# X-pack watcher: Compare alerts from yesterday

**URL:** <https://discuss.elastic.co/t/x-pack-watcher-compare-alerts-from-yesterday/103406>\
**Category:** Elasticsearch\
**Created:** [October 10, 2017, 3:53pm UTC](https://discuss.elastic.co/t/x-pack-watcher-compare-alerts-from-yesterday/103406 "2017-10-10T15:53:36Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![xixo](https://avatars.discourse-cdn.com/v4/letter/x/e68b1a/32.png) [@xixo](https://discuss.elastic.co/u/xixo)\
**Post date:** [October 10, 2017, 3:53pm UTC](https://discuss.elastic.co/t/x-pack-watcher-compare-alerts-from-yesterday/103406/1 "2017-10-10T15:53:36Z")

</div>

Hi,

I want to generate a notification if the current events have decreased a 20% since yesterday.

Example:  
Sunday: 100 Events  
Monday: 60 Events -\> Notification

is it possible to define this query?

---

<div class="post-metadata">

**Author:** ![Narayanan\_Sukumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/narayanan_sukumar/32/19546_2.png) [@Narayanan\_Sukumar](https://discuss.elastic.co/u/Narayanan_Sukumar)\
**Post date:** [October 11, 2017, 6:57am UTC](https://discuss.elastic.co/t/x-pack-watcher-compare-alerts-from-yesterday/103406/2 "2017-10-11T06:57:05Z")

</div>

Yes Looking for a same.

I need to execute the same query last 15 mins and the same time 7 days back. If last 15mins value is greater than 7 days value, it should trigger an alert.

Is it possible?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 11, 2017, 9:55am UTC](https://discuss.elastic.co/t/x-pack-watcher-compare-alerts-from-yesterday/103406/3 "2017-10-11T09:55:52Z")

</div>

you can either execute two queries using a chained input and then compare those in the condition or you can execute a single query, that has two `range` queries (one for each range) and then use the `filters` aggregation to aggregate for each range.

---

<div class="post-metadata">

**Author:** ![Narayanan\_Sukumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/narayanan_sukumar/32/19546_2.png) [@Narayanan\_Sukumar](https://discuss.elastic.co/u/Narayanan_Sukumar)\
**Post date:** [October 12, 2017, 6:19am UTC](https://discuss.elastic.co/t/x-pack-watcher-compare-alerts-from-yesterday/103406/4 "2017-10-12T06:19:16Z")

</div>

I am facing issue when chaining the inputs. To add, I am using AWS elasticsearch service and inhouse kibana with sentinl plugin.

My ES index are created daily with index-YYYY.MM.dd format.

> <https://gist.github.com/narayanan1993/580a31a79723d1b91eb9a8141a4f7def>

Please help!

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 12, 2017, 7:13am UTC](https://discuss.elastic.co/t/x-pack-watcher-compare-alerts-from-yesterday/103406/5 "2017-10-12T07:13:54Z")

</div>

I am confused here. Are you using watcher or just hoping it is installed?

the AWS elasticsearch service does not ship with alerting, as this is a commercial feature of Elastic. If you want to use it, you need to have a valid license or use [Elastic Cloud](https://www.elastic.co/cloud), the hosted Elasticsearch platform run by us, Elastic.

Can you run `GET _xpack/watcher/stats` to find out if watcher is really installed?

---

<div class="post-metadata">

**Author:** ![Narayanan\_Sukumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/narayanan_sukumar/32/19546_2.png) [@Narayanan\_Sukumar](https://discuss.elastic.co/u/Narayanan_Sukumar)\
**Post date:** [October 16, 2017, 5:59am UTC](https://discuss.elastic.co/t/x-pack-watcher-compare-alerts-from-yesterday/103406/6 "2017-10-16T05:59:20Z")

</div>

Hi Spinscale,

Sorry for the confusion.

I am using the sentinl plugin that uses the same feature of xpack. All the plugin configurations are fine. All I am worried is that the query what I wrote is not working with the xpack plugin too.

Can you please help me with some sample queries that can satisfy the case I am doing.

Thanks!

---

<div class="post-metadata">

**Author:** ![Martin\_Becker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/martin_becker/32/22885_2.png) [@Martin\_Becker](https://discuss.elastic.co/u/Martin_Becker)\
**Post date:** [October 18, 2017, 9:56am UTC](https://discuss.elastic.co/t/x-pack-watcher-compare-alerts-from-yesterday/103406/7 "2017-10-18T09:56:28Z")

</div>

Are you looking for an example of a chained input?

---

<div class="post-metadata">

**Author:** ![lmangani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lmangani/32/12362_2.png) [@lmangani](https://discuss.elastic.co/u/lmangani)\
**Post date:** [October 24, 2017, 8:14am UTC](https://discuss.elastic.co/t/x-pack-watcher-compare-alerts-from-yesterday/103406/8 "2017-10-24T08:14:04Z")

</div>

Hi @Narayanan_Sukumar input chain support is coming soon in SENTINL 5.x

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 21, 2017, 8:14am UTC](https://discuss.elastic.co/t/x-pack-watcher-compare-alerts-from-yesterday/103406/9 "2017-11-21T08:14:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
