# Watcher alert not functioning with Time range

**URL:** <https://discuss.elastic.co/t/watcher-alert-not-functioning-with-time-range/161737>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [December 20, 2018, 5:40pm UTC](https://discuss.elastic.co/t/watcher-alert-not-functioning-with-time-range/161737 "2018-12-20T17:40:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![fjm](https://avatars.discourse-cdn.com/v4/letter/f/6f9a4e/32.png) [@fjm](https://discuss.elastic.co/u/fjm)\
**Post date:** [December 20, 2018, 5:40pm UTC](https://discuss.elastic.co/t/watcher-alert-not-functioning-with-time-range/161737/1 "2018-12-20T17:40:27Z")

</div>

Hi there,

I am looking to create an advanced watch where I am alerted when any docker container stops running on any VMs in a network. While I receive results back and during testing I am able to have the alert fire off correctly, the results that are appearing date too far back. Therefore I added a time range but for some reason am getting an error when doing so (below). Here is the code for the watcher alert:

```
{
  "trigger": {
    "schedule": {
      "interval": "15s"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "metricbeat*"
        ],
        "types": [],
        "body": {
          "size": 1,
          "query": {
            "bool": {
              "filter": {
                "range": {
                  "@timestamp": {
                    "gte": "now-16h",
                    "lt": "now"
                  }
                },
                "match": {
                  "docker.info.containers.stopped": "1"
                }
              }
            }
          }
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.hits.0._source.host.name": {
        "gte": "hgnode-*"
      }
    }
  },
  "actions": {
    "email_admin": {
      "email": {
        "profile": "standard",
        "to": [
          "'john <johnsmith@gmail.com>'"
        ],
        "subject": "{{ctx.payload.hits.hits.0._source.host.name}} is down",
        "body": {
          "text": "Go fix it!!!"
        }
      }
    },
    "my-logging-action": {
      "logging": {
        "level": "info",
        "text": "There are {{ctx.payload.hits.hits.0._source.host.name}} documents in your index. Threshold is 10."
      }
    }
  }
}

```

Part of the output when simulating the watch, with the range as configured above is the following:

```
"input": {
  "type": "search",
  "status": "failure",
  "error": {
    "root_cause": [
      {
        "type": "parsing_exception",
        "reason": "[range] malformed query, expected [END_OBJECT] but found [FIELD_NAME]",
        "line": 1,
        "col": 89
      }
    ],
    "type": "parsing_exception",
    "reason": "[range] malformed query, expected [END_OBJECT] but found [FIELD_NAME]",
    "line": 1,
    "col": 89
  },

```

Could someone please help me find what is wrong with the code that I have?

Thanks in advance!  
Javier

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [December 20, 2018, 8:31pm UTC](https://discuss.elastic.co/t/watcher-alert-not-functioning-with-time-range/161737/2 "2018-12-20T20:31:24Z")

</div>

Looks like you need to put your multiple `bool` conditions in an array:

```auto
{
    "filter": [{
        "range": {
            "@timestamp": {
                "gte": "now-16h",
                "lt": "now"
            }
        }
    }, {
        "match": {
            "docker.info.containers.stopped": "1"
        }
    }]
}

```

---

<div class="post-metadata">

**Author:** ![fjm](https://avatars.discourse-cdn.com/v4/letter/f/6f9a4e/32.png) [@fjm](https://discuss.elastic.co/u/fjm)\
**Post date:** [December 21, 2018, 2:06pm UTC](https://discuss.elastic.co/t/watcher-alert-not-functioning-with-time-range/161737/3 "2018-12-21T14:06:32Z")

</div>

Hi Lukas!

This solved the issue. Thank you so much for the help!

Regards,  
Javier

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 18, 2019, 2:06pm UTC](https://discuss.elastic.co/t/watcher-alert-not-functioning-with-time-range/161737/4 "2019-01-18T14:06:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
