# Configure Alerts in elastic cloud 7.7

**URL:** <https://discuss.elastic.co/t/configure-alerts-in-elastic-cloud-7-7/233744>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [May 21, 2020, 1:44pm UTC](https://discuss.elastic.co/t/configure-alerts-in-elastic-cloud-7-7/233744 "2020-05-21T13:44:42Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![David\_Oceans](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/david_oceans/32/51452_2.png) [@David\_Oceans](https://discuss.elastic.co/u/David_Oceans)\
**Post date:** [May 21, 2020, 1:44pm UTC](https://discuss.elastic.co/t/configure-alerts-in-elastic-cloud-7-7/233744/1 "2020-05-21T13:44:42Z")

</div>

Hi,

I have Elastic Cloud service, recently I've updated to 7.7 but I don't see the way to use alerts notifications with slack or my email.

That's functionalities are premium or something? or I should have the possibility to alert by slack or email some triggers?

Thank you very much

---

<div class="post-metadata">

**Author:** ![RaTheDev](https://avatars.discourse-cdn.com/v4/letter/r/c5a1d2/32.png) [@RaTheDev](https://discuss.elastic.co/u/RaTheDev)\
**Post date:** [May 21, 2020, 1:51pm UTC](https://discuss.elastic.co/t/configure-alerts-in-elastic-cloud-7-7/233744/2 "2020-05-21T13:51:42Z")

</div>

Have you tried the WATCHER options under Management -\> ElasticSearch -\> Wather.

---

<div class="post-metadata">

**Author:** ![David\_Oceans](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/david_oceans/32/51452_2.png) [@David\_Oceans](https://discuss.elastic.co/u/David_Oceans)\
**Post date:** [May 21, 2020, 1:59pm UTC](https://discuss.elastic.co/t/configure-alerts-in-elastic-cloud-7-7/233744/3 "2020-05-21T13:59:22Z")

</div>

I can see watcher, but when I want to add action for example by slack I have this message

```auto
Account may not be configured

To create this action, you must configure at least one Slack account. Learn more.

```

So, when I go to Kibana / Alerts and Actions / Connectors  
I filled slack options

- NAME
- WEBHOOK URL

So I turn back and create an alert but I got this message

```auto
Error testing action
[illegal_argument_exception] no accounts of type [slack] configured. Please set up an account using the [xpack.notification.slack] settings

```

I miss something?

Thanks

---

<div class="post-metadata">

**Author:** ![David\_Oceans](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/david_oceans/32/51452_2.png) [@David\_Oceans](https://discuss.elastic.co/u/David_Oceans)\
**Post date:** [May 22, 2020, 7:29am UTC](https://discuss.elastic.co/t/configure-alerts-in-elastic-cloud-7-7/233744/4 "2020-05-22T07:29:11Z")

</div>

Please any suggestion to solve the problem about how configure Alerts?

I read a lot it seems that now you don't need touch elastic cloud console or restarts nodes? all should be done from Kibana UI or dev tools?

Any clues to follow?

Thank you very much

---

<div class="post-metadata">

**Author:** ![David\_Oceans](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/david_oceans/32/51452_2.png) [@David\_Oceans](https://discuss.elastic.co/u/David_Oceans)\
**Post date:** [May 25, 2020, 3:45pm UTC](https://discuss.elastic.co/t/configure-alerts-in-elastic-cloud-7-7/233744/5 "2020-05-25T15:45:09Z")

</div>

I have my alert created but I'm not able to configure and alert by slack.

I have my incomming wehbook created like documentation says.

But I can't configure more, didn't work I can't save when I try to add slack method

**Error saving watch**

**[illegal\_argument\_exception] no accounts of type [slack] configured. Please set up an account using the [xpack.notification.slack] settings**

```auto
{
  "trigger": {
    "schedule": {
      "interval": "5m"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "gke_stage_*"
        ],
        "rest_total_hits_as_int": true,
        "body": {
          "size": 0,
          "query": {
            "bool": {
              "must": [
                {
                  "match": {
                    "message": "ERROR"
                  }
                },
                {
                  "range": {
                    "@timestamp": {
                      "from": "now-5m",
                      "to": "now"
                    }
                  }
                }
              ],
              "must_not": [
                {
                  "match": {
                    "kubernetes.namespace": "logging"
                  }
                },
                {
                  "match": {
                    "kubernetes.namespace": "kube-system"
                  }
                }
              ]
            }
          }
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "gt": 1
      }
    }
  },
"actions" : {
  "notify-slack" : {
    "throttle_period" : "5m",
    "slack" : {
      "message" : {
        "to" : ["#sysops", "@david"], 
        "text" : "Encountered {{ctx.payload.hits.total.value}} errors in the last 5 minutes (facepalm)" 
      }
    }
  }
}
}

```

I read  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/actions-slack.html#configuring-slack](https://www.elastic.co/guide/en/elasticsearch/reference/current/actions-slack.html#configuring-slack)

I don't know how I should configure the keystore on elastic cloud, the example seems onpremise.

```auto
bin/elasticsearch-keystore add xpack.notification.slack.account.monitoring.secure_url

```

Please any sugestion? no body use watcher in elastic cloud or alerts vía slack?

Thank you very much

---

<div class="post-metadata">

**Author:** ![David\_Oceans](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/david_oceans/32/51452_2.png) [@David\_Oceans](https://discuss.elastic.co/u/David_Oceans)\
**Post date:** [May 25, 2020, 5:13pm UTC](https://discuss.elastic.co/t/configure-alerts-in-elastic-cloud-7-7/233744/6 "2020-05-25T17:13:39Z")

</div>

Solved.

If you are using elastic cloud 7.7 you have to create in **keystore** (console elastic UI) that key `xpack.notification.slack.account.account1.secure_url`

and then in **secret** field you have to put Slack webhook.

Then if you want to use watcher, in your alert definition you have to put an action like this using the **account1** that you create before.

```auto
"actions": {
    "notify-slack": {
      "throttle_period_in_millis": 1000,
      "slack": {
        "account": "account1",
        "message": {
          "to": [
            "#env_dev"
          ],
          "text": "Encountered {{ctx.payload.hits.total}} errors in the last 5 minutes :face_with_monocle:"
        }
      }
    }

```

Enjoy!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 22, 2020, 5:14pm UTC](https://discuss.elastic.co/t/configure-alerts-in-elastic-cloud-7-7/233744/7 "2020-06-22T17:14:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
