# Watchers: moustache expressions syntax

**URL:** <https://discuss.elastic.co/t/watchers-moustache-expressions-syntax/130839>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [May 7, 2018, 1:32pm UTC](https://discuss.elastic.co/t/watchers-moustache-expressions-syntax/130839 "2018-05-07T13:32:51Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![jetnet](https://avatars.discourse-cdn.com/v4/letter/j/a87d85/32.png) [@jetnet](https://discuss.elastic.co/u/jetnet)\
**Post date:** [May 7, 2018, 1:32pm UTC](https://discuss.elastic.co/t/watchers-moustache-expressions-syntax/130839/1 "2018-05-07T13:32:51Z")

</div>

Hi again!

one more question regarding Watchers: I've been using such syntax for long time already:

```auto
 "range": {
  "modification": {
    "gte": "{{ctx.trigger.scheduled_time}}||-60m",
     "lte": null
  }
}

```

The variables are described [here](https://www.elastic.co/guide/en/x-pack/current/condition-compare.html#_accessing_values_in_the_execution_context), but I've never seen documentation for that syntax: `||-60m` . Why does the double pipe mean just "space" and not "OR", as one might think? 🙂

Could you guy please point to the documentation for these operations?  
Thank you!

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 7, 2018, 2:08pm UTC](https://discuss.elastic.co/t/watchers-moustache-expressions-syntax/130839/2 "2018-05-07T14:08:01Z")

</div>

~~It's not clear why (as in what is the behavior you experience that justifies this ) you think this is a space and not a boolean OR, but it **is** a boolean OR operator as it is [clearly documented in the painless docs](https://www.elastic.co/guide/en/elasticsearch/painless/current/_operators.html#_boolean_or)~~

See below for the correct answer.

---

<div class="post-metadata">

**Author:** ![jetnet](https://avatars.discourse-cdn.com/v4/letter/j/a87d85/32.png) [@jetnet](https://discuss.elastic.co/u/jetnet)\
**Post date:** [May 7, 2018, 2:24pm UTC](https://discuss.elastic.co/t/watchers-moustache-expressions-syntax/130839/3 "2018-05-07T14:24:47Z")

</div>

oops, I always thought that such expression meant _scheduled time MINUS 60 minutes_, basically, I use it to check the events for the last hour 😕  
If the double pipe is just the "normal" OR operator, how should the expression above be read? If `{{ctx.trigger.scheduled_time}}` is not set, then use `-60m`?  
Thanks!

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [May 7, 2018, 2:25pm UTC](https://discuss.elastic.co/t/watchers-moustache-expressions-syntax/130839/4 "2018-05-07T14:25:27Z")

</div>

@jetnet you are correct. This is indeed not painless , but the [date math feature](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/common-options.html#date-math) of Elasticsearch

---

<div class="post-metadata">

**Author:** ![jetnet](https://avatars.discourse-cdn.com/v4/letter/j/a87d85/32.png) [@jetnet](https://discuss.elastic.co/u/jetnet)\
**Post date:** [May 7, 2018, 2:33pm UTC](https://discuss.elastic.co/t/watchers-moustache-expressions-syntax/130839/5 "2018-05-07T14:33:55Z")

</div>

Great! Going to bookmark the link 🙂  
Thanks a lot again!

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 7, 2018, 2:55pm UTC](https://discuss.elastic.co/t/watchers-moustache-expressions-syntax/130839/6 "2018-05-07T14:55:48Z")

</div>

Sorry for the confusion @jetnet and @spinscale . I totally misread this and spoke too quickly, glad you figured it out.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 4, 2018, 2:55pm UTC](https://discuss.elastic.co/t/watchers-moustache-expressions-syntax/130839/7 "2018-06-04T14:55:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
