# Invalid index name \[\_watcher\], must not start with '\_', '-', or '+'"

**URL:** <https://discuss.elastic.co/t/invalid-index-name-watcher-must-not-start-with-or/203930>\
**Category:** Elasticsearch\
**Created:** [October 16, 2019, 9:06pm UTC](https://discuss.elastic.co/t/invalid-index-name-watcher-must-not-start-with-or/203930 "2019-10-16T21:06:51Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mv007](https://avatars.discourse-cdn.com/v4/letter/m/bbce88/32.png) [@mv007](https://discuss.elastic.co/u/mv007)\
**Post date:** [October 16, 2019, 9:06pm UTC](https://discuss.elastic.co/t/invalid-index-name-watcher-must-not-start-with-or/203930/1 "2019-10-16T21:06:51Z")

</div>

Hello All,

I am a newbie in ELK and still learning it. I am planning to setup a watcher functionality.

Below is the watcher definition that i have written,

 ![Query_watcher_notworking](https://us1.discourse-cdn.com/elastic/original/3X/c/c/cc80c12121879e710b741a110d88a2799e81b1b9.png)

I have just followed the online document. However, I am not able to run this. It shows the below error

 ![Error_issue](https://us1.discourse-cdn.com/elastic/original/3X/6/b/6b5ac9435e16e8c6dc1ae368cea25f0921f86b93.png)

I followed similar post on this forum like : ["reason": "Invalid index name [\_watcher], must not start with '\_'",](https://discuss.elastic.co/t/reason-invalid-index-name--watcher-must-not-start-with--/68568/6)

However, I could not able to crack the solution. I am looking forward to the suggestion on what is wrong here.

Thank you

Sincerely,  
Maunil

---

<div class="post-metadata">

**Author:** ![Yogesh\_Gaikwad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yogesh_gaikwad/32/27025_2.png) [@Yogesh\_Gaikwad](https://discuss.elastic.co/u/Yogesh_Gaikwad)\
**Post date:** [October 16, 2019, 11:40pm UTC](https://discuss.elastic.co/t/invalid-index-name-watcher-must-not-start-with-or/203930/2 "2019-10-16T23:40:26Z")

</div>

Hi @mv007,

Looks like the instead of Watcher endpoint being handled by the rest controller, it is trying to create the index named `_watcher`. This is failing as the ES does not allow index names to start with `_`.  
By default the watcher is enabled and the service is started the request should be handled by rest controller but in your case the watcher seems to be disabled.

Could you please check if the watcher is enabled on your setup?  
You can check it by using the x-pack info API  
`GET _xpack?categories=features&pretty`

In the output you should see something like following:

```auto
"watcher" : {
      "available" : true,
      "enabled" : true
    }

```

if `enabled: false` then you will need to enable watcher by setting `xpack.watcher.enabled`.  
Note that by default it would have been enabled.

Also, would be good to know what version of Elasticsearch you are using, `elasticsearch.yml` config file and logs if there are any errors.

Hope this helps.

Regards,  
Yogesh Gaikwad

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 17, 2019, 5:27am UTC](https://discuss.elastic.co/t/invalid-index-name-watcher-must-not-start-with-or/203930/3 "2019-10-17T05:27:18Z")

</div>

I agree. My guess is that @mv007 did not install the standard version but another one like oss.

BTW @mv007 please don't post images of text as they are hard to read, may not display correctly for everyone, and are not searchable.

Instead, paste the text and format it with `</>` icon or pairs of triple backticks (```), and check the preview window to make sure it's properly formatted before posting it. This makes it more likely that your question will receive a useful answer.

---

<div class="post-metadata">

**Author:** ![mv007](https://avatars.discourse-cdn.com/v4/letter/m/bbce88/32.png) [@mv007](https://discuss.elastic.co/u/mv007)\
**Post date:** [November 6, 2019, 4:53pm UTC](https://discuss.elastic.co/t/invalid-index-name-watcher-must-not-start-with-or/203930/4 "2019-11-06T16:53:22Z")

</div>

Thank you for your response and sorry for the late reply. You were right, the watcher was disabled and using your suggestions, I enabled them. It is working now 🙂

Thank you

---

<div class="post-metadata">

**Author:** ![mv007](https://avatars.discourse-cdn.com/v4/letter/m/bbce88/32.png) [@mv007](https://discuss.elastic.co/u/mv007)\
**Post date:** [November 6, 2019, 4:54pm UTC](https://discuss.elastic.co/t/invalid-index-name-watcher-must-not-start-with-or/203930/5 "2019-11-06T16:54:11Z")

</div>

Thank you for your suggestion, and sorry for the late response. I will not post images.

Sincerely,  
MV

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 4, 2019, 4:54pm UTC](https://discuss.elastic.co/t/invalid-index-name-watcher-must-not-start-with-or/203930/6 "2019-12-04T16:54:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
