# Watcher alerts not triggered

**URL:** <https://discuss.elastic.co/t/watcher-alerts-not-triggered/137220>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [June 25, 2018, 9:14am UTC](https://discuss.elastic.co/t/watcher-alerts-not-triggered/137220 "2018-06-25T09:14:34Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![VietCong](https://avatars.discourse-cdn.com/v4/letter/v/e47774/32.png) [@VietCong](https://discuss.elastic.co/u/VietCong)\
**Post date:** [June 25, 2018, 9:14am UTC](https://discuss.elastic.co/t/watcher-alerts-not-triggered/137220/1 "2018-06-25T09:14:34Z")

</div>

Hi,

I have my basic watch to alert of log on failures. When I stimulated the watch it worked and generated a Slack message but the watch never triggered even though the conditions are met. Please find my alert below.

```
{
  "trigger": {
    "schedule": {
      "interval": "60m"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "auth.log"
        ],
        "types": [],
        "body": {
          "query": {
            "bool": {
              "must": {
                "match": {
                  "message": "failure"
                }
              },
              "filter": {
                "range": {
                  "@timestamp": {
                    "from": "now-5m",
                    "to": "now"
                  }
                }
              }
            }
          }
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "gte": 3
      }
    }
  },
  "actions": {
    "notify-slack": {
      "slack": {
        "message": {
          "to": [
            "#slack-alert-from-siem"
          ],
          "text": "there is multiple logon failures within the last 3 mins"
        }
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 25, 2018, 10:02am UTC](https://discuss.elastic.co/t/watcher-alerts-not-triggered/137220/2 "2018-06-25T10:02:21Z")

</div>

Hey,

please format your messages properly using markdown. Just pasting JSON makes it super hard to read.

Can you include the watch history for this watch? The query below allows you to query the last watch exeuctions. Should be sufficient to only the most recent one for now by using `"size": 1` in the query as well.

```auto
GET .watcher-history-*/_search
{
  "query": {
    "bool": {
      "filter": [
        {
          "term": {
            "watch_id": "my_watch"
          }
        }
      ]
    }
  },
  "sort": [
    {
      "trigger_event.triggered_time": {
        "order": "desc"
      }
    }
  ]
}

```

---

<div class="post-metadata">

**Author:** ![VietCong](https://avatars.discourse-cdn.com/v4/letter/v/e47774/32.png) [@VietCong](https://discuss.elastic.co/u/VietCong)\
**Post date:** [June 27, 2018, 11:50pm UTC](https://discuss.elastic.co/t/watcher-alerts-not-triggered/137220/3 "2018-06-27T23:50:01Z")

</div>

Hi,

My apologies for the messy code. I edited my initial question. Please find the picture below for the watch history. It is the last very bottom watch and hasn't triggered at all.

 ![Screenshot%20from%202018-06-27%2018-48-47](https://us1.discourse-cdn.com/elastic/original/3X/7/5/75dfd368a4096c2950996527ea495af5c0c72c1f.png)

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 29, 2018, 8:42am UTC](https://discuss.elastic.co/t/watcher-alerts-not-triggered/137220/4 "2018-06-29T08:42:13Z")

</div>

Hey,

that screenshot does not really help, please include the output from the query that I asked for. There is one watch marked as disabled - I have n idea however if that is the watch you are talking about. Did you maybe deactivate it? You can either activate it, or just delete it and put it again and see if that makes the watch trigger.

Hope this helps.

--Alex

---

<div class="post-metadata">

**Author:** ![VietCong](https://avatars.discourse-cdn.com/v4/letter/v/e47774/32.png) [@VietCong](https://discuss.elastic.co/u/VietCong)\
**Post date:** [June 29, 2018, 9:07am UTC](https://discuss.elastic.co/t/watcher-alerts-not-triggered/137220/5 "2018-06-29T09:07:23Z")

</div>

Hi Alex,

The watch I am talking about is the very last one.

---

<div class="post-metadata">

**Author:** ![VietCong](https://avatars.discourse-cdn.com/v4/letter/v/e47774/32.png) [@VietCong](https://discuss.elastic.co/u/VietCong)\
**Post date:** [July 3, 2018, 4:17am UTC](https://discuss.elastic.co/t/watcher-alerts-not-triggered/137220/6 "2018-07-03T04:17:10Z")

</div>

I found out it is the problem with the logic. I should have had my "Interval" : "1m" instead of "60m" --\> interval refers to how often I want my watch to run

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 31, 2018, 4:17am UTC](https://discuss.elastic.co/t/watcher-alerts-not-triggered/137220/7 "2018-07-31T04:17:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
