# Creating a Watcher Alert to a Webhook

**URL:** <https://discuss.elastic.co/t/creating-a-watcher-alert-to-a-webhook/121538>\
**Category:** Elasticsearch\
**Created:** [February 26, 2018, 5:45pm UTC](https://discuss.elastic.co/t/creating-a-watcher-alert-to-a-webhook/121538 "2018-02-26T17:45:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dmdm](https://avatars.discourse-cdn.com/v4/letter/d/858c86/32.png) [@dmdm](https://discuss.elastic.co/u/dmdm)\
**Post date:** [February 26, 2018, 5:45pm UTC](https://discuss.elastic.co/t/creating-a-watcher-alert-to-a-webhook/121538/1 "2018-02-26T17:45:43Z")

</div>

Need a little help, new to Elastisearch and Kibana. Could someone tell me what I'm doing wrong I tried changing the example send an email on cluster status to use a web hook, but just keep getting errors:

{  
"trigger" : {  
"schedule" : { "interval" : "10s" }  
},  
"input" : {  
"http" : {  
"request" : {  
"host" : "localhost",  
"port" : 9200,  
"path" : "/\_cluster/health"  
}  
}  
},  
"condition" : {  
"compare" : {  
"ctx.payload.status" : { "eq" : "red" }  
}  
},  
"actions" : {  
"webhook" : {  
"method" : "POST"'  
"url" : "[hooks.slack.com/services/restofurlhere](http://hooks.slack.com/services/restofurlhere)",  
"subject" : "Cluster Status Warning",  
"body" : "Cluster status is RED"  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![dmdm](https://avatars.discourse-cdn.com/v4/letter/d/858c86/32.png) [@dmdm](https://discuss.elastic.co/u/dmdm)\
**Post date:** [February 26, 2018, 5:55pm UTC](https://discuss.elastic.co/t/creating-a-watcher-alert-to-a-webhook/121538/2 "2018-02-26T17:55:32Z")

</div>

Think I got it:

{  
"trigger": {  
"schedule": {  
"interval": "10s"  
}  
},  
"input": {  
"http": {  
"request": {  
"scheme": "http",  
"host": "localhost",  
"port": 9200,  
"method": "get",  
"path": "/\_cluster/health",  
"params": {},  
"headers": {}  
}  
}  
},  
"condition": {  
"compare": {  
"ctx.payload.status": {  
"eq": "green"  
}  
}  
},  
"actions": {  
"my\_webhook": {  
"throttle\_period\_in\_millis": 10000,  
"webhook": {  
"scheme": "https",  
"host": "[hooks.slack.com](http://hooks.slack.com)",  
"port": 443,  
"method": "post",  
"path": "/services/restofurl",  
"params": {},  
"headers": {},  
"body": "Cluster status is RED"  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 27, 2018, 12:52pm UTC](https://discuss.elastic.co/t/creating-a-watcher-alert-to-a-webhook/121538/3 "2018-02-27T12:52:13Z")

</div>

please use proper formatting for JSON snippets, just pasting them makes it impossible to read.

Also, dont just post a snippet, but add the response your request as well. And the output of the execute watch API in case your watch was successfully stored.

Lastly I highly encourage you to [this blog post](https://www.elastic.co/blog/watching-the-watches-writing-debugging-and-testing-watches) about writing and debugging watches, which should give you the shortest feedback loop possible when writing new watches.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 27, 2018, 12:53pm UTC](https://discuss.elastic.co/t/creating-a-watcher-alert-to-a-webhook/121538/4 "2018-03-27T12:53:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
