# Creating Watcher and Trigger alert from outlook 365

**URL:** <https://discuss.elastic.co/t/creating-watcher-and-trigger-alert-from-outlook-365/216510>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [January 25, 2020, 6:31am UTC](https://discuss.elastic.co/t/creating-watcher-and-trigger-alert-from-outlook-365/216510 "2020-01-25T06:31:01Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [January 25, 2020, 6:31am UTC](https://discuss.elastic.co/t/creating-watcher-and-trigger-alert-from-outlook-365/216510/1 "2020-01-25T06:31:01Z")

</div>

Hello,

I am trying to trigger an alert but I am getting an error

[2020-01-25T06:26:06,821][ERROR][o.e.x.w.a.e.ExecutableEmailAction] [CGAUH-PDLXS03] failed to execute action [_inlined_/email\_1]  
org.elasticsearch.common.settings.SettingsException: missing required email account setting for account [gmail\_account]. 'smtp.host' must be configured  
at org.elasticsearch.xpack.watcher.notification.email.Account$Config.(Account.java:197) ~[?:?]  
at org.elasticsearch.xpack.watcher.notification.email.EmailService.createAccount(EmailService.java:144) ~[?:?]  
at org.elasticsearch.xpack.watcher.notification.email.EmailService.createAccount(EmailService.java:35) ~[?:?]  
at org.elasticsearch.xpack.watcher.notification.NotificationService.lambda$buildAccounts$0(NotificationService.java:98) ~[?:?]  
at org.elasticsearch.xpack.watcher.notification.NotificationService.lambda$createAccounts$1(NotificationService.java:142) ~[?:?]  
at org.elasticsearch.common.util.LazyInitializable.maybeCompute(LazyInitializable.java:103) ~[elasticsearch-7.5.0.jar:7.5.0]  
at org.elasticsearch.common.util.LazyInitializable.getOrCompute(LazyInitializable.java:81) ~[elasticsearch-7.5.0.jar:7.5.0]  
at org.elasticsearch.xpack.watcher.notification.NotificationService.getAccount(NotificationService.java:121) ~[?:?]  
at org.elasticsearch.xpack.watcher.notification.email.EmailService.send(EmailService.java:158) ~[?:?]  
at org.elasticsearch.xpack.watcher.actions.email.ExecutableEmailAction.execute(ExecutableEmailAction.java:72) ~[?:?]  
at org.elasticsearch.xpack.core.watcher.actions.ActionWrapper.execute(ActionWrapper.java:164) [x-pack-core-7.5.0.jar:7.5.0]  
at org.elasticsearch.xpack.watcher.execution.ExecutionService.executeInner(ExecutionService.java:534) [x-pack-watcher-7.5.0.jar:7.5.0]  
at org.elasticsearch.xpack.watcher.execution.ExecutionService.execute(ExecutionService.java:320) [x-pack-watcher-7.5.0.jar:7.5.0]  
at org.elasticsearch.xpack.watcher.transport.actions.execute.TransportExecuteWatchAction$1.doRun(TransportExecuteWatchAction.java:159) [x-pack-watcher-7.5.0.jar:7.5.0]  
at org.elasticsearch.common.util.concurrent.AbstractRunnable.run(AbstractRunnable.java:37) [elasticsearch-7.5.0.jar:7.5.0]  
at org.elasticsearch.xpack.watcher.execution.ExecutionService$WatchExecutionTask.run(ExecutionService.java:627) [x-pack-watcher-7.5.0.jar:7.5.0]  
at org.elasticsearch.common.util.concurrent.ThreadContext$ContextPreservingRunnable.run(ThreadContext.java:703) [elasticsearch-7.5.0.jar:7.5.0]  
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1128) [?:?]  
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:628) [?:?]  
at java.lang.Thread.run(Thread.java:830) [?:?]

My elasticsearch.yml file config is

xpack.notification.email.account:  
outlook\_account:  
profile: outlook  
smtp:  
auth: true  
starttls.enable: true  
host: [smtp.office365.com](http://smtp.office365.com)  
port: 587  
user: Shrikant@domain.techno

Can someone Please guide me where i am facing problem

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [January 25, 2020, 1:28pm UTC](https://discuss.elastic.co/t/creating-watcher-and-trigger-alert-from-outlook-365/216510/2 "2020-01-25T13:28:02Z")

</div>

Others that have [reported this issue have had indention issues](https://stackoverflow.com/questions/37299590/error-smtp-host-must-be-configured-in-elasticsearch-yml), but your post isn't formatted to show indention.

---

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [January 26, 2020, 12:07pm UTC](https://discuss.elastic.co/t/creating-watcher-and-trigger-alert-from-outlook-365/216510/3 "2020-01-26T12:07:12Z")

</div>

It is showing that

missing required email account setting for account [gmail\_account]. 'smtp.host' must be configured

can someone help me out

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [January 27, 2020, 9:10am UTC](https://discuss.elastic.co/t/creating-watcher-and-trigger-alert-from-outlook-365/216510/4 "2020-01-27T09:10:51Z")

</div>

Len has a valid point, that your post is not showing indentation for the email account configuration. Please use markdown and code snippet functionality properly.

I see that `smtp.host` looks to be configured, but one cannot be sure due to not seeing the indentation.

Another important aspect is to make sure, that you updated the configuration file on all nodes and restarted them in order to take changes in the YAML file into effect. Did you do that?

---

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [January 27, 2020, 9:14am UTC](https://discuss.elastic.co/t/creating-watcher-and-trigger-alert-from-outlook-365/216510/5 "2020-01-27T09:14:24Z")

</div>

Hello @spinscale,

Thankyou for the response  
Please find the snapshot of the config

![image](https://us1.discourse-cdn.com/elastic/original/3X/7/8/78c6d361968de33ab31a6e0bd98fda177729d7f8.png)

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [January 27, 2020, 10:50am UTC](https://discuss.elastic.co/t/creating-watcher-and-trigger-alert-from-outlook-365/216510/6 "2020-01-27T10:50:45Z")

</div>

your error message mentions however a `gmail_account` - is it possible that your watch action refers to a different account?

---

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [January 27, 2020, 12:57pm UTC](https://discuss.elastic.co/t/creating-watcher-and-trigger-alert-from-outlook-365/216510/7 "2020-01-27T12:57:24Z")

</div>

Hello @spinscale,  
How to make changes then  
What should be done?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [January 27, 2020, 2:38pm UTC](https://discuss.elastic.co/t/creating-watcher-and-trigger-alert-from-outlook-365/216510/8 "2020-01-27T14:38:06Z")

</div>

Have you checked your watch action, that sends am email? Can you share that one?

---

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [January 28, 2020, 4:45am UTC](https://discuss.elastic.co/t/creating-watcher-and-trigger-alert-from-outlook-365/216510/9 "2020-01-28T04:45:59Z")

</div>

Hello @spinscale,

My watcher action is coming out OK

{  
"watch\_id": "3b854c7e-f3ef-44d9-94f5-5fb9e3e661e7",  
"node": "HQQ24uQGRnalcc1RPfPEBw",  
"state": "execution\_not\_needed",  
"status": {  
"state": {  
"active": true,  
"timestamp": "2020-01-28T04:45:00.498Z"  
},  
"last\_checked": "2020-01-28T04:46:00.654Z",  
"actions": {  
"email\_1": {  
"ack": {  
"timestamp": "2020-01-28T04:45:00.498Z",  
"state": "awaits\_successful\_execution"  
}  
}  
},  
"execution\_state": "execution\_not\_needed",  
"version": -1  
},  
"trigger\_event": {  
"type": "schedule",  
"triggered\_time": "2020-01-28T04:46:00.653Z",  
"schedule": {  
"scheduled\_time": "2020-01-28T04:46:00.504Z"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"hello1"  
],  
"rest\_total\_hits\_as\_int": true,  
"body": {  
"size": 0,  
"query": {  
"bool": {  
"filter": {  
"range": {  
"@timestamp": {  
"gte": "{{ctx.trigger.scheduled\_time}}||-5d",  
"lte": "{{ctx.trigger.scheduled\_time}}",  
"format": "strict\_date\_optional\_time||epoch\_millis"  
}  
}  
}  
}  
}  
}  
}  
}  
},  
"condition": {  
"script": {  
"source": "if (ctx.payload.hits.total \> params.threshold) { return true; } return false;",  
"lang": "painless",  
"params": {  
"threshold": 1000  
}  
}  
},  
"metadata": {  
"name": "test",  
"watcherui": {  
"trigger\_interval\_unit": "m",  
"agg\_type": "count",  
"time\_field": "@timestamp",  
"trigger\_interval\_size": 1,  
"term\_size": 5,  
"time\_window\_unit": "d",  
"threshold\_comparator": "\>",  
"index": [  
"hello1"  
],  
"time\_window\_size": 5,  
"threshold": 1000  
},  
"xpack": {  
"type": "threshold"  
}  
},  
"result": {  
"execution\_time": "2020-01-28T04:46:00.654Z",  
"execution\_duration": 15,  
"input": {  
"type": "search",  
"status": "success",  
"payload": {  
"\_shards": {  
"total": 1,  
"failed": 0,  
"successful": 1,  
"skipped": 0  
},  
"hits": {  
"hits": ,  
"total": 303,  
"max\_score": null  
},  
"took": 1,  
"timed\_out": false  
},  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"hello1"  
],  
"rest\_total\_hits\_as\_int": true,  
"body": {  
"size": 0,  
"query": {  
"bool": {  
"filter": {  
"range": {  
"@timestamp": {  
"gte": "2020-01-28T04:46:00.504Z||-5d",  
"lte": "2020-01-28T04:46:00.504Z",  
"format": "strict\_date\_optional\_time||epoch\_millis"  
}  
}  
}  
}  
}  
}  
}  
}  
},  
"condition": {  
"type": "script",  
"status": "success",  
"met": false  
},  
"actions":   
},  
"messages":   
}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [January 28, 2020, 11:54am UTC](https://discuss.elastic.co/t/creating-watcher-and-trigger-alert-from-outlook-365/216510/10 "2020-01-28T11:54:34Z")

</div>

please format your answers using markdown and code snippets. This is super hard to read. Thanks!

That watch condition was not true, so no email was triggered. That is no proof that email does not work as expected.

You can use the [execute watch API](https://www.elastic.co/guide/en/elasticsearch/reference/7.5/watcher-api-execute-watch.html) and ignore the condition to trigger the email sending and then paste that output here.

---

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [January 28, 2020, 12:07pm UTC](https://discuss.elastic.co/t/creating-watcher-and-trigger-alert-from-outlook-365/216510/11 "2020-01-28T12:07:20Z")

</div>

Hello @spinscale when I am trying to test it  
still it is not sending me the test email

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [January 28, 2020, 2:14pm UTC](https://discuss.elastic.co/t/creating-watcher-and-trigger-alert-from-outlook-365/216510/12 "2020-01-28T14:14:41Z")

</div>

If you do not share results and outputs of APIs, then it is impossible to help you. I asked for a specific output above. Please paste the request you made and the response. Thx.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 25, 2020, 2:14pm UTC](https://discuss.elastic.co/t/creating-watcher-and-trigger-alert-from-outlook-365/216510/13 "2020-02-25T14:14:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
