# Watcher does not get triggered properly

**URL:** <https://discuss.elastic.co/t/watcher-does-not-get-triggered-properly/275630>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [June 10, 2021, 10:45pm UTC](https://discuss.elastic.co/t/watcher-does-not-get-triggered-properly/275630 "2021-06-10T22:45:49Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mhmtsvr](https://avatars.discourse-cdn.com/v4/letter/m/ebca7d/32.png) [@mhmtsvr](https://discuss.elastic.co/u/mhmtsvr)\
**Post date:** [June 10, 2021, 10:45pm UTC](https://discuss.elastic.co/t/watcher-does-not-get-triggered-properly/275630/1 "2021-06-10T22:45:49Z")

</div>

Hi,

I have a watcher notifying the slack channel once elastic receives any logs regarding the query I set. It usually triggers, but I sometimes observe that the watcher does not get triggered even though logs are available in the elastic. Is there something wrong with the watcher configuration or the watcher itself?

```auto
{
  "trigger": {
    "schedule": {
      "interval": "30s"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "filebeat-*"
        ],
        "rest_total_hits_as_int": true,
        "body": {
          "query": {
            "bool": {
              "filter": [
                {
                  "range": {
                    "@timestamp": {
                      "gte": "now-30s",
                      "lte": "now"
                    }
                  }
                }
              ],
              "must": [
                {
                  "regexp": {
                    "fields.auditlog": "<app-name>"
                  }
                },
                {
                  "regexp": {
                    "request.path": "path/.*"
                  }
                }
              ]
            }
          }
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "gte": 1
      }
    }
  },
  "actions": {
    "notify-slack": {
      "throttle_period_in_millis": 30000,
      "slack": {
        "message": {
          "from": "Monitoring App",
          "to": [
            "<#slack-channel-name>"
          ],
              "text": "<text here>"
        }
      }
    }
  }
}

```

As it can be seen, the watcher is able to get triggered. However, I try to trigger it after 2 mins, it happens nothing. Like I mentioned, the logs are available in elastic.

 ![Screen Shot 2021-06-10 at 6.41.27 PM](https://us1.discourse-cdn.com/elastic/original/3X/b/3/b32f90d9b30b7bea7ac684dff2d606160980d020.png)

Any leads on this issue will be highly appreciated. Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 8, 2021, 10:45pm UTC](https://discuss.elastic.co/t/watcher-does-not-get-triggered-properly/275630/2 "2021-07-08T22:45:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
