# Watcher not letting me pull a timestamp from a log and use it to search from there

**URL:** <https://discuss.elastic.co/t/watcher-not-letting-me-pull-a-timestamp-from-a-log-and-use-it-to-search-from-there/258636>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [December 14, 2020, 7:51pm UTC](https://discuss.elastic.co/t/watcher-not-letting-me-pull-a-timestamp-from-a-log-and-use-it-to-search-from-there/258636 "2020-12-14T19:51:20Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![cah-cborders](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cah-cborders/32/80843_2.png) [@cah-cborders](https://discuss.elastic.co/u/cah-cborders)\
**Post date:** [December 14, 2020, 7:51pm UTC](https://discuss.elastic.co/t/watcher-not-letting-me-pull-a-timestamp-from-a-log-and-use-it-to-search-from-there/258636/1 "2020-12-14T19:51:20Z")

</div>

I'm trying to set up a Watcher in Kibana that will let me find an log with the message "Exit Status 1", then use the timestamp from that log to chain a new search and go back 20 logs or so from there so I can kind of create a stacktrace in Slack so we can begin to think about what might have caused the error without actually firing sorting through the logs.

Here's what I have so far:

```auto
        {
      "trigger": {
        "schedule": {
          "interval": "5m"
        }
      },
      "input": {
        "chain": {
          "inputs": [
            {
              "first": {
                "search": {
                  "request": {
                    "search_type": "query_then_fetch",
                    "indices": [
                      "pcf-*"
                    ],
                    "types": [],
                    "body": {
                      "size": 1,
                      "query": {
                        "bool": {
                          "must": [
                            {
                              "query_string": {
                                "query": "cf_app_name:\"app-name\""
                              }
                            },
                            {
                              "query_string": {
                                "query": "msg:\"*Exit status 1*\""
                              }
                            },
                            {
                              "query_string": {
                                "query": "cf_space_name: prod"
                              }
                            }
                          ]
                        }
                      }
                    }
                  }
                }
              }
            },
            {
              "second": {
                "transform": {
                  "script": {
                    "source": "return ['time': ctx.payload.first.hits.hits.0._source.syslog5424_ts = new date_time()]",
                    "lang": "painless"
                  }
                }
              }
            },
            {
              "third": {
                "search": {
                  "request": {
                    "search_type": "query_then_fetch",
                    "indices": [
                      "pcf-*"
                    ],
                    "types": [],
                    "body": {
                      "size": 20,
                      "query": {
                        "bool": {
                          "must": [
                            {
                              "query_string": {
                                "query": "cf_app_name:\"app-name\""
                              }
                            },
                            {
                              "query_string": {
                                "query": "cf_space_name: prod"
                              }
                            },
                            {
                              "range": {
                                "time": {
                                  "gte": "ctx.payload.second.time - 5m"
                                }
                              }
                            }
                          ]
                        }
                      }
                    }
                  }
                }
              }
            }
          ]
        }
      },
      "condition": {
        "always": {}
      },
      "actions": {
        "notify_slack": {
          "slack": {
            "message": {
              "to": [
                "#my-team"
              ],
              "text": "{{ctx.payload.second.time}}{{ctx.payload.third.hits.hits.0._source.syslog5424_ts}} {{ctx.payload.third.hits.hits.0._source.msg}} \n {{ctx.payload.third.hits.hits.1._source.msg}} \n {{ctx.payload.third.hits.hits.2._source.msg}} \n {{ctx.payload.third.hits.hits.3._source.msg}} \n {{ctx.payload.third.hits.hits.4._source.msg}} \n {{ctx.payload.third.hits.hits.5._source.msg}} \n {{ctx.payload.third.hits.hits.6._source.msg}} \n {{ctx.payload.third.hits.hits.7._source.msg}} \n {{ctx.payload.third.hits.hits.8._source.msg}} \n {{ctx.payload.third.hits.hits.9._source.msg}} \n{{ctx.payload.third.hits.hits.10._source.msg}} \n {{ctx.payload.third.hits.hits.11._source.msg}} \n {{ctx.payload.third.hits.hits.12._source.msg}} \n {{ctx.payload.third.hits.hits.13._source.msg}} \n {{ctx.payload.third.hits.hits.14._source.msg}} \n {{ctx.payload.third.hits.hits.15._source.msg}} \n {{ctx.payload.third.hits.hits.16._source.msg}} \n {{ctx.payload.third.hits.hits.17._source.msg}} \n {{ctx.payload.third.hits.hits.18._source.msg}} \n {{ctx.payload.third.hits.hits.19._source.msg}}"
            }
          }
        }
      }
    }

```

Based on the different things I've tried, I either get an error saying that the time range I'm trying to specify can't be parsed because it's not an instance of a date/time or I get zero results and I don't know why that is

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 11, 2021, 7:51pm UTC](https://discuss.elastic.co/t/watcher-not-letting-me-pull-a-timestamp-from-a-log-and-use-it-to-search-from-there/258636/2 "2021-01-11T19:51:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
