﻿---
title: stack es watcher put-watch cli command
description: Create or update a watch. Behaviour flags: --dry-run — validate all inputs and exit without performing any action 
url: https://www.elastic.co/elastic/docs-builder/docs/4075/reference/elastic-cli/cli/stack/es/watcher/put-watch
applies_to:
  - Elastic Cloud Serverless: Preview
  - Elastic Stack: Preview
---

# stack es watcher put-watch cli command
<cli-modifiers>
</cli-modifiers>

```bash
elastic stack es watcher put-watch --id <id> [options]
```

Create or update a watch.
**Behaviour flags:**
`--dry-run` — validate all inputs and exit without performing any action

## Options

<definitions>
  <definition term="--id string required">
    The identifier for the watch.
  </definition>
  <definition term="--active">
    The initial state of the watch.
    The default value is `true`, which means the watch is active by default.
  </definition>
  <definition term="--if-primary-term number">
    Only update the watch if the last operation that has changed the watch has the specified primary term
  </definition>
  <definition term="--if-seq-no number">
    Only update the watch if the last operation that has changed the watch has the specified sequence number
  </definition>
  <definition term="--version number">
    Explicit version number for concurrency control
  </definition>
  <definition term="--actions string">
    The list of actions that will be run if the condition matches.
  </definition>
  <definition term="--condition string">
    The condition that defines if the actions should be run.
  </definition>
  <definition term="--input string">
    The input that defines the input that loads the data for the watch.
  </definition>
  <definition term="--metadata string">
    Metadata JSON that will be copied into the history entries.
  </definition>
  <definition term="--throttle-period string">
    The minimum time between actions being run.
    The default is 5 seconds.
    This default can be changed in the config file with the setting `xpack.watcher.throttle.period.default_period`.
    If both this value and the `throttle_period_in_millis` parameter are specified, Watcher uses the last parameter included in the request.
  </definition>
  <definition term="--throttle-period-in-millis string">
    Minimum time in milliseconds between actions being run. Defaults to 5000. If both this value and the throttle_period parameter are specified, Watcher uses the last parameter included in the request.
  </definition>
  <definition term="--transform string">
    The transform that processes the watch payload to prepare it for the watch actions.
  </definition>
  <definition term="--trigger string">
    The trigger that defines when the watch should run.
  </definition>
  <definition term="--error-trace">
    When set to `true` Elasticsearch will include the full stack trace of errors
    when they occur.
  </definition>
  <definition term="--filter-path string">
    Comma-separated list of filters in dot notation which reduce the response
    returned by Elasticsearch.
    **Repeatable:** pass `--filter-path` multiple times to supply more than one value
  </definition>
  <definition term="--human">
    When set to `true` will return statistics in a format suitable for humans.
    For example `"exists_time": "1h"` for humans and
    `"exists_time_in_millis": 3600000` for computers. When disabled the human
    readable values will be omitted. This makes sense for responses being consumed
    only by machines.
  </definition>
  <definition term="--pretty">
    If set to `true` the returned JSON will be "pretty-formatted". Only use
    this option for debugging only.
  </definition>
  <definition term="--input-file string">
    path to a JSON file to use as command input
  </definition>
  <definition term="--dry-run">
    validate all inputs and exit without performing any action (preview changes without applying them)
  </definition>
</definitions>


## Global Options

<definitions>
  <definition term="--json">
    output as JSON
  </definition>
</definitions>