools when I query for now-7d, but in the watch is never executed. this is my range

```auto
              "filter": [
                {
                  "range": {
                    "@timestamp": {
                      "gte": "now-60s",
                      "lte": "now"
                    }
                  }
                }

```

I was wondering if I have to modify the range to match my timezone, that is UTC -5?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 26, 2021, 10:52pm UTC](https://discuss.elastic.co/t/watcher-7-8-do-i-have-to-modify-the-range-of-my-query-to-match-the-timezone/274103/2 "2021-05-26T22:52:11Z")

</div>

Elasticsearch works on UTC, so you will likely need to adjust for that, yes.

---

<div class="post-metadata">

**Author:** ![ElasticLiver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticliver/32/64869_2.png) [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Post date:** [May 26, 2021, 11:12pm UTC](https://discuss.elastic.co/t/watcher-7-8-do-i-have-to-modify-the-range-of-my-query-to-match-the-timezone/274103/3 "2021-05-26T23:12:55Z")

</div>

Mmmm seems that its not necessary, I have another alert identical to the one that has problems, with the same range, the only difference that match another phrase, and seems to work, I got the email , and the index has a document that match....

 ![Sin título](https://us1.discourse-cdn.com/elastic/original/3X/9/5/957a62c36e025c6fb7012345007cdc06facc9995.png)  
Now Im confused 🤔

this is the watcher:

```auto
{
  "trigger": {
    "schedule": {
      "interval": "60s"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "metrics-syslog-*"
        ],
        "rest_total_hits_as_int": true,
        "body": {
          "query": {
            "bool": {
              "must": [
                {
                  "match_phrase": {
                    "syslog_event.keyword": "HSRP-5-STATECHANGE"
                  }
                }
              ],
              "filter": [
                {
                  "range": {
                    "@timestamp": {
                      "gte": "now-60s",
                      "lte": "now"
                    }
                  }
                },
                {
                  "terms": {
                    "bcp_family.keyword": [
                      "Router ASR"
                    ]
                  }
                }
              ]
            }
          },
          "size": 5
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "gt": 0
      }
    }
  },
  "actions": {
    "send_email": {
      "throttle_period_in_millis": 60000,
      "transform": {
        "script": {
          "source": """
        DateTimeFormatter dtf = DateTimeFormatter.ofPattern(
        "yyyy/MM/dd HH:mm:ss");
return ['date': Instant.ofEpochMilli(OffsetDateTime.parse(ctx.payload.hits.hits.0._source['@timestamp']).toInstant().toEpochMilli()).atZone(ZoneId.of("America/Lima")).format(dtf), 'nodo': ctx.payload.hits.hits.0._source.node_name, 'message' : ctx.payload.hits.hits.0._source.syslog_message ]""",
          "lang": "painless"
        }
      },
      "email": {
        "profile": "standard",
        "from": "net@mon.com",
        "to": [
          "my@mail"
        ],
        "subject": "%HSRP-5-STATECHANGE - {{ctx.payload.nodo}} - Alerta de Evento-Elastic",
        "body": {
          "html": """<html>
          ....
            </html>
            """
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [May 31, 2021, 7:21am UTC](https://discuss.elastic.co/t/watcher-7-8-do-i-have-to-modify-the-range-of-my-query-to-match-the-timezone/274103/4 "2021-05-31T07:21:15Z")

</div>

What happens internally here is, that your date with a timezone will be converted to UTC and then stored in Elasticsearch. If you are searching for `now-5m` it still has happened five minutes ago and this will be catered for. As long as you ensure the timezone is set when indexing (via the date or the mapping), all should be good.

Hope that helps to understand what happens here!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 28, 2021, 7:21am UTC](https://discuss.elastic.co/t/watcher-7-8-do-i-have-to-modify-the-range-of-my-query-to-match-the-timezone/274103/5 "2021-06-28T07:21:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
