# Watcher elastic query

**URL:** <https://discuss.elastic.co/t/watcher-elastic-query/274210>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [May 27, 2021, 12:54pm UTC](https://discuss.elastic.co/t/watcher-elastic-query/274210 "2021-05-27T12:54:40Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![lucac](https://avatars.discourse-cdn.com/v4/letter/l/46a35a/32.png) [@lucac](https://discuss.elastic.co/u/lucac)\
**Post date:** [May 27, 2021, 12:54pm UTC](https://discuss.elastic.co/t/watcher-elastic-query/274210/1 "2021-05-27T12:54:41Z")

</div>

Hello everybody,  
I'm trying to create in Elastic (the cloud version) a trigger / alert that, based on the value of an index field, sends an email.

My index is, more or less, structured like this:

id timestamp  
XX 2021-05-01 17:23  
YY 2021-05-01 16:15

I would like to create an alert that, if the data is older than 10 minutes, a specific alert relating to the id will start, so:

"XX hasn't sent data for more than 10 minutes"

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [May 31, 2021, 7:16am UTC](https://discuss.elastic.co/t/watcher-elastic-query/274210/2 "2021-05-31T07:16:47Z")

</div>

Hey,

so the idea of watcher here, is to create an elasticsearch query first, that returns the data you need - so we should probably work on this first. In your case it seems you are interested in the latest timestamp for certain ids. You can try with a max aggregation on the timestamp and use a terms aggregation on the id field, and also filter for your 10 minute window in your query and then check the number of buckets - this will however only work for up to 10k buckets.

hope that helps as a start

--Alex

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 31, 2021, 7:36am UTC](https://discuss.elastic.co/t/watcher-elastic-query/274210/3 "2021-05-31T07:36:36Z")

</div>

Welcome to our community! 😃

There's a few examples here that might be of use - [examples/Alerting/Sample Watches at master · elastic/examples · GitHub](https://github.com/elastic/examples/tree/master/Alerting/Sample%20Watches)

---

<div class="post-metadata">

**Author:** ![lucac](https://avatars.discourse-cdn.com/v4/letter/l/46a35a/32.png) [@lucac](https://discuss.elastic.co/u/lucac)\
**Post date:** [May 31, 2021, 8:32am UTC](https://discuss.elastic.co/t/watcher-elastic-query/274210/4 "2021-05-31T08:32:20Z")

</div>

Can you help me with the query?

Where can I put the query and activate the trigger?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 21, 2021, 8:29am UTC](https://discuss.elastic.co/t/watcher-elastic-query/274210/5 "2021-06-21T08:29:20Z")

</div>

The [Create Watch API](https://www.elastic.co/guide/en/elasticsearch/reference/7.13/watcher-api-put-watch.html) should help you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 19, 2021, 8:29am UTC](https://discuss.elastic.co/t/watcher-elastic-query/274210/6 "2021-07-19T08:29:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
