ERROR - Kibana Canvas email Reporting via Watcher


My use case is to automate email report via Watcher from a kibana Canvas report.

ELK Stack => 7.14.0

I have already build a Canvas report. And from this same Canvas report I copied automatically generated Watcher context that help me to automate sending the report via e-mail as attachment.

Now when I Execute the Watcher simulator manually, It perfectly create the report and send it as a email attachment. All work to perfection. However, when the Watcher execute it on its own trigger interval It throws the following error.

"message":"[security_exception: [security_exception] Reason: unable to authenticate user [custom_reporting_user] for REST request [/_security/_authenticate]]: unable to authenticate user [custom_reporting_user] for REST request [/_security/_authenticate]"

See the full error here

[2021-08-12T11:51:10,908][ERROR][o.e.x.w.a.e.ExecutableEmailAction] [elastic.local] failed to execute action [b56bbc5e-ac3a-4387-8e0c-9b3fcdc9555d/email_admin]
org.elasticsearch.ElasticsearchException: Watch[b56bbc5e-ac3a-4387-8e0c-9b3fcdc9555d] reporting[Report.pdf] Error response when trying to trigger reporting generation host[], port[5601] method[POST], path[/api/reporting/generate/printablePdf], response[status=[401], headers=[[date: [Thu, 12 Aug 2021 15:50:24 GMT]], [content-length: [297]], [kbn-name: [elastic.local]], [keep-alive: [timeout=120]], [kbn-license-sig: [27cff87299da52c6010e984e859132fa22edda1a0b46a6e398763e8a3dea229f]], [x-content-type-options: [nosniff]], [referrer-policy: [no-referrer-when-downgrade]], [connection: [keep-alive]], [content-type: [application/json; charset=utf-8]], [cache-control: [private, no-cache, no-store, must-revalidate]]], body=[{"statusCode":401,"error":"Unauthorized","message":"[security_exception: [security_exception] Reason: unable to authenticate user [custom_reporting_user] for REST request [/_security/_authenticate]]: unable to authenticate user [custom_reporting_user] for REST request [/_security/_authenticate]"}]]
    at ~[x-pack-watcher-7.14.0.jar:7.14.0]
    at ~[x-pack-watcher-7.14.0.jar:7.14.0]
    at ~[x-pack-watcher-7.14.0.jar:7.14.0]
    at [x-pack-watcher-7.14.0.jar:7.14.0]
    at org.elasticsearch.xpack.core.watcher.actions.ActionWrapper.execute( [x-pack-core-7.14.0.jar:7.14.0]
    at org.elasticsearch.xpack.watcher.execution.ExecutionService.executeInner( [x-pack-watcher-7.14.0.jar:7.14.0]
    at org.elasticsearch.xpack.watcher.execution.ExecutionService.execute( [x-pack-watcher-7.14.0.jar:7.14.0]
    at org.elasticsearch.xpack.watcher.execution.ExecutionService.lambda$executeAsync$5( [x-pack-watcher-7.14.0.jar:7.14.0]
    at org.elasticsearch.xpack.watcher.execution.ExecutionService$ [x-pack-watcher-7.14.0.jar:7.14.0]
    at org.elasticsearch.common.util.concurrent.ThreadContext$ [elasticsearch-7.14.0.jar:7.14.0]
    at java.util.concurrent.ThreadPoolExecutor.runWorker( [?:?]
    at java.util.concurrent.ThreadPoolExecutor$ [?:?]
    at [?:?]

Watcher Rule

  "trigger": {
    "schedule": {
      "interval": "5m"
  "input": {
    "none": {}
  "condition": {
    "always": {}
  "actions": {
    "email_admin": {
      "email": {
        "profile": "standard",
        "attachments": {
          "Report.pdf": {
            "reporting": {
              "url": "",
              "retries": 40,
              "interval": "300s",
              "auth": {
                "basic": {
                  "username": "custom_reporting_user",
                  "password": "::es_encrypted::/2GcP+B+xxxxxxxxxxxxxxxxxx"
        "to": [
        "subject": "Report"

@spinscale If you are busy, not a hurry. If not, can you please help us to fix this issue. Thanks in advanced.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.