# Watcher: same query two different ranges (times)

**URL:** <https://discuss.elastic.co/t/watcher-same-query-two-different-ranges-times/316982>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [October 19, 2022, 10:11am UTC](https://discuss.elastic.co/t/watcher-same-query-two-different-ranges-times/316982 "2022-10-19T10:11:24Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [October 19, 2022, 10:11am UTC](https://discuss.elastic.co/t/watcher-same-query-two-different-ranges-times/316982/1 "2022-10-19T10:11:24Z")

</div>

Hi,  
it's possible to create a watcher with a single query on two different times?

Ex. If a certain threshold is exceeded between 10-11 and 11-12 and so on. So the alert would trigger only if the two conditions are met

Thanks  
Regards

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [October 20, 2022, 2:43am UTC](https://discuss.elastic.co/t/watcher-same-query-two-different-ranges-times/316982/2 "2022-10-20T02:43:47Z")

</div>

Gosh, there are many ways this could be solved.

1. You could use a [input chain](https://www.elastic.co/guide/en/elasticsearch/reference/current/input-chain.html) to make multiple queries (one for time range X and the other for time range Y) and then inspect the results of each. Here's an example that uses 3 inputs.

> <https://gist.github.com/richcollier/13e245c1c8c8cfc38ecb12e324ce301e>

The time frames are the same in this example (but could differ)

1. Alternatively, you could do a single query over a time range, but then do a `date_histogram` aggregation on that query to break the time ranges up into chunks, aggregate the data in some way within those chunks, and then inspect the data in each sub aggregation. An example (albeit a little complex) can be seen here:

> <https://gist.github.com/richcollier/31e4de8773d6f9183a6cf4799836b8e0>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 17, 2022, 2:44am UTC](https://discuss.elastic.co/t/watcher-same-query-two-different-ranges-times/316982/3 "2022-11-17T02:44:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
