# Error 400 when creating Watcher with Slack action

**URL:** <https://discuss.elastic.co/t/error-400-when-creating-watcher-with-slack-action/51627>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [June 1, 2016, 10:24pm UTC](https://discuss.elastic.co/t/error-400-when-creating-watcher-with-slack-action/51627 "2016-06-01T22:24:44Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mike\_Wurtz](https://avatars.discourse-cdn.com/v4/letter/m/c0e974/32.png) [@Mike\_Wurtz](https://discuss.elastic.co/u/Mike_Wurtz)\
**Post date:** [June 1, 2016, 10:24pm UTC](https://discuss.elastic.co/t/error-400-when-creating-watcher-with-slack-action/51627/1 "2016-06-01T22:24:44Z")

</div>

ES 5.0 Alpha 3

I was able to create an alert like this in Alpha 1 and Alpha 2, but not any more.

This request:

```auto
    "notify-slack" : {
  "throttle_period" : "15m",
  "slack" : {
    "account" : "monitoring",
    "message" : {
      "from" : "ELK Stack",
      "to" : ["#elk"],
      "text" : "Watcher Alert Triggered!",
      "attachments" : [
        {
          "title" : "HSM_DISCONNECTED",
          "text" : "At least {{ctx.payload.hits.total}} events have just occurred...\n<https://10.40.10.118/goto/89d029848dee8f935740dd0314348654|ANALYZE THIS IN KIBANA>\n_Slack will only be notified every 15 minutes for this alert._",
          "color" : "danger"
        }
      ]
    }
  }
}

```

Is giving me this response:

```auto
{
  "error": {
    "root_cause": [
      {
        "type": "parse_exception",
        "reason": "could not parse [slack] action [prod_hsm_disconnected]. unknown slack account [monitoring]"
      }
    ],
    "type": "parse_exception",
    "reason": "could not parse [slack] action [prod_hsm_disconnected]. unknown slack account [monitoring]"
  },
  "status": 400
}

```

and I've verified this config is on my ES nodes:

```auto
xpack.notification.slack.service:
  account:
    monitoring:
      url: https://hooks.slack.com/services/webhookurl
      message_defaults:
        from: Watcher

```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 2, 2016, 11:35am UTC](https://discuss.elastic.co/t/error-400-when-creating-watcher-with-slack-action/51627/2 "2016-06-02T11:35:05Z")

</div>

Hey,

try `xpack.notification.slack:` instead of `xpack.notification.slack.service:`

--Alex

---

<div class="post-metadata">

**Author:** ![Mike\_Wurtz](https://avatars.discourse-cdn.com/v4/letter/m/c0e974/32.png) [@Mike\_Wurtz](https://discuss.elastic.co/u/Mike_Wurtz)\
**Post date:** [June 2, 2016, 11:28pm UTC](https://discuss.elastic.co/t/error-400-when-creating-watcher-with-slack-action/51627/3 "2016-06-02T23:28:10Z")

</div>

Done. Looks like I'm getting the same response:

```auto
{
  "error": {
    "root_cause": [
      {
        "type": "parse_exception",
        "reason": "could not parse [slack] action [prod_hsm_disconnected]. unknown slack account [monitoring]"
      }
    ],
    "type": "parse_exception",
    "reason": "could not parse [slack] action [prod_hsm_disconnected]. unknown slack account [monitoring]"
  },
  "status": 400
}

```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 6, 2016, 11:18am UTC](https://discuss.elastic.co/t/error-400-when-creating-watcher-with-slack-action/51627/4 "2016-06-06T11:18:48Z")

</div>

Hey,

just tested this locally and it works, so lets try to find the differences:

my `elasticsearch.yml`

```auto
xpack.notification.slack:
  account:
    monitoring:
      url: https://hooks.slack.com/services/MY_CREDS
      message_defaults:
        from: Watcher

```

the watch

```json
PUT _xpack/watcher/watch/my-watch
{
  "trigger": {
    "schedule": {
      "interval": "10s"
    }
  },
  "input": {
    "http": {
      "request": {
        "host": "localhost",
        "port": 9200,
        "path": "/_cluster/health"
      }
    }
  },
  "actions": {
    "logging": {
      "logging": {
        "text": "{{ctx}}"
      }
    },
    "notify-slack": {
      "slack": {
        "account": "monitoring",
        "message": {
          "from": "ELK Stack",
          "to": [
            "#watcher-test"
          ],
          "text": "Watcher Alert Triggered!",
          "attachments": [
            {
              "title": "HSM_DISCONNECTED",
              "text": "At least {{ctx.payload.hits.total}} events have just occurred...\n<https://10.40.10.118/goto/89d029848dee8f935740dd0314348654|ANALYZE THIS IN KIBANA>\n_Slack will only be notified every 15 minutes for this alert._",
              "color": "danger"
            }
          ]
        }
      }
    }
  }
}

```

Can you spot a difference?

--Alex

---

<div class="post-metadata">

**Author:** ![Mike\_Wurtz](https://avatars.discourse-cdn.com/v4/letter/m/c0e974/32.png) [@Mike\_Wurtz](https://discuss.elastic.co/u/Mike_Wurtz)\
**Post date:** [June 6, 2016, 7:50pm UTC](https://discuss.elastic.co/t/error-400-when-creating-watcher-with-slack-action/51627/5 "2016-06-06T19:50:01Z")

</div>

I'm unable to spot a difference.. I feel like the issue is where the "monitoring" account is suppose to be configured on the ES noes.. Is there a ES or Watcher API method that should expose the "monitoring" account that is configuerd for verification?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 7, 2016, 6:54am UTC](https://discuss.elastic.co/t/error-400-when-creating-watcher-with-slack-action/51627/6 "2016-06-07T06:54:06Z")

</div>

Hey,

can you upload your config file somewhere? Maybe it's just an indendation issue? Also is the monitoring account configured in all elasticsearch.yml config files?

--Alex

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 7, 2016, 7:17pm UTC](https://discuss.elastic.co/t/error-400-when-creating-watcher-with-slack-action/51627/8 "2016-06-07T19:17:48Z")

</div>

Hey,

the file still lists `xpack.notification.slack.service` instead of `xpack.notification.slack`?

looks good otherwise.

--Alex

---

<div class="post-metadata">

**Author:** ![Mike\_Wurtz](https://avatars.discourse-cdn.com/v4/letter/m/c0e974/32.png) [@Mike\_Wurtz](https://discuss.elastic.co/u/Mike_Wurtz)\
**Post date:** [June 7, 2016, 7:34pm UTC](https://discuss.elastic.co/t/error-400-when-creating-watcher-with-slack-action/51627/9 "2016-06-07T19:34:11Z")

</div>

Sorry, sent the yml from the wrong instance.. Please review this:

> **[Dropbox - Error](https://www.dropbox.com/s/6hgh0u7bwbboa1z/elasticsearch.yml?dl=0)**
>
> Dropbox is a free service that lets you bring your photos, docs, and videos anywhere and share them easily. Never email yourself a file again!

---

<div class="post-metadata">

**Author:** ![kiran\_karnam](https://avatars.discourse-cdn.com/v4/letter/k/46a35a/32.png) [@kiran\_karnam](https://discuss.elastic.co/u/kiran_karnam)\
**Post date:** [September 1, 2016, 8:44pm UTC](https://discuss.elastic.co/t/error-400-when-creating-watcher-with-slack-action/51627/10 "2016-09-01T20:44:18Z")

</div>

Hi,

Facing the same issue with elastic search 2.3.5 the logs say  
[watcher.actions.slack.service] default slack account set to [monitoring]

but when i do a put i see the following error  
{"error":{"root\_cause":[{"type":"parse\_exception","reason":"could not parse [slack] action [cluster\_health\_watch/null]. unknown slack account [monitoring]"}],"type":"parse\_exception","reason":"could not parse [slack] action [cluster\_health\_watch/null]. unknown slack account [monitoring]"},"status":400}

any clues what might be wrong?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 5, 2016, 3:50pm UTC](https://discuss.elastic.co/t/error-400-when-creating-watcher-with-slack-action/51627/11 "2016-09-05T15:50:42Z")

</div>

@kiran_karnam can you please create a new issue, including your configuration, your example watch and all error messages/ stack traces that you got. This issue is about elasticsearch 5.0 and we should not clutter it with 2.3.5 infos.

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:43pm UTC](https://discuss.elastic.co/t/error-400-when-creating-watcher-with-slack-action/51627/12 "2017-07-06T13:43:08Z")

</div>


