# X-Pack Watcher Duplicate Slack Notifications

**URL:** <https://discuss.elastic.co/t/x-pack-watcher-duplicate-slack-notifications/136087>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [June 15, 2018, 11:33am UTC](https://discuss.elastic.co/t/x-pack-watcher-duplicate-slack-notifications/136087 "2018-06-15T11:33:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ddregalo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ddregalo/32/32320_2.png) [@ddregalo](https://discuss.elastic.co/u/ddregalo)\
**Post date:** [June 15, 2018, 11:33am UTC](https://discuss.elastic.co/t/x-pack-watcher-duplicate-slack-notifications/136087/1 "2018-06-15T11:33:20Z")

</div>

Hi, I have set up a watcher to check "monitor.status": "down" with a condition of "ctx.payload.hits.total" : { "gt": 0 } and throttle\_period of 30 minutes (inside the actions) for a "notify-slack" action.

This works fine (watch sends slack notification every 30 mins) but I would like to know if there is a way NOT to send the slack notification if the error (same url monitor.status is down) even when the throttle-period expires...basically only send a particular error message ONCE and not repeatedly every 30 mins. I've looked at ACK Watch API but can't figure out how to implement this in my Watch JSON syntax (kibana).

Any help would be greatly appreciated! 🙂

Daniel

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 22, 2018, 2:09pm UTC](https://discuss.elastic.co/t/x-pack-watcher-duplicate-slack-notifications/136087/2 "2018-06-22T14:09:35Z")

</div>

Hey,

you cannot ack a watch while it is running. What you could do as a work around though, is to query the watch history index using a chained input, get the last x hits from the last n minutes, and check if the condition was met earlier. If it was always met, then return `false` in the condition.

Hope this helps!

--Alex

---

<div class="post-metadata">

**Author:** ![ddregalo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ddregalo/32/32320_2.png) [@ddregalo](https://discuss.elastic.co/u/ddregalo)\
**Post date:** [June 25, 2018, 11:11am UTC](https://discuss.elastic.co/t/x-pack-watcher-duplicate-slack-notifications/136087/3 "2018-06-25T11:11:03Z")

</div>

Thanks for the help Alex! Really appreciate your time and having a blast working with elasticsearch watchers 🙂

Cheers,  
Daniel

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 23, 2018, 11:11am UTC](https://discuss.elastic.co/t/x-pack-watcher-duplicate-slack-notifications/136087/4 "2018-07-23T11:11:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
