# Email notification for Alerting/reporting

**URL:** <https://discuss.elastic.co/t/email-notification-for-alerting-reporting/150758>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-reporting\
**Created:** [October 2, 2018, 8:00pm UTC](https://discuss.elastic.co/t/email-notification-for-alerting-reporting/150758 "2018-10-02T20:00:40Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![lcui\_dxc](https://avatars.discourse-cdn.com/v4/letter/l/8edcca/32.png) [@lcui\_dxc](https://discuss.elastic.co/u/lcui_dxc)\
**Post date:** [October 2, 2018, 8:00pm UTC](https://discuss.elastic.co/t/email-notification-for-alerting-reporting/150758/1 "2018-10-02T20:00:40Z")

</div>

Hello there,

I need to set up the email notification for watchers/alerts and reporting with x-pack on AWS cloud.

I read the docs below:

[https://www.elastic.co/guide/en/elastic-stack-overview/6.3/actions-email.html#amazon-ses](https://www.elastic.co/guide/en/elastic-stack-overview/6.3/actions-email.html#amazon-ses)

And set up the email notification account in elasticsearch.yml as below:

xpack.notification.email.account:  
ses\_account:  
smtp:  
auth: true  
starttls.enable: true  
starttls.required: true  
host: [email-smtp.us-east-1.amazonaws.com](http://email-smtp.us-east-1.amazonaws.com)  
port: 465  
user:   
password:

But I'm getting the following error in elasticsearch log:

===========================  
[2018-10-02T14:56:41,865][ERROR][o.e.x.w.a.e.ExecutableEmailAction] [hlsoelse1a-02] failed to execute action [efad0a6c-fc1a-4079-9448-5543a800a75a/email\_1]  
javax.mail.MessagingException: failed to send email with subject [Watch [MetricBeatFilesystemUsed] has exceeded the threshold] via account [ses\_account]  
...

# Caused by: com.sun.mail.util.MailConnectException: Couldn't connect to host, port: [email-smtp.us-east-1.amazonaws.com](http://email-smtp.us-east-1.amazonaws.com), 465; timeout 120000 ...........

I didn't set up the TLS on elasticsearch nodes yet...

Did I miss anything or anything incorrect?

Please help, thank you very much

Li

---

<div class="post-metadata">

**Author:** ![pjanzen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pjanzen/32/13756_2.png) [@pjanzen](https://discuss.elastic.co/u/pjanzen)\
**Post date:** [October 2, 2018, 8:18pm UTC](https://discuss.elastic.co/t/email-notification-for-alerting-reporting/150758/2 "2018-10-02T20:18:50Z")

</div>

Try setting the port to 25.

---

<div class="post-metadata">

**Author:** ![lcui\_dxc](https://avatars.discourse-cdn.com/v4/letter/l/8edcca/32.png) [@lcui\_dxc](https://discuss.elastic.co/u/lcui_dxc)\
**Post date:** [October 3, 2018, 7:37pm UTC](https://discuss.elastic.co/t/email-notification-for-alerting-reporting/150758/3 "2018-10-03T19:37:08Z")

</div>

I set the port to 25, the error messages are gone from the elasticsearch log, but still I don't receive any email notification from watcher/alerts. The Watchers show everything goes fine.

The execution output is like below and except to set up the smtp email account in elasticsearch.yml, is there anything else that I might be missing?

Please help.

{  
"watch\_id": "a724e8b2-3bd8-4c4c-b6bb-01b2548d77d4",  
"node": "HIzDm73kRKidQ4M1M20IgQ",  
"state": "execution\_not\_needed",  
"status": {  
"state": {  
"active": true,  
"timestamp": "2018-10-03T06:19:05.129Z"  
},  
"last\_checked": "2018-10-03T19:34:18.547Z",  
"actions": {  
"email\_1": {  
"ack": {  
"timestamp": "2018-10-03T06:19:05.129Z",  
"state": "awaits\_successful\_execution"  
}  
}  
},  
"execution\_state": "execution\_not\_needed",  
"version": -1  
},  
"trigger\_event": {  
"type": "schedule",  
"triggered\_time": "2018-10-03T19:34:18.547Z",  
"schedule": {  
"scheduled\_time": "2018-10-03T19:34:18.523Z"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"metricbeat-_"  
],  
"types": [],  
"body": {  
"size": 0,  
"query": {  
"bool": {  
"filter": {  
"range": {  
"@timestamp": {  
"gte": "{{ctx.trigger.scheduled\_time}}||-5m",  
"lte": "{{ctx.trigger.scheduled\_time}}",  
"format": "strict\_date\_optional\_time||epoch\_millis"  
}  
}  
}  
}  
},  
"aggs": {  
"metricAgg": {  
"max": {  
"field": "system.filesystem.used.pct"  
}  
}  
}  
}  
}  
}  
},  
"condition": {  
"script": {  
"source": "if (ctx.payload.aggregations.metricAgg.value \> params.threshold) { return true; } return false;",  
"lang": "painless",  
"params": {  
"threshold": 1  
}  
}  
},  
"metadata": {  
"name": "watcher-testing",  
"watcherui": {  
"trigger\_interval\_unit": "m",  
"agg\_type": "max",  
"time\_field": "@timestamp",  
"trigger\_interval\_size": 1,  
"term\_size": 5,  
"time\_window\_unit": "m",  
"threshold\_comparator": "\>",  
"term\_field": null,  
"index": [  
"metricbeat-_"  
],  
"time\_window\_size": 5,  
"threshold": 1,  
"agg\_field": "system.filesystem.used.pct"  
},  
"xpack": {  
"type": "threshold"  
}  
},  
"result": {  
"execution\_time": "2018-10-03T19:34:18.547Z",  
"execution\_duration": 7,  
"input": {  
"type": "search",  
"status": "success",  
"payload": {  
"\_shards": {  
"total": 42,  
"failed": 0,  
"successful": 42,  
"skipped": 0  
},  
"hits": {  
"hits": [],  
"total": 13498,  
"max\_score": 0  
},  
"took": 6,  
"timed\_out": false,  
"aggregations": {  
"metricAgg": {  
"value": 0.9520000000000001  
}  
}  
},  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"metricbeat-\*"  
],  
"types": [],  
"body": {  
"size": 0,  
"query": {  
"bool": {  
"filter": {  
"range": {  
"@timestamp": {  
"gte": "2018-10-03T19:34:18.523Z||-5m",  
"lte": "2018-10-03T19:34:18.523Z",  
"format": "strict\_date\_optional\_time||epoch\_millis"  
}  
}  
}  
}  
},  
"aggs": {  
"metricAgg": {  
"max": {  
"field": "system.filesystem.used.pct"  
}  
}  
}  
}  
}  
}  
},  
"condition": {  
"type": "script",  
"status": "success",  
"met": false  
},  
"actions": []  
},  
"messages": []  
}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 4, 2018, 6:23am UTC](https://discuss.elastic.co/t/email-notification-for-alerting-reporting/150758/4 "2018-10-04T06:23:21Z")

</div>

please take the time to properly format your messages using markdown, especially json snippets. those are pretty much impossible to read otherwise. Thanks a lot!

in your last pasted snippet the condition was not met, thus no action was triggered, see this output

```auto
"condition": {
"type": "script",
"status": "success",
"met": false
}

```

---

<div class="post-metadata">

**Author:** ![lcui\_dxc](https://avatars.discourse-cdn.com/v4/letter/l/8edcca/32.png) [@lcui\_dxc](https://discuss.elastic.co/u/lcui_dxc)\
**Post date:** [October 4, 2018, 10:53pm UTC](https://discuss.elastic.co/t/email-notification-for-alerting-reporting/150758/5 "2018-10-04T22:53:54Z")

</div>

Hello there,

Now the condition was met and the email was not sent out...

Please see the following and advise, thank you

* * *

{  
"watch\_id": "a724e8b2-3bd8-4c4c-b6bb-01b2548d77d4",  
"node": "PSBN9nLqQe62KJmr1-oRMw",  
"state": "executed",  
"status": {  
"state": {  
"active": true,  
"timestamp": "2018-10-04T22:42:24.066Z"  
},  
"last\_checked": "2018-10-04T22:50:00.348Z",  
"last\_met\_condition": "2018-10-04T22:50:00.348Z",  
"actions": {  
"email\_1": {  
"ack": {  
"timestamp": "2018-10-04T22:42:24.066Z",  
"state": "awaits\_successful\_execution"  
},  
"last\_execution": {  
"timestamp": "2018-10-04T22:50:00.348Z",  
"successful": false,  
"reason": ""  
}  
}  
},  
"execution\_state": "executed",  
"version": -1  
},  
"trigger\_event": {  
"type": "schedule",  
"triggered\_time": "2018-10-04T22:50:00.348Z",  
"schedule": {  
"scheduled\_time": "2018-10-04T22:50:00.323Z"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"metricbeat-_"  
],  
"types": [],  
"body": {  
"size": 0,  
"query": {  
"bool": {  
"filter": {  
"range": {  
"@timestamp": {  
"gte": "{{ctx.trigger.scheduled\_time}}||-5m",  
"lte": "{{ctx.trigger.scheduled\_time}}",  
"format": "strict\_date\_optional\_time||epoch\_millis"  
}  
}  
}  
}  
},  
"aggs": {  
"metricAgg": {  
"max": {  
"field": "system.filesystem.used.pct"  
}  
}  
}  
}  
}  
}  
},  
"condition": {  
"script": {  
"source": "if (ctx.payload.aggregations.metricAgg.value \> params.threshold) { return true; } return false;",  
"lang": "painless",  
"params": {  
"threshold": 0.3  
}  
}  
},  
"metadata": {  
"name": "watcher-testing",  
"watcherui": {  
"trigger\_interval\_unit": "m",  
"agg\_type": "max",  
"time\_field": "@timestamp",  
"trigger\_interval\_size": 1,  
"term\_size": 5,  
"time\_window\_unit": "m",  
"threshold\_comparator": "\>",  
"term\_field": null,  
"index": [  
"metricbeat-_"  
],  
"time\_window\_size": 5,  
"threshold": 0.3,  
"agg\_field": "system.filesystem.used.pct"  
},  
"xpack": {  
"type": "threshold"  
}  
},  
"result": {  
"execution\_time": "2018-10-04T22:50:00.348Z",  
"execution\_duration": 120079,  
"input": {  
"type": "search",  
"status": "success",  
"payload": {  
"\_shards": {  
"total": 44,  
"failed": 0,  
"successful": 44,  
"skipped": 0  
},  
"hits": {  
"hits": [],  
"total": 19352,  
"max\_score": 0  
},  
"took": 5,  
"timed\_out": false,  
"aggregations": {  
"metricAgg": {  
"value": 0.988  
}  
}  
},  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"metricbeat-\*"  
],  
"types": [],  
"body": {  
"size": 0,  
"query": {  
"bool": {  
"filter": {  
"range": {  
"@timestamp": {  
"gte": "2018-10-04T22:50:00.323Z||-5m",  
"lte": "2018-10-04T22:50:00.323Z",  
"format": "strict\_date\_optional\_time||epoch\_millis"  
}  
}  
}  
}  
},  
"aggs": {  
"metricAgg": {  
"max": {  
"field": "system.filesystem.used.pct"  
}  
}  
}  
}  
}  
}  
},  
"condition": {  
"type": "script",  
"status": "success",  
"met": true  
},  
"transform": {  
"type": "script",  
"status": "success",  
"payload": {  
"result": 0.988  
}  
},  
"actions": [  
{  
"id": "email\_1",  
"type": "email",  
"status": "failure",  
"error": {  
"root\_cause": [  
{  
"type": "messaging\_exception",  
"reason": "failed to send email with subject [Watch [watcher-testing] has exceeded the threshold] via account [ses\_account]"  
}  
],  
"type": "messaging\_exception",  
"reason": "failed to send email with subject [Watch [watcher-testing] has exceeded the threshold] via account [ses\_account]",  
"caused\_by": {  
"type": "mail\_connect\_exception",  
"reason": "Couldn't connect to host, port: [email-smtp.us-east-1.amazonaws.com](http://email-smtp.us-east-1.amazonaws.com), 25; timeout 120000",  
"caused\_by": {  
"type": "socket\_timeout\_exception",  
"reason": "connect timed out"  
}  
}  
}  
}  
]  
},  
"messages": []  
}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 9, 2018, 1:47pm UTC](https://discuss.elastic.co/t/email-notification-for-alerting-reporting/150758/6 "2018-10-09T13:47:09Z")

</div>

please take the time to go through the JSON you provided, read and interpret it. You will see the following lines at the end

> [@lcui\_dxc](#):
>
> "type": "messaging\_exception",  
> "reason": "failed to send email with subject [Watch [watcher-testing] has exceeded the threshold] via account [ses\_account]",  
> "caused\_by": {  
> "type": "mail\_connect\_exception",  
> "reason": "Couldn't connect to host, port: [email-smtp.us-east-1.amazonaws.com](http://email-smtp.us-east-1.amazonaws.com), 25; timeout 120000",  
> "caused\_by": {  
> "type": "socket\_timeout\_exception",  
> "reason": "connect timed out"

This indicates that elasticsearch was not able to connect to the AWS infrastructure - potentially not being able to connect to it due to firewalls in between. Can you try to manually connect from the elasticsearch host to the amazon mailservers and see if that works?

---

<div class="post-metadata">

**Author:** ![lcui\_dxc](https://avatars.discourse-cdn.com/v4/letter/l/8edcca/32.png) [@lcui\_dxc](https://discuss.elastic.co/u/lcui_dxc)\
**Post date:** [October 9, 2018, 8:36pm UTC](https://discuss.elastic.co/t/email-notification-for-alerting-reporting/150758/7 "2018-10-09T20:36:57Z")

</div>

This one has been fixed, it is on AWS side... thanks a lot

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 6, 2018, 8:37pm UTC](https://discuss.elastic.co/t/email-notification-for-alerting-reporting/150758/8 "2018-11-06T20:37:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
