# Watcher Timestamp showing in EPOCH

**URL:** <https://discuss.elastic.co/t/watcher-timestamp-showing-in-epoch/283075>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [September 1, 2021, 4:07pm UTC](https://discuss.elastic.co/t/watcher-timestamp-showing-in-epoch/283075 "2021-09-01T16:07:40Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![arunhk3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arunhk3/32/32864_2.png) [@arunhk3](https://discuss.elastic.co/u/arunhk3)\
**Post date:** [September 1, 2021, 4:07pm UTC](https://discuss.elastic.co/t/watcher-timestamp-showing-in-epoch/283075/1 "2021-09-01T16:07:40Z")

</div>

Hi All,

I was creating a watch in watcher which looks as below

```auto
{
  "trigger" : {
    "schedule" : {
      "interval" : "3h"
    }
  }
},
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "test_index*"
        ],
        "types": [],
        "body": {
          "query": {
            "bool": {
              "filter": [
                {
                  "range": {
                    "creationDate": {
                      "gte": "now-180m"
                    }
                  }
                }
              ],
              "must": [
                {
                  "term": {
                    "responseCode": "400"
                  }
                }
              ],
              "should": [
                {
                  "match_phrase": {
                    "apiName": "TEST_API"
                  }
                }
              ],
              "minimum_should_match": 1
            }
          }
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "gte": 1
      }
    }
  },
  "actions": {
    "send_email": {
	    "email": {
        "profile": "standard",
        "from": "Alerts@xxxxxxxx.com",
        "to": [
          "recepient1@xxxxxxxx.com",
		  "recepeint2@xxxxxxxx.com"
        ],
        "subject": "ALERT: Alert for {{ctx.payload.hits.hits.0._source.apiName}} (Error: 400)",
        "body": {
          "html": "Total Failure In The Last 3 hours: <strong>{{ctx.payload.hits.total}}</strong> <br><br><strong><u>Quick Snapshot of failures</u></strong><br><br> <table><tr> <th>API_Name</th> <th>Transaction_Status</th> <th>Response_Code</th> <th>Creation_Date</th></tr> {{#ctx.payload.hits.hits}}<tr><td>{{_source.apiName}}</td><td>{{_source.status}}</td><td>{{_source.responseCode}}</td><td>{{_source.creationDate}}</td></tr>{{/ctx.payload.hits.hits}}</table><br>"
        }
      }
    }
  }
}

```

The email when fired captures the timestamp field as **\_source.creationDate** and it returns it as **1630066569744**.

But I need the result to be shown in **MM/DD/YYYY HH:MM:SS** in the timezone **America/Alabama**.

I am new to this and upon my research I came to know that I need to use script transform for it. So please guide me in the right direction as it would help me to a greater extent!

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 2, 2021, 8:25am UTC](https://discuss.elastic.co/t/watcher-timestamp-showing-in-epoch/283075/2 "2021-09-02T08:25:11Z")

</div>

Hey,

so if the original JSON value is a epoch date, you can use a transform to convert that date. This is from the top of my head and might need some refinement but shows the basic idea:

```auto
Instant.ofEpochMilli(1636314242323L).atZone(ZoneId.of("America/Chicago")).format(DateTimeFormatter.ISO_OFFSET_DATE_TIME)

```

---

<div class="post-metadata">

**Author:** ![arunhk3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arunhk3/32/32864_2.png) [@arunhk3](https://discuss.elastic.co/u/arunhk3)\
**Post date:** [September 2, 2021, 5:05pm UTC](https://discuss.elastic.co/t/watcher-timestamp-showing-in-epoch/283075/3 "2021-09-02T17:05:50Z")

</div>

Thanks for the reply!

But does it have to be used in a **Script Transform**? I am quite new to scripting and stuff, so do we have any samples to look at so that I could use it as a reference?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 3, 2021, 2:51pm UTC](https://discuss.elastic.co/t/watcher-timestamp-showing-in-epoch/283075/4 "2021-09-03T14:51:28Z")

</div>

This repo might help: [https://github.com/elastic/examples/tree/master/Alerting](https://github.com/elastic/examples/tree/master/Alerting)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 1, 2021, 2:51pm UTC](https://discuss.elastic.co/t/watcher-timestamp-showing-in-epoch/283075/5 "2021-10-01T14:51:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
