# Watcher query current index by week

**URL:** <https://discuss.elastic.co/t/watcher-query-current-index-by-week/208750>\
**Category:** Kibana\
**Created:** [November 20, 2019, 6:27pm UTC](https://discuss.elastic.co/t/watcher-query-current-index-by-week/208750 "2019-11-20T18:27:32Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![uklipse](https://avatars.discourse-cdn.com/v4/letter/u/cdc98d/32.png) [@uklipse](https://discuss.elastic.co/u/uklipse)\
**Post date:** [November 20, 2019, 6:27pm UTC](https://discuss.elastic.co/t/watcher-query-current-index-by-week/208750/1 "2019-11-20T18:27:32Z")

</div>

I'm trying to create a watcher that will query the current index and indexes are rolled over each week with a format of flows-2019.46. I'm having troubles trying to get that expression to work in a watcher and could use some help. The line in question is:

"flows-{now/d{xxxx.ww}}"

I've tried variations of {YYYY.ww} and now/M{xxxx.ww} but can't get any to work. Any suggestion is appreciated.

---

<div class="post-metadata">

**Author:** ![cufflinks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cufflinks/32/42129_2.png) [@cufflinks](https://discuss.elastic.co/u/cufflinks)\
**Post date:** [November 20, 2019, 6:55pm UTC](https://discuss.elastic.co/t/watcher-query-current-index-by-week/208750/2 "2019-11-20T18:55:29Z")

</div>

Hi @uklipse,

Let me look into this and I will get back with you.

---

<div class="post-metadata">

**Author:** ![cufflinks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cufflinks/32/42129_2.png) [@cufflinks](https://discuss.elastic.co/u/cufflinks)\
**Post date:** [November 20, 2019, 7:23pm UTC](https://discuss.elastic.co/t/watcher-query-current-index-by-week/208750/3 "2019-11-20T19:23:23Z")

</div>

So is the issue when you are trying to format the rollup to have that name? Or is it when you are trying to set the indices to watch, you are trying to find the name? Because when looking for the indices to watch, you would just need a wildcard like `flows-*`. It's only when creating the rollup job that you have to use the formatting for the name of the generated rollup indices.

---

<div class="post-metadata">

**Author:** ![uklipse](https://avatars.discourse-cdn.com/v4/letter/u/cdc98d/32.png) [@uklipse](https://discuss.elastic.co/u/uklipse)\
**Post date:** [November 20, 2019, 7:30pm UTC](https://discuss.elastic.co/t/watcher-query-current-index-by-week/208750/4 "2019-11-20T19:30:43Z")

</div>

It is when we are trying to set the indices to watch. It works if I use flows-\* but this watcher runs every 30 minutes and I didn't want to search over all indexes for all time just the current one for performance reasons. Its purpose is to look back 1 hour and return a response if less than 10 hits are seen which would indicate something has stopped sending logs to this index.

The watcher has a compare condition to trigger if total hits are less than 10 (which triggers an alert) so if it sees more than 10 does it automatically stop searching and the compare condition fails and doens't trigger an alert?

Also thanks for the quick response!

---

<div class="post-metadata">

**Author:** ![cufflinks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cufflinks/32/42129_2.png) [@cufflinks](https://discuss.elastic.co/u/cufflinks)\
**Post date:** [November 20, 2019, 7:40pm UTC](https://discuss.elastic.co/t/watcher-query-current-index-by-week/208750/5 "2019-11-20T19:40:57Z")

</div>

I guess one way you can handle is to have the legacy data deleted or name changed so it no longer matches the wildcard expression once the new rollup is created.

---

<div class="post-metadata">

**Author:** ![uklipse](https://avatars.discourse-cdn.com/v4/letter/u/cdc98d/32.png) [@uklipse](https://discuss.elastic.co/u/uklipse)\
**Post date:** [November 20, 2019, 7:46pm UTC](https://discuss.elastic.co/t/watcher-query-current-index-by-week/208750/6 "2019-11-20T19:46:43Z")

</div>

When I run this watcher manually in dev tools, one of the fields it returns is execution\_duration. In my case, it returns a value of 7. Do you know what scale that value is in?

---

<div class="post-metadata">

**Author:** ![cufflinks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cufflinks/32/42129_2.png) [@cufflinks](https://discuss.elastic.co/u/cufflinks)\
**Post date:** [November 20, 2019, 9:10pm UTC](https://discuss.elastic.co/t/watcher-query-current-index-by-week/208750/7 "2019-11-20T21:10:55Z")

</div>

I am not sure. Another way you can get this achieved is with an advanced watch.  
But you should be able to do what you are asking in the UI.

[https://www.elastic.co/guide/en/elasticsearch/reference/current/input-search.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/input-search.html)  
[https://www.elastic.co/guide/en/elasticsearch/reference/7.4/date-math-index-names.html](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/date-math-index-names.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 18, 2019, 9:11pm UTC](https://discuss.elastic.co/t/watcher-query-current-index-by-week/208750/8 "2019-12-18T21:11:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
