# Watcher which tries 2 times before alerting

**URL:** <https://discuss.elastic.co/t/watcher-which-tries-2-times-before-alerting/293128>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [December 29, 2021, 2:10pm UTC](https://discuss.elastic.co/t/watcher-which-tries-2-times-before-alerting/293128 "2021-12-29T14:10:12Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dimitri2](https://avatars.discourse-cdn.com/v4/letter/d/9e8a1a/32.png) [@Dimitri2](https://discuss.elastic.co/u/Dimitri2)\
**Post date:** [December 29, 2021, 2:10pm UTC](https://discuss.elastic.co/t/watcher-which-tries-2-times-before-alerting/293128/1 "2021-12-29T14:10:12Z")

</div>

Hello everyone,

I'm new to Elastic and I'm having trouble.

I'm trying to get my Watcher to not return an alert right away but wait a moment to confirm or deny the problem.  
So instead of sending an alert directly, I want the Watcher to wait for example 15 minutes then look again and send the alert if the problem persists.

I found this topic that seemed to have the same problem as me but I didn't understand the answer given : [Delay watcher trigger time | Heartbeat](https://discuss.elastic.co/t/delay-watcher-trigger-time-heartbeat/149996)

Do you have an idea?

Thank you for your help. 🙂

---

<div class="post-metadata">

**Author:** ![Dimitri2](https://avatars.discourse-cdn.com/v4/letter/d/9e8a1a/32.png) [@Dimitri2](https://discuss.elastic.co/u/Dimitri2)\
**Post date:** [January 3, 2022, 2:14pm UTC](https://discuss.elastic.co/t/watcher-which-tries-2-times-before-alerting/293128/3 "2022-01-03T14:14:53Z")

</div>

Hello everyone!

I'm still stuck, can you please help me?

Thank you!

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 5, 2022, 1:16pm UTC](https://discuss.elastic.co/t/watcher-which-tries-2-times-before-alerting/293128/4 "2022-01-05T13:16:47Z")

</div>

I think you can write the first alert to another index with the timestamp.  
Then add a watch on this index and if the number of hits within an 15 minutes period is more than one, send the alert you want.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [January 5, 2022, 3:32pm UTC](https://discuss.elastic.co/t/watcher-which-tries-2-times-before-alerting/293128/5 "2022-01-05T15:32:40Z")

</div>

How about refining the way you are querying Elasticsearch? Instead of one query looking back the last 15 minutes, how about creating two queries. The first looks back from now till 15 minutes ago, the second from 15 minutes ago till 30 minutes ago (or whatever time delay you are interested in) and then you check if the problem exists in both queries. If that is the case trigger an alert.

--Alex

---

<div class="post-metadata">

**Author:** ![Dimitri2](https://avatars.discourse-cdn.com/v4/letter/d/9e8a1a/32.png) [@Dimitri2](https://discuss.elastic.co/u/Dimitri2)\
**Post date:** [January 7, 2022, 1:08pm UTC](https://discuss.elastic.co/t/watcher-which-tries-2-times-before-alerting/293128/6 "2022-01-07T13:08:45Z")

</div>

Hello,

I'll try to do it like this.

Thank you very much for your answers!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 4, 2022, 1:09pm UTC](https://discuss.elastic.co/t/watcher-which-tries-2-times-before-alerting/293128/7 "2022-02-04T13:09:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
