# Configure monitor query with limitation on aggeration

**URL:** <https://forum.opensearch.org/t/configure-monitor-query-with-limitation-on-aggeration/11071>\
**Category:** OpenSearch\
**Tags:** alerting\
**Created:** [September 28, 2022, 6:57am UTC](https://forum.opensearch.org/t/configure-monitor-query-with-limitation-on-aggeration/11071 "2022-09-28T06:57:36Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marius](https://avatars.discourse-cdn.com/v4/letter/m/ed655f/32.png) [@Marius](https://forum.opensearch.org/u/Marius)\
**Post date:** [September 28, 2022, 6:57am UTC](https://forum.opensearch.org/t/configure-monitor-query-with-limitation-on-aggeration/11071/1 "2022-09-28T06:57:36Z")

</div>

Hello,  
I am trying to configure a monitor that looks at data logged by cron jobs.  
I want to trigger an alert if a job does stop to log data.  
The query using SQL looks something like this:

```auto
POST _plugins/_sql/
{
  "query" : "SELECT instance, job-id, count(*), max(@timestamp) as newest FROM job-statistics-* where @timestamp > '2022-09-28 00:00:00.000' group BY job-id, instance HAVING newest < '2022-09-28 08:45:00.000'"
}

```

Using exlplain I converted this to a JSON Query and made the timestamp dynamic:

```auto
{
    "from": 0,
    "size": 0,
    "timeout": "1m",
    "query": {
        "range": {
            "@timestamp": {
                "from": "now-1h",
                "to": null,
                "include_lower": false,
                "include_upper": true,
                "boost": 1
            }
        }
    },
    "sort": [
        {
            "_doc": {
                "order": "asc"
            }
        }
    ],
    "aggregations": {
        "composite_buckets": {
            "composite": {
                "size": 1000,
                "sources": [
                    {
                        "job-id": {
                            "terms": {
                                "field": "job-id.keyword",
                                "missing_bucket": true,
                                "missing_order": "first",
                                "order": "asc"
                            }
                        }
                    },
                    {
                        "instance": {
                            "terms": {
                                "field": "instance.keyword",
                                "missing_bucket": true,
                                "missing_order": "first",
                                "order": "asc"
                            }
                        }
                    }
                ]
            },
            "aggregations": {
                "count(*)": {
                    "value_count": {
                        "field": "_index"
                    }
                },
                "max(@timestamp)": {
                    "max": {
                        "field": "@timestamp"
                    }
                }
            }
        }
    }
}

```

From this query, the limitation on the aggeration max(@timestmap) is missing.  
In the explain response it is here:

```auto
        "name": "FilterOperator",
        "description": {
          "conditions": """<(max(@timestamp), cast_to_timestamp("2022-09-28 08:45:00.000"))"""
        },

```

Ideally, this should be max(@timestmap) \< now-30min  
My question:  
How can I integrate this into the query or the monitor?  
Is there another way to do this?

Thanks a lot  
Marius
