# Automated Report Failing

**URL:** <https://discuss.elastic.co/t/automated-report-failing/83093>\
**Category:** Elasticsearch\
**Created:** [April 20, 2017, 4:56pm UTC](https://discuss.elastic.co/t/automated-report-failing/83093 "2017-04-20T16:56:54Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![banderson](https://avatars.discourse-cdn.com/v4/letter/b/a8b319/32.png) [@banderson](https://discuss.elastic.co/u/banderson)\
**Post date:** [April 20, 2017, 4:56pm UTC](https://discuss.elastic.co/t/automated-report-failing/83093/1 "2017-04-20T16:56:54Z")

</div>

I configured a notification email elasticsearch:

```
xpack.notification.email:
   smtp_account:
      profile: standard
      smtp:
         host: momail.mo.gov
         user: bill.anderson@oa.mo.gov
         from: kibana@oa.mo.gov

```

Then I created a watch:

```
PUT _xpack/watcher/watch/ios_severity
{
   "trigger": {
      "schedule": {
         "interval": "1h"
      }
   },
   "actions": {
      "smtp_account": {
         "email": {
            "profile": "standard",
            "attachments": {
               "cisco_ios_severity_report.pdf": {
                  "reporting": {
                     "url": "https://10.241.52.8:5601/api/reporting/generate/visualization/4b8ab530-1f91-11e7-9d44-ef23cde92150?_g=()&_a=(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:%27severity:%22alert%22%27)),uiState:(vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:%271%27,params:(),schema:metric,type:count),(enabled:!t,id:%272%27,params:(customLabel:%27Syslog+Host%27,field:sysloghost.keyword,order:desc,orderBy:%271%27,size:25),schema:bucket,type:terms)),listeners:(),params:(perPage:10,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:%27Top+Alert+(1)+Hosts%27,type:table))",
                     "retries": 10,
                     "interval": "1s",
                     "auth": {
                        "basic": {
                           "username": "elastic",
                           "password": "changeme"
                        }
                     }
                  }
               }
            },
            "to": [
               "bill.anderson@oa.mo.gov"
            ],
            "subject": "Cisco IOS Severity Report"
         }
      }
   }
}

```

So far so good. When I execute the watch:

`POST _xpack/watcher/watch/ios_severity/_execute`

I get this with an error

```
{
  "_id": "ios_severity_f1244026-7607-4d9d-ba77-d7301d035ff2-2017-04-20T16:55:09.850Z",
  "watch_record": {
    "watch_id": "ios_severity",
    "state": "executed",
    "trigger_event": {
      "type": "manual",
      "triggered_time": "2017-04-20T16:55:09.850Z",
      "manual": {
        "schedule": {
          "scheduled_time": "2017-04-20T16:55:09.850Z"
        }
      }
    },
    "input": {
      "none": {}
    },
    "condition": {
      "always": {}
    },
    "result": {
      "execution_time": "2017-04-20T16:55:09.850Z",
      "execution_duration": 8489,
      "input": {
        "type": "none",
        "status": "success",
        "payload": {}
      },
      "condition": {
        "type": "always",
        "status": "success",
        "met": true
      },
      "actions": [
        {
          "id": "smtp_account",
          "type": "email",
          "status": "failure",
          "reason": "IllegalArgumentException[no account found for name: [null]]"
        }
      ]
    },
    "messages": []
  }
}

```

I don't know why the account name is [null].

---

<div class="post-metadata">

**Author:** ![Stacey\_Gammon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stacey_gammon/32/14025_2.png) [@Stacey\_Gammon](https://discuss.elastic.co/u/Stacey_Gammon)\
**Post date:** [April 20, 2017, 6:50pm UTC](https://discuss.elastic.co/t/automated-report-failing/83093/2 "2017-04-20T18:50:56Z")

</div>

Did you configure a password field for your email account? In all the examples here I see a password field, but it's missing from your snippet (though perhaps you just left it out intentionally). [https://www.elastic.co/guide/en/x-pack/current/actions-email.html](https://www.elastic.co/guide/en/x-pack/current/actions-email.html)

---

<div class="post-metadata">

**Author:** ![banderson](https://avatars.discourse-cdn.com/v4/letter/b/a8b319/32.png) [@banderson](https://discuss.elastic.co/u/banderson)\
**Post date:** [April 20, 2017, 7:09pm UTC](https://discuss.elastic.co/t/automated-report-failing/83093/3 "2017-04-20T19:09:33Z")

</div>

This mail server does not require authentication.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 20, 2017, 7:46pm UTC](https://discuss.elastic.co/t/automated-report-failing/83093/4 "2017-04-20T19:46:42Z")

</div>

Hey Bill,

did you add the above account configuration to all of your nodes in the cluster?

Also, can you add `"account": "smtp_account"` to your watch email action and see if this works?

Thanks a lot!

--Alex

---

<div class="post-metadata">

**Author:** ![banderson](https://avatars.discourse-cdn.com/v4/letter/b/a8b319/32.png) [@banderson](https://discuss.elastic.co/u/banderson)\
**Post date:** [April 20, 2017, 8:37pm UTC](https://discuss.elastic.co/t/automated-report-failing/83093/5 "2017-04-20T20:37:40Z")

</div>

There is only one node in the cluster.

I added the account and I am now getting a different error:

```
"_id": "ios_severity_cf0fa8c7-0805-4b08-9d9c-e51006b4d7f3-2017-04-20T20:34:22.341Z",
  "watch_record": {
    "watch_id": "ios_severity",
    "state": "not_executed_already_queued",
    "trigger_event": {
      "type": "manual",
      "triggered_time": "2017-04-20T20:34:22.341Z",
      "manual": {
        "schedule": {
          "scheduled_time": "2017-04-20T20:34:22.341Z"
        }
      }
    },
    "messages": [
      "Watch is already queued in thread pool"
    ]
  }
}
```

---

<div class="post-metadata">

**Author:** ![banderson](https://avatars.discourse-cdn.com/v4/letter/b/a8b319/32.png) [@banderson](https://discuss.elastic.co/u/banderson)\
**Post date:** [April 20, 2017, 9:50pm UTC](https://discuss.elastic.co/t/automated-report-failing/83093/6 "2017-04-20T21:50:41Z")

</div>

I created a simpler watch:

```
PUT _xpack/watcher/watch/send_mail
{
  "trigger": {
      "schedule": {
         "interval": "1h"
      }
  },
  "actions": {
    "send_email" : { 
      "email" : { 
        "account": "smtp_account",
        "to" : "bill.anderson@oa.mo.gov", 
        "subject" : "Watcher Notification", 
        "body" : "error logs found" 
      }
    }
  }
}

```

And I get this error:

```
"actions": [
        {
          "id": "send_email",
          "type": "email",
          "status": "failure",
          "reason": "IllegalArgumentException[no account found for name: [smtp_account]]"
        }
      ]
```

---

<div class="post-metadata">

**Author:** ![banderson](https://avatars.discourse-cdn.com/v4/letter/b/a8b319/32.png) [@banderson](https://discuss.elastic.co/u/banderson)\
**Post date:** [April 20, 2017, 9:59pm UTC](https://discuss.elastic.co/t/automated-report-failing/83093/7 "2017-04-20T21:59:47Z")

</div>

```
I found the error. Here is the correct pack.notification.email section in elasticsearch.yml

    xpack.notification.email:
       account:
          smtp_account:
             profile: standard
             smtp:
                host: momail.mo.gov
                user: bill.anderson@oa.mo.gov
                from: kibana@oa.mo.gov

```

The `account:` line between the `xpack.notification.email:` line and the `smtp_account:` line was missing.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 18, 2017, 10:07pm UTC](https://discuss.elastic.co/t/automated-report-failing/83093/8 "2017-05-18T22:07:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
