# Watcher auto acknowledgment, throttle\_period reset

**URL:** <https://discuss.elastic.co/t/watcher-auto-acknowledgment-throttle-period-reset/107915>\
**Category:** Elasticsearch\
**Created:** [November 16, 2017, 11:25am UTC](https://discuss.elastic.co/t/watcher-auto-acknowledgment-throttle-period-reset/107915 "2017-11-16T11:25:58Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sergey\_Urushkin](https://avatars.discourse-cdn.com/v4/letter/s/8baadc/32.png) [@Sergey\_Urushkin](https://discuss.elastic.co/u/Sergey_Urushkin)\
**Post date:** [November 16, 2017, 11:25am UTC](https://discuss.elastic.co/t/watcher-auto-acknowledgment-throttle-period-reset/107915/1 "2017-11-16T11:25:59Z")

</div>

This has been discussed earlier. In my case I need oneshot messages for PROBLEM (hits \< N) and OK (hist =\>N).  
Throttling with large time period will not help in this situation, since condition=false doesn't reset throttle\_period (not for actions [https://github.com/elastic/elasticsearch/issues/27358](https://github.com/elastic/elasticsearch/issues/27358) , not for watcher ) . So, throttle-reset or auto-ack options would solve this problem.  
For now I have to create 1 watcher with 3 actions: OK action, PROBLEM action, ACK action (webhook to elasticsearch itself). Looks like this:

```auto
 "condition": {
    "always": {}
  },
  "actions": {
    "notify-slack-problem": {
      "condition": {
        "compare": {
          "ctx.payload.hits.total": {
            "lte": 150
          }
        }
      },
      "slack": { ... }
      }
    },
    "notify-slack-ok": {
      "condition": {
        "compare": {
          "ctx.payload.hits.total": {
            "gt": 150
          }
        }
      },
      "slack": { ... }
    },
    "ack-slack": {
      "webhook": {
        "scheme": "http",
        "host": "localhost",
        "port": 9200,
        "method": "post",
        "path": "/_xpack/watcher/watch/{{ctx.watch_id}}/_ack/notify-slack-problem,notify-slack-ok",
        "params": {},
        "headers": {}
      }
    }
  }

```

This haven't been tested much, could there be a race problem (notify-slack-\* get completed after ack-slack)? Also, this will not work with security-enabled installation (in that case second watcher could be created, anyway there will be plaintext credentials in watcher)... May be there is a better solution for all these?

---

<div class="post-metadata">

**Author:** ![Sergey\_Urushkin](https://avatars.discourse-cdn.com/v4/letter/s/8baadc/32.png) [@Sergey\_Urushkin](https://discuss.elastic.co/u/Sergey_Urushkin)\
**Post date:** [November 20, 2017, 7:09am UTC](https://discuss.elastic.co/t/watcher-auto-acknowledgment-throttle-period-reset/107915/2 "2017-11-20T07:09:46Z")

</div>

It seems that 1 watcher doesn't work as I expect (action's condition doesn't reset acked state). But 2 watchers with opposite conditions seems to work (with limitations from previous message):

```auto
"condition": {
   "compare": {
     "ctx.payload.hits.total": {
       "gt": 150
     }
   }
 },
 "actions": {
   "notify-slack": { ...
   },
   "ack-slack": {
     "webhook": {
       "scheme": "http",
       "host": "localhost",
       "port": 9200,
       "method": "post",
       "path": "/_xpack/watcher/watch/{{ctx.watch_id}}/_ack",
       "params": {},
       "headers": {}
     }
   }
 }

```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 20, 2017, 8:14am UTC](https://discuss.elastic.co/t/watcher-auto-acknowledgment-throttle-period-reset/107915/3 "2017-11-20T08:14:34Z")

</div>

what Elasticsearch version are you using?

---

<div class="post-metadata">

**Author:** ![Sergey\_Urushkin](https://avatars.discourse-cdn.com/v4/letter/s/8baadc/32.png) [@Sergey\_Urushkin](https://discuss.elastic.co/u/Sergey_Urushkin)\
**Post date:** [November 21, 2017, 11:39am UTC](https://discuss.elastic.co/t/watcher-auto-acknowledgment-throttle-period-reset/107915/4 "2017-11-21T11:39:40Z")

</div>

5.6.4

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 22, 2017, 10:39am UTC](https://discuss.elastic.co/t/watcher-auto-acknowledgment-throttle-period-reset/107915/5 "2017-11-22T10:39:50Z")

</div>

if you need one-shot messages, wouldnt it work if you use a chained input, that gets/searches a specific document, and if that document exist, you do/do not execute any action?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 20, 2017, 10:40am UTC](https://discuss.elastic.co/t/watcher-auto-acknowledgment-throttle-period-reset/107915/6 "2017-12-20T10:40:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
