# X-Pack watcher alarm "one new document indexed"

**URL:** <https://discuss.elastic.co/t/x-pack-watcher-alarm-one-new-document-indexed/65201>\
**Category:** Elasticsearch\
**Created:** [November 7, 2016, 10:38am UTC](https://discuss.elastic.co/t/x-pack-watcher-alarm-one-new-document-indexed/65201 "2016-11-07T10:38:27Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![chernals](https://avatars.discourse-cdn.com/v4/letter/c/a3d4f5/32.png) [@chernals](https://discuss.elastic.co/u/chernals)\
**Post date:** [November 7, 2016, 10:38am UTC](https://discuss.elastic.co/t/x-pack-watcher-alarm-one-new-document-indexed/65201/1 "2016-11-07T10:38:27Z")

</div>

I might have missed something in the doc, or just lack basic knowledge, but how could I define a watch to get alerted when one more document is indexed ?

I have an external system that triggers an "alert" by indexing one document in a special index in ES. Ideally the alarm should say "3 more alerts registered since last time I fired" (and I'll make it so that it fires often enough to have \<10 new alerts every time).

Thanks a lot 🙂

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 7, 2016, 1:50pm UTC](https://discuss.elastic.co/t/x-pack-watcher-alarm-one-new-document-indexed/65201/2 "2016-11-07T13:50:05Z")

</div>

Hey,

you could execute a query in a `search input`, that contains a timestamp filter, so you could search for documents that have been inserted in the last 10 minutes? All you need to add is the insertion timestamp for each document that gets added to that special index.

I might have missed your requirement that forbids this though...

--Alex

---

<div class="post-metadata">

**Author:** ![chernals](https://avatars.discourse-cdn.com/v4/letter/c/a3d4f5/32.png) [@chernals](https://discuss.elastic.co/u/chernals)\
**Post date:** [November 7, 2016, 2:27pm UTC](https://discuss.elastic.co/t/x-pack-watcher-alarm-one-new-document-indexed/65201/3 "2016-11-07T14:27:21Z")

</div>

Indeed, that makes perfect sense. I'll have a try (so far I'm still very inefficient writing queries).

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 7, 2016, 2:30pm UTC](https://discuss.elastic.co/t/x-pack-watcher-alarm-one-new-document-indexed/65201/4 "2016-11-07T14:30:19Z")

</div>

Side note: I moved this over to the x-pack forum for now. Feel free to paste your watches when you run into more issues.

---

<div class="post-metadata">

**Author:** ![chernals](https://avatars.discourse-cdn.com/v4/letter/c/a3d4f5/32.png) [@chernals](https://discuss.elastic.co/u/chernals)\
**Post date:** [November 7, 2016, 4:29pm UTC](https://discuss.elastic.co/t/x-pack-watcher-alarm-one-new-document-indexed/65201/5 "2016-11-07T16:29:22Z")

</div>

I managed to get exactly what I wanted 😉

```
PUT _watcher/watch/my_name
{
  "trigger": {
"schedule": {
  "interval": "1m"
}
  },
  "input": {
"search": {
  "request": {
    "indices": "my_index",
    "types": "my_type",
    "body": {
      "query": {
"bool" : {
  "must" : [
    { 
      "range" : { 
        "upload_date" : {
          "gte": "now-1m"
        }
      }
    },
    {
      "term": {"field": "value"}  
    }
  ]
}
  }
    }
  }
}
  },
  "condition": {
"compare" : {
  "ctx.payload.hits.total" : { 
    "gte" : 1
  }
}
  },
  "actions": {
"notify-slack" : {
  "throttle_period" : "1m",
  "slack" : {
    "account": "monitoring",
    "message" : {
      "to" : ["#general"],
      "text" : "{{ctx.payload.hits.total}} logs added."
    }
  }
}
  }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 5, 2016, 4:29pm UTC](https://discuss.elastic.co/t/x-pack-watcher-alarm-one-new-document-indexed/65201/6 "2016-12-05T16:29:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
