# How create watcher email alerts and elasticsearch.yml file settings

**URL:** <https://discuss.elastic.co/t/how-create-watcher-email-alerts-and-elasticsearch-yml-file-settings/206314>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [November 4, 2019, 2:00am UTC](https://discuss.elastic.co/t/how-create-watcher-email-alerts-and-elasticsearch-yml-file-settings/206314 "2019-11-04T02:00:50Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![vishnuvardhan](https://avatars.discourse-cdn.com/v4/letter/v/50afbb/32.png) [@vishnuvardhan](https://discuss.elastic.co/u/vishnuvardhan)\
**Post date:** [November 4, 2019, 2:00am UTC](https://discuss.elastic.co/t/how-create-watcher-email-alerts-and-elasticsearch-yml-file-settings/206314/1 "2019-11-04T02:00:50Z")

</div>

please share step by step configure watcher and elasticsearch.yml file settings and smtp mail configurations .

thanks in advance .

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 4, 2019, 10:11am UTC](https://discuss.elastic.co/t/how-create-watcher-email-alerts-and-elasticsearch-yml-file-settings/206314/2 "2019-11-04T10:11:22Z")

</div>

Please see the documentation about configuring email accounts at [https://www.elastic.co/guide/en/elasticsearch/reference/7.4/actions-email.html#configuring-email](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/actions-email.html#configuring-email)

If there are problems, please name concrete problems and we can try figure them out one-by-one.

---

<div class="post-metadata">

**Author:** ![vishnuvardhan](https://avatars.discourse-cdn.com/v4/letter/v/50afbb/32.png) [@vishnuvardhan](https://discuss.elastic.co/u/vishnuvardhan)\
**Post date:** [November 4, 2019, 11:57am UTC](https://discuss.elastic.co/t/how-create-watcher-email-alerts-and-elasticsearch-yml-file-settings/206314/3 "2019-11-04T11:57:34Z")

</div>

hi spinscale,

i configured outlook account email successfully . but when i crearte threshold alert in watcher . click on 'test on fire email ' it shows " Failed to send e-mail to [vishnuxxxx@outlook.com](mailto:vishnuxxxx@outlook.com)" please help what is the issue ?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 4, 2019, 1:36pm UTC](https://discuss.elastic.co/t/how-create-watcher-email-alerts-and-elasticsearch-yml-file-settings/206314/4 "2019-11-04T13:36:21Z")

</div>

Can you share the output of [execute watch API](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/watcher-api-execute-watch.html) for that particular watch?

---

<div class="post-metadata">

**Author:** ![vishnuvardhan](https://avatars.discourse-cdn.com/v4/letter/v/50afbb/32.png) [@vishnuvardhan](https://discuss.elastic.co/u/vishnuvardhan)\
**Post date:** [November 5, 2019, 2:46am UTC](https://discuss.elastic.co/t/how-create-watcher-email-alerts-and-elasticsearch-yml-file-settings/206314/5 "2019-11-05T02:46:25Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/2/8/28dc596e5650ea62a5750999ec1a1f597c11195c.png)

---

<div class="post-metadata">

**Author:** ![vishnuvardhan](https://avatars.discourse-cdn.com/v4/letter/v/50afbb/32.png) [@vishnuvardhan](https://discuss.elastic.co/u/vishnuvardhan)\
**Post date:** [November 5, 2019, 2:49am UTC](https://discuss.elastic.co/t/how-create-watcher-email-alerts-and-elasticsearch-yml-file-settings/206314/6 "2019-11-05T02:49:40Z")

</div>

i am trying to create threshold alert greater than 40000 send the mail .

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 5, 2019, 9:34am UTC](https://discuss.elastic.co/t/how-create-watcher-email-alerts-and-elasticsearch-yml-file-settings/206314/7 "2019-11-05T09:34:01Z")

</div>

Please use the console-tools and help to obtain the output of the execute watcher API as I mentioned in my last post. Unfortunately, screenshots are not helpful here.

Thank you!

---

<div class="post-metadata">

**Author:** ![vishnuvardhan](https://avatars.discourse-cdn.com/v4/letter/v/50afbb/32.png) [@vishnuvardhan](https://discuss.elastic.co/u/vishnuvardhan)\
**Post date:** [November 5, 2019, 11:52am UTC](https://discuss.elastic.co/t/how-create-watcher-email-alerts-and-elasticsearch-yml-file-settings/206314/8 "2019-11-05T11:52:42Z")

</div>

Hi Spin,  
after excution of my watcher get output error like this .  
...................................................................................................................  
{  
"watch\_id": "a84dc88d-9474-484b-84ff-19643d134f39",  
"node": "-eDQJ7UPTw-d0mHO0F3ZoA",  
"state": "executed",  
"status": {  
"state": {  
"active": true,  
"timestamp": "2019-11-05T01:54:17.823Z"  
},  
"last\_checked": "2019-11-05T03:04:54.137Z",  
"last\_met\_condition": "2019-11-05T03:04:54.137Z",  
"actions": {  
"email\_1": {  
"ack": {  
"timestamp": "2019-11-05T01:54:17.823Z",  
"state": "awaits\_successful\_execution"  
},  
"last\_execution": {  
"timestamp": "2019-11-05T03:04:54.137Z",  
"successful": false,  
"reason": ""  
}  
}  
},  
"execution\_state": "executed",  
"version": -1  
},  
"trigger\_event": {  
"type": "schedule",  
"triggered\_time": "2019-11-05T03:04:54.137Z",  
"schedule": {  
"scheduled\_time": "2019-11-05T03:04:54.064Z"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
".ml-anomalies-metricbeat\_outages\_ecs",  
"metricbeat-_"  
],  
"rest\_total\_hits\_as\_int": true,  
"body": {  
"size": 0,  
"query": {  
"bool": {  
"filter": {  
"range": {  
"timestamp": {  
"gte": "{{ctx.trigger.scheduled\_time}}||-180d",  
"lte": "{{ctx.trigger.scheduled\_time}}",  
"format": "strict\_date\_optional\_time||epoch\_millis"  
}  
}  
}  
}  
}  
}  
}  
}  
},  
"condition": {  
"script": {  
"source": "if (ctx.payload.hits.total \> params.threshold) { return true; } return false;",  
"lang": "painless",  
"params": {  
"threshold": 1000  
}  
}  
},  
"metadata": {  
"name": "testing",  
"watcherui": {  
"trigger\_interval\_unit": "m",  
"agg\_type": "count",  
"time\_field": "timestamp",  
"trigger\_interval\_size": 1,  
"term\_size": 5,  
"time\_window\_unit": "d",  
"threshold\_comparator": "\>",  
"term\_field": null,  
"index": [  
".ml-anomalies-metricbeat\_outages\_ecs",  
"metricbeat-_"  
],  
"time\_window\_size": 180,  
"threshold": 1000,  
"agg\_field": null  
},  
"xpack": {  
"type": "threshold"  
}  
},  
"result": {  
"execution\_time": "2019-11-05T03:04:54.137Z",  
"execution\_duration": 120179,  
"input": {  
"type": "search",  
"status": "success",  
"payload": {  
"\_shards": {  
"total": 5,  
"failed": 0,  
"successful": 5,  
"skipped": 0  
},  
"hits": {  
"hits": ,  
"total": 10000,  
"max\_score": null  
},  
"took": 1,  
"timed\_out": false  
},  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
".ml-anomalies-metricbeat\_outages\_ecs",  
"metricbeat-\*"  
],  
"rest\_total\_hits\_as\_int": true,  
"body": {  
"size": 0,  
"query": {  
"bool": {  
"filter": {  
"range": {  
"timestamp": {  
"gte": "2019-11-05T03:04:54.064Z||-180d",  
"lte": "2019-11-05T03:04:54.064Z",  
"format": "strict\_date\_optional\_time||epoch\_millis"  
}  
}  
}  
}  
}  
}  
}  
}  
},  
"condition": {  
"type": "script",  
"status": "success",  
"met": true  
},  
"transform": {  
"type": "script",  
"status": "success",  
"payload": {  
"result": 10000  
}  
},  
"actions": [  
{  
"id": "email\_1",  
"type": "email",  
"status": "failure",  
"error": {  
"root\_cause": [  
{  
"type": "messaging\_exception",  
"reason": "failed to send email with subject [Watch [testing] has exceeded the threshold] via account [gmail\_account]"  
}  
],  
"type": "messaging\_exception",  
"reason": "failed to send email with subject [Watch [testing] has exceeded the threshold] via account [gmail\_account]",  
"caused\_by": {  
"type": "messaging\_exception",  
"reason": "Exception reading response",  
"caused\_by": {  
"type": "socket\_timeout\_exception",  
"reason": "Read timed out"  
}  
}  
}  
}  
]  
},  
"messages":   
}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 5, 2019, 9:27pm UTC](https://discuss.elastic.co/t/how-create-watcher-email-alerts-and-elasticsearch-yml-file-settings/206314/9 "2019-11-05T21:27:53Z")

</div>

the interesting part is at the end, where the exception is listed, it seems that the email cannot be sent. Is it possible that you may have configured the wrong port to connect to your mailserver so that the TCP connection cannot be made?

--Alex

---

<div class="post-metadata">

**Author:** ![vishnuvardhan](https://avatars.discourse-cdn.com/v4/letter/v/50afbb/32.png) [@vishnuvardhan](https://discuss.elastic.co/u/vishnuvardhan)\
**Post date:** [November 6, 2019, 3:07am UTC](https://discuss.elastic.co/t/how-create-watcher-email-alerts-and-elasticsearch-yml-file-settings/206314/10 "2019-11-06T03:07:39Z")

</div>

Hi spin,  
please check the yml file and my below settings . i need to change anything on .yml file .. still same issue is there

(elasticsearch.yml file ):  
xpack.watcher.enabled: true  
xpack.notification.email.account:  
gmail\_account:  
profile: gmail  
smtp:  
auth: true  
starttls.enable: true  
host: [smtp.gmail.com](http://smtp.gmail.com)  
port: 587  
user: [mymail@gmail.com](mailto:mymail@gmail.com)  
pwd given in SMTP pwd:  
bin/elasticsearch-keystore add xpack.notification.email.account.gmail\_account.smtp.secure\_password  
smtp gmail connection also established:  
[root@localhost elasticsearch]# telnet [smtp.gmail.com](http://smtp.gmail.com) 587  
Trying 74.125.24.109...  
Connected to [smtp.gmail.com](http://smtp.gmail.com).  
Escape character is '^]'.  
...........................................

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 6, 2019, 8:59am UTC](https://discuss.elastic.co/t/how-create-watcher-email-alerts-and-elasticsearch-yml-file-settings/206314/11 "2019-11-06T08:59:41Z")

</div>

what Elasticsearch version are you on?

Also, can you put this somewhere (in a gist/pastebin) where the indentation does not get lost? Thank you!

---

<div class="post-metadata">

**Author:** ![vishnuvardhan](https://avatars.discourse-cdn.com/v4/letter/v/50afbb/32.png) [@vishnuvardhan](https://discuss.elastic.co/u/vishnuvardhan)\
**Post date:** [November 6, 2019, 9:15am UTC](https://discuss.elastic.co/t/how-create-watcher-email-alerts-and-elasticsearch-yml-file-settings/206314/12 "2019-11-06T09:15:57Z")

</div>

Hi spin,

elasticsearch 7.0 version using.. may i know the where the issue is there it is port or .yml file

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 6, 2019, 9:45am UTC](https://discuss.elastic.co/t/how-create-watcher-email-alerts-and-elasticsearch-yml-file-settings/206314/13 "2019-11-06T09:45:39Z")

</div>

sorry, but 7.0 is not a concrete version.

I just want to be sure that the configuration is correct, thus I asked for it. Even though it looks ok, indendation in YAML is always tricky and I want to rule that out first.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 4, 2019, 9:45am UTC](https://discuss.elastic.co/t/how-create-watcher-email-alerts-and-elasticsearch-yml-file-settings/206314/14 "2019-12-04T09:45:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
