# How can I check the status of an email from a watch

**URL:** <https://discuss.elastic.co/t/how-can-i-check-the-status-of-an-email-from-a-watch/179587>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [May 3, 2019, 9:06pm UTC](https://discuss.elastic.co/t/how-can-i-check-the-status-of-an-email-from-a-watch/179587 "2019-05-03T21:06:34Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![drivera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/drivera/32/39900_2.png) [@drivera](https://discuss.elastic.co/u/drivera)\
**Post date:** [May 3, 2019, 9:06pm UTC](https://discuss.elastic.co/t/how-can-i-check-the-status-of-an-email-from-a-watch/179587/1 "2019-05-03T21:06:34Z")

</div>

Running ES 5.6 .

Trying to setup the watch below but not receiving any email. How can I check the status of the email? I don't see anything in the logs. The watch is monitoring that the cluster is in a green state. Do you see anything wrong with the watch?

PUT \_xpack/watcher/watch/cluster\_health\_watch  
{  
"trigger" : {  
"schedule" : { "interval" : "10s" }  
},  
"input" : {  
"http" : {  
"request" : {  
"host" : "[master\_node](http://ist000225.esri.com/)",  
"port" : 9200,  
"path" : "/\_cluster/health"  
}  
}  
},  
"condition" : {  
"compare" : {  
"ctx.payload.status" : { "eq" : "green" }  
}  
},  
"actions" : {  
"send\_email" : {  
"email" : {  
"to" : "email\_address" "@[mydomain.com](http://mydomain.com/)",  
"subject" : "Cluster Status Warning",  
"body" : "Cluster status is GREEN"  
}  
}  
}  
}

my yml file looks like this:

cluster.name: istunixes  
node.name: \<master\_node\>  
path.conf: /etc/elasticsearch  
path.data: /data/elasticsearch  
path.repo: ["/mount/backups/esbackup"]  
#path.work: /tmp/elasticsearch  
path.logs: /var/log/elasticsearch  
#path.plugins: /usr/share/elasticsearch/plugins  
network.bind\_host: 0.0.0.0  
network.publish\_host: 0.0.0.0  
http.port: 9200  
http.cors.enabled: true  
http.cors.allow-origin: "/.\*/"  
http.cors.allow-methods: OPTIONS, HEAD, GET, POST, PUT, DELETE  
#action.disable\_delete\_all\_indices: true  
#bootstrap.mlockall: false  
#gateway.type: local  
discovery.zen.ping.unicast.hosts:  
action.auto\_create\_index: true  
#script.disable\_dynamic: True  
#shield.audit.enabled: true  
#shield.audit.outputs: logfile  
#shield.authc:

# realms:

# default:

# type: esusers

# order: 0

node.data: false  
node.master: true  
#node.size: none  
discovery.zen.minimum\_master\_nodes: 2  
#cluster.routing.allocation.cluster\_concurrent\_rebalance: 5  
#cluster.routing.allocation.cluster\_concurrent\_recoveries: 5  
#index.unassigned.node\_left.delayed\_timeout: 5m

# x pack settings

xpack.security.enabled: true  
xpack.monitoring.enabled: true  
xpack.graph.enabled: true  
xpack.watcher.enabled: true  
xpack.notification.email.account:  
exchange\_account:  
profile: outlook  
email\_defaults:  
from:   
smtp:  
auth: true  
starttls.enable: true  
host:   
port: 587  
user: xxxx  
password: xxxx

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [May 6, 2019, 7:50am UTC](https://discuss.elastic.co/t/how-can-i-check-the-status-of-an-email-from-a-watch/179587/2 "2019-05-06T07:50:21Z")

</div>

Hey,

please take the time to properly format your emails. You can use markdown here and it supports awesome code formatting. This will make it much easier for other to check out your code samples and also have correct indendation. Thank you.

Every watch execution creates a so-called history record which shows if any error has occured. You can either query the watch history or simply run the [Execute Watch API](https://www.elastic.co/guide/en/elasticsearch/reference/7.0/watcher-api-execute-watch.html). Then put the output into a pastebin and refer to it over here in order to take a further look.

I also highly encourage you to read [this blog post about watch debugging](https://www.elastic.co/blog/watching-the-watches-writing-debugging-and-testing-watches) as it will probably save you hours down the road debugging issues.

--Alex

---

<div class="post-metadata">

**Author:** ![drivera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/drivera/32/39900_2.png) [@drivera](https://discuss.elastic.co/u/drivera)\
**Post date:** [May 8, 2019, 4:56pm UTC](https://discuss.elastic.co/t/how-can-i-check-the-status-of-an-email-from-a-watch/179587/4 "2019-05-08T16:56:18Z")

</div>

Thank you Alexander, will fix my posts in the future. Here it the error I'm receiving when I try to send email

```
"execution_time": "2019-05-08T16:51:41.896Z",
"execution_duration": 2,
"input": {
  "type": "http",
  "status": "success",
  "payload": {
    "_headers": {
      "www-authenticate": [
        "Basic realm=\"security\" charset=\"UTF-8\""
      ],
      "content-length": [
        "399"
      ],
      "content-type": [
        "application/json; charset=UTF-8"
      ]
    },
    "error": {
      "root_cause": [
        {
          "type": "security_exception",
          "reason": "missing authentication token for REST request [/_cluster/health]",
          "header": {
            "WWW-Authenticate": "Basic realm=\"security\" charset=\"UTF-8\""
          }
        }
      ],
      "type": "security_exception",
      "reason": "missing authentication token for REST request [/_cluster/health]",
      "header": {
        "WWW-Authenticate": "Basic realm=\"security\" charset=\"UTF-8\""
      }
    },
    "_status_code": 401,
    "status": 401
  }, spaces
```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [May 9, 2019, 10:00am UTC](https://discuss.elastic.co/t/how-can-i-check-the-status-of-an-email-from-a-watch/179587/5 "2019-05-09T10:00:12Z")

</div>

Taking a look at the output, there is an error message telling you about a missing authentication token. In order to connect to the Elasticsearch node, you need to specify a username and a password.

---

<div class="post-metadata">

**Author:** ![drivera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/drivera/32/39900_2.png) [@drivera](https://discuss.elastic.co/u/drivera)\
**Post date:** [May 10, 2019, 5:29pm UTC](https://discuss.elastic.co/t/how-can-i-check-the-status-of-an-email-from-a-watch/179587/7 "2019-05-10T17:29:09Z")

</div>

```
    xpack.notification.email.account:
  exchange_account:
    profile: "my profile"
    email_defaults:
      from: "email account
    smtp:
      auth: true
      starttls.enable: true
      host: smtp.mydomain.com
      port: 25
      user: "email account"
      password: "password"

```

Resolved by changing my server and port information above. Thanks for your help. Better formatting, right? 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 7, 2019, 5:29pm UTC](https://discuss.elastic.co/t/how-can-i-check-the-status-of-an-email-from-a-watch/179587/8 "2019-06-07T17:29:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
