# Watcher alerts 7.5 interval and bucket span

**URL:** <https://discuss.elastic.co/t/watcher-alerts-7-5-interval-and-bucket-span/272319>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [May 6, 2021, 4:02pm UTC](https://discuss.elastic.co/t/watcher-alerts-7-5-interval-and-bucket-span/272319 "2021-05-06T16:02:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ElasticLiver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticliver/32/64869_2.png) [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Post date:** [May 6, 2021, 4:02pm UTC](https://discuss.elastic.co/t/watcher-alerts-7-5-interval-and-bucket-span/272319/1 "2021-05-06T16:02:11Z")

</div>

Why if its recomended that the interval of a watch has to be [equal to twice the defined `bucket_span` for the job.](https://www.elastic.co/es/blog/alerting-on-machine-learning-jobs-in-elasticsearch-v55) , when I create an anomaly detection alert in the kibana GUI, the interval is set to aprox. one minute?

my bucket span is 15 minutes, so in the creation of the watch, the bucket span is not taken in to consideration automatically?

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [May 6, 2021, 6:23pm UTC](https://discuss.elastic.co/t/watcher-alerts-7-5-interval-and-bucket-span/272319/2 "2021-05-06T18:23:10Z")

</div>

It's because the `timestamp` of the documents in `.ml-anomalies-*` are written with a value that is the leading edge of the `bucket_span`. So results from 12:00-12:15 will be written with a `timestamp` of 12:00 - but they won't be "finalized" until some short amount of time after 12:15. Well, actually, 12:15+`query_delay`+whatever time it takes the analytics to run. So, using a look-back interval of `2* bucket_span` will ensure nothing gets "missed".

In the Kibana GUI, the one minute setting is the "frequency" of the check for an alert condition, not the look-back window (which is indeed set to `2* bucket_span` (although some optimizations are being made. See: [https://github.com/elastic/kibana/pull/97370](https://github.com/elastic/kibana/pull/97370))

---

<div class="post-metadata">

**Author:** ![ElasticLiver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticliver/32/64869_2.png) [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Post date:** [May 6, 2021, 7:52pm UTC](https://discuss.elastic.co/t/watcher-alerts-7-5-interval-and-bucket-span/272319/3 "2021-05-06T19:52:56Z")

</div>

Hi Rich, sorry english is not my native language, so this value "interval" must be 2\*bucket\_span?

![image](https://us1.discourse-cdn.com/elastic/original/3X/5/3/53c8be1a782db3367b092c0286b2473fbc4d351c.png)

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [May 6, 2021, 9:12pm UTC](https://discuss.elastic.co/t/watcher-alerts-7-5-interval-and-bucket-span/272319/4 "2021-05-06T21:12:54Z")

</div>

No worries about language!

No, the `interval` of the watch is NOT what I'm talking about. The `interval` is how often the watch is executed.

The "lookback" period of the watch is in the `range` of the query itself as in:

```auto
                {
                  "range": {
                    "timestamp": {
                      "gte": "now-30m"
                    }
                  }
                },

```

This value (in this case, the `30m`) should be the value that is 2\*bucket\_span.

If the `interval` value is short (like `1m`), the watch will run the query very frequently. This is good because it gives the fastest time to notification, but then you might have to deal with duplicate alerts since the information returned from the query is not changing as fast as you're checking it.

Hope that helps

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 3, 2021, 9:13pm UTC](https://discuss.elastic.co/t/watcher-alerts-7-5-interval-and-bucket-span/272319/5 "2021-06-03T21:13:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
