# Elastalert https post

**URL:** <https://discuss.elastic.co/t/elastalert-https-post/210242>\
**Category:** Elasticsearch\
**Created:** [December 2, 2019, 8:40pm UTC](https://discuss.elastic.co/t/elastalert-https-post/210242 "2019-12-02T20:40:46Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![JennS](https://avatars.discourse-cdn.com/v4/letter/j/b9e5f3/32.png) [@JennS](https://discuss.elastic.co/u/JennS)\
**Post date:** [December 2, 2019, 8:40pm UTC](https://discuss.elastic.co/t/elastalert-https-post/210242/1 "2019-12-02T20:40:46Z")

</div>

I have data going into Elastalert and I am getting email alerts. I am also trying to post to an https page and I keep getting this error `ERROR:root:Error while running alert http_post: Error posting HTTP Post alert: HTTPSConnectionPool(host='notify.ltnglobal.com', port=443): Max retries exceeded with url: / (Caused by SSLError(SSLError("bad handshake: Error([('SSL routines', 'tls_process_server_certificate', 'certificate verify failed')],)",),))`

No matter where I put the certificates. My rule looks like this:

> name: snmp data ingest pipeline down  
> type: flatline  
> index: snmplogger-\*  
> ca\_certs: /etc/ssl/certs/ca-bundle.pem  
> threshold: 500000
> 
> use\_count\_query: true  
> doc\_type: "doc"
> 
> realert:  
> hours: 12
> 
> threshold\_cur: 10
> 
> timeframe:  
> minutes: 15
> 
> alert:
> 
> - "email"
> - "post"
> 
> email:
> 
> - "[name@company.com](mailto:name@company.com)"  
> smtp\_host: "[imap.company.com](http://imap.company.com)"  
> from\_addr: "[name@company.com](mailto:name@company.com)"
> 
> post:  
> http\_post\_url: "[https://page.com](https://page.com)"  
> http\_post\_payload:  
> notification\_type: "SNMPtrap"  
> identifier: "hostname"  
> end\_date\_time: "2050-12-31 02:00:00"  
> description: "This is a test"  
> communication\_types: ["zendesk", "email", "noc\_notification"]  
> http\_post\_headers:  
> content-type: "application/json"  
> Authorization: "N6a777vFju"

The email part works but the post part does not.

Any ideas?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [December 3, 2019, 10:12am UTC](https://discuss.elastic.co/t/elastalert-https-post/210242/2 "2019-12-03T10:12:01Z")

</div>

As this is a not elastalert supported forum, but rather about Elasticsearch, you are probably find more people willing to help you out if you ask on more elastalert specific forums/github repos/whatever other means of support they might have.

Hope this helps!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 31, 2019, 10:12am UTC](https://discuss.elastic.co/t/elastalert-https-post/210242/3 "2019-12-31T10:12:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
