# Watcher time filter problem

**URL:** <https://discuss.elastic.co/t/watcher-time-filter-problem/34690>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [November 16, 2015, 3:26pm UTC](https://discuss.elastic.co/t/watcher-time-filter-problem/34690 "2015-11-16T15:26:49Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![zokratez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zokratez/32/5974_2.png) [@zokratez](https://discuss.elastic.co/u/zokratez)\
**Post date:** [November 16, 2015, 3:26pm UTC](https://discuss.elastic.co/t/watcher-time-filter-problem/34690/1 "2015-11-16T15:26:49Z")

</div>

I have a watcher checking if somebody is making ssh bruteforce... I run the Hydra to generate some logs... and the watcher find it and send me emails correctly. The problem is that it's never stop sending me emails... So I read this post: [How do I setup watcher to only alert on new messages?](https://discuss.elastic.co/t/how-do-i-setup-watcher-to-only-alert-on-new-messages/27330) and change my query, but the error persist...

Here is my watcher snippet:

```
curl -XPUT 'http://localhost:9200/_watcher/watch/ssh_bruteforce' -d '{
  "trigger" : {
    "schedule" : { "interval" : "30s" } 
  },
  "input" : {
    "search" : {
      "request" : {
        "indices" : ["logstash-*"],
        "body" : {
          "query" : {
            "filtered" : {
              "query" : {"match" : {"message": "*Too many authentication failures*"}},
              "filter": {
                "bool": {
                  "must": [
                    {
                      "range": {
                        "@timestamp": {
                          "gte": "now-60s"
                        }
                      }
                    }
                  ]
                }
              }
            }
          }
        }
      }
    }
  },
  "condition" : {
    "compare" : { "ctx.payload.hits.total" : { "gt" : 0 }}
  },
  "actions" : {
    "email_administrator" : {
      "throttle_period": "30s", 
      "email" : { 
        "to" : "email@gmail.com",
        "subject" : "[Watcher]Posible ataque de fuerza bruta a SSH",
        "body" : "Demasiados intentos fallidos para por SSH.",
        "attach_data" : true,
        "priority" : "high"
      }
    }
  }
}'

```

The time filter is not working... The watcher send me an email each 30 seconds...

Thanks!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 17, 2015, 9:15am UTC](https://discuss.elastic.co/t/watcher-time-filter-problem/34690/2 "2015-11-17T09:15:57Z")

</div>

Pretty sure `"throttle_period"` shouldn't be under the `"actions"` section, eg [https://www.elastic.co/guide/en/watcher/current/watching-marvel-data.html#watching-cluster-health](https://www.elastic.co/guide/en/watcher/current/watching-marvel-data.html#watching-cluster-health)

---

<div class="post-metadata">

**Author:** ![zokratez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zokratez/32/5974_2.png) [@zokratez](https://discuss.elastic.co/u/zokratez)\
**Post date:** [November 17, 2015, 12:38pm UTC](https://discuss.elastic.co/t/watcher-time-filter-problem/34690/3 "2015-11-17T12:38:47Z")

</div>

Thanks for the reply! I change this line place, but the problem is the filter... Is finding hits from 2 days ago, and I need 5 minutes ago...

```
       "query" : {
            "filtered" : {
              "query" : {"match" : {"message": "*Too many authentication failures*"}},
              "filter": {
                "bool": {
                  "must": [
                    {
                      "range": {
                        "@timestamp": {
                          "gte": "now-60s"
                        }
                      }
                    }
                  ]
                }
              }
            }
          }

```

What's the correct way to filter only newest hits for specific event?

Thanks!

---

<div class="post-metadata">

**Author:** ![zokratez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zokratez/32/5974_2.png) [@zokratez](https://discuss.elastic.co/u/zokratez)\
**Post date:** [November 17, 2015, 4:40pm UTC](https://discuss.elastic.co/t/watcher-time-filter-problem/34690/4 "2015-11-17T16:40:03Z")

</div>

I find out that the problem is the filter.

```
"query" : {"match" : {"message": "*Too many authentication failures*"}},

```

This is'nt finding the literal string with wildcards, is finding any word in the string... Match for authentication, or failures, or many.... However, in the kibana that search work fine...

---

<div class="post-metadata">

**Author:** ![zokratez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zokratez/32/5974_2.png) [@zokratez](https://discuss.elastic.co/u/zokratez)\
**Post date:** [November 20, 2015, 12:12pm UTC](https://discuss.elastic.co/t/watcher-time-filter-problem/34690/5 "2015-11-20T12:12:37Z")

</div>

I solved changing the "match" by "match\_phrase" and now, the search is exact.

Thanks!

---

<div class="post-metadata">

**Author:** ![sthurlow](https://avatars.discourse-cdn.com/v4/letter/s/e9bcb4/32.png) [@sthurlow](https://discuss.elastic.co/u/sthurlow)\
**Post date:** [January 1, 2016, 5:36am UTC](https://discuss.elastic.co/t/watcher-time-filter-problem/34690/6 "2016-01-01T05:36:26Z")

</div>

I spent 5 hours trying to get this working, thanks for posting your answer - solved it for me immediately.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:47pm UTC](https://discuss.elastic.co/t/watcher-time-filter-problem/34690/7 "2017-07-06T13:47:30Z")

</div>


