# Is there a repo of watches

**URL:** <https://discuss.elastic.co/t/is-there-a-repo-of-watches/56810>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [July 31, 2016, 2:28am UTC](https://discuss.elastic.co/t/is-there-a-repo-of-watches/56810 "2016-07-31T02:28:26Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![kartikvelastic](https://avatars.discourse-cdn.com/v4/letter/k/7ba0ec/32.png) [@kartikvelastic](https://discuss.elastic.co/u/kartikvelastic)\
**Post date:** [July 31, 2016, 2:28am UTC](https://discuss.elastic.co/t/is-there-a-repo-of-watches/56810/1 "2016-07-31T02:28:26Z")

</div>

or some sample/example watches, I am looking for something that sends an email when a httpd 404 occurs

I wrote this:  
[http://pastebin.com/XPAaYM8U](http://pastebin.com/XPAaYM8U)

This is what it looks like in Kibana:  
[http://pastebin.com/xw4eTi1N](http://pastebin.com/xw4eTi1N)

but have one question:  
Should sendmail be installed, started and enabled on all the nodes of the cluster

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 1, 2016, 2:31pm UTC](https://discuss.elastic.co/t/is-there-a-repo-of-watches/56810/2 "2016-08-01T14:31:55Z")

</div>

Hey,

you might want to check out our new Watcher Labs Series], which shows you some of those examples.

- [Creating your first alert](https://www.elastic.co/videos/watcher-lab-creating-your-first-alert)
- [Using aggregations in a watch](https://www.elastic.co/videos/watcher-lab-using-elasticsearch-aggregations-in-your-watch)
- [Creating Alerts with dynamic thresholds](https://www.elastic.co/videos/watcher-lab-creating-alerts-with-dynamic-threshold)

That said, you should get into a certain workflow state to easily test your watches:

1. First make sure, that you search actuallty returns any results. In this case this will likely fail, beacuse you have specified an index that does not exist (missing an asterisk at the end)
2. If that works, write up your watch, and store it
3. If that has worked, use the [execute watch api](https://www.elastic.co/guide/en/watcher/2.3/api-rest.html#api-rest-execute-watch) and check the output

In addition you can also use the execute watch api without persisting a watch, which should speed up development a lot.

Hope this helps.

--Alex

---

<div class="post-metadata">

**Author:** ![kartikvelastic](https://avatars.discourse-cdn.com/v4/letter/k/7ba0ec/32.png) [@kartikvelastic](https://discuss.elastic.co/u/kartikvelastic)\
**Post date:** [August 1, 2016, 9:36pm UTC](https://discuss.elastic.co/t/is-there-a-repo-of-watches/56810/3 "2016-08-01T21:36:08Z")

</div>

Well, even something as simple as this: [http://pastebin.com/hhNxSEvU](http://pastebin.com/hhNxSEvU)  
does not seem to work  
here's what I am "grepping": [http://pastebin.com/HKzDSuEs](http://pastebin.com/HKzDSuEs)

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 2, 2016, 6:18am UTC](https://discuss.elastic.co/t/is-there-a-repo-of-watches/56810/4 "2016-08-02T06:18:30Z")

</div>

Hey,

please reread my comment above and apply the workflow I laid out. If you want to dig into the problem, you need to understand why something fails. And this is why you need to use the execute watch API. I can see that your condition will never work, but it's not durable to post things into the forum, if you need to solve issues fast 🙂

Use the execute watch API, check the condition documentation and especially take your time to read the output of the execute watch API, which contains information about each step executed. If your condition never turns true, there might be an error with the condition.

Just adding pastebins of your watches wont help either, because in order to debug one always needs the watch as well as the response. Otherwise it is impossible for other folks to help. Writing a clear and concise problem statement is a hard thing, but you're making the life of everyone easier who reads your post and increase the likelyhood of getting help by tenfold.

--Alex

---

<div class="post-metadata">

**Author:** ![kartikvelastic](https://avatars.discourse-cdn.com/v4/letter/k/7ba0ec/32.png) [@kartikvelastic](https://discuss.elastic.co/u/kartikvelastic)\
**Post date:** [August 3, 2016, 10:13am UTC](https://discuss.elastic.co/t/is-there-a-repo-of-watches/56810/5 "2016-08-03T10:13:39Z")

</div>

So I copied verbatim(almost) from the ES website, still no go:  
[http://pastebin.com/xHC8iDrK](http://pastebin.com/xHC8iDrK)

---

<div class="post-metadata">

**Author:** ![kartikvelastic](https://avatars.discourse-cdn.com/v4/letter/k/7ba0ec/32.png) [@kartikvelastic](https://discuss.elastic.co/u/kartikvelastic)\
**Post date:** [August 3, 2016, 12:44pm UTC](https://discuss.elastic.co/t/is-there-a-repo-of-watches/56810/6 "2016-08-03T12:44:09Z")

</div>

I think I got it I was doing curl -XPUL to the kibana (neither a master nor a data node) host, doing it to a data node works. Thanks for all your efforts.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:43pm UTC](https://discuss.elastic.co/t/is-there-a-repo-of-watches/56810/7 "2017-07-06T13:43:56Z")

</div>


