# Watcher Query with filter

**URL:** <https://discuss.elastic.co/t/watcher-query-with-filter/314600>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [September 16, 2022, 7:40pm UTC](https://discuss.elastic.co/t/watcher-query-with-filter/314600 "2022-09-16T19:40:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![lchan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lchan/32/90857_2.png) [@lchan](https://discuss.elastic.co/u/lchan)\
**Post date:** [September 16, 2022, 7:40pm UTC](https://discuss.elastic.co/t/watcher-query-with-filter/314600/1 "2022-09-16T19:40:35Z")

</div>

Hi all,

I am new and testing Watcher but for some reason I am not getting any hits count from this search.

I am trying to search "Authentication failure" in the syslog index, get alerted if any hits are found in the last 1hr.

Any insight would be helpful.  
Thanks!

```auto
PUT _watcher/watch/ssh_auth_failure_login
{
  "trigger": {
    "schedule": { "interval": "1h" }
  },
  "input": {
    "search": {
      "request": {
        "indices": ["syslog*"],
        "body": {
          "query": {
            "bool": {
              "must": {
                "match": {
                  "message": "Authentication failure"
                }
              },
              "filter": {
                "range": {
                  "@timestamp:": {
                    "from": "now-1h",
                    "to": "now"
                  }
                }
              }
            }
          }
        }
      }
    }
  },
  "actions": {
    "notify-slack" : {
      "throttle_period" : "5m",
      "slack" : {
        "message" : {
          "to" : ["@foo"], 
          "text" : "{{ctx.payload.hits.total}} hits in the last 1 hr :facepalm: " 
        }
      }
    }
  }
}

```

```auto

```

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [September 18, 2022, 9:28pm UTC](https://discuss.elastic.co/t/watcher-query-with-filter/314600/2 "2022-09-18T21:28:08Z")

</div>

First validate your search works all on it's own:

```auto
GET syslog*/_search
{
          "query": {
            "bool": {
              "must": {
                "match": {
                  "message": "Authentication failure"
                }
              },
              "filter": {
                "range": {
                  "@timestamp:": {
                    "from": "now-1h",
                    "to": "now"
                  }
                }
              }
            }
          }
        }
      }
    }
}

```

I can also imagine that you might not get any in the last 1 hour. So, in your test search (above, you can increase it to `1d`, `30d`, or whatever) to prove to yourself that you get at least some matches (and that nothing is wrong with your query).

---

<div class="post-metadata">

**Author:** ![lchan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lchan/32/90857_2.png) [@lchan](https://discuss.elastic.co/u/lchan)\
**Post date:** [September 20, 2022, 1:45pm UTC](https://discuss.elastic.co/t/watcher-query-with-filter/314600/3 "2022-09-20T13:45:07Z")

</div>

@richcollier thanks a lot! This helped, I figured it with the following. I believe this is the issue `"match": { "syslog_message":"Authentication failure" }`

```auto
GET syslog*/_search
{
"query": {
            "bool": {
              "must": [
                {
                  "match": { "syslog_message":"Authentication failure" }
                }
              ],
              "filter": [
                {
                  "range": { 
                    "@timestamp": {
                      "gte": "now-5m",
                      "lte": "now"
                    }
                  }
                }
              ]
            }
          }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 18, 2022, 1:46pm UTC](https://discuss.elastic.co/t/watcher-query-with-filter/314600/4 "2022-10-18T13:46:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
