# List/backup/restore watchers

**URL:** <https://discuss.elastic.co/t/list-backup-restore-watchers/123403>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [March 11, 2018, 1:49am UTC](https://discuss.elastic.co/t/list-backup-restore-watchers/123403 "2018-03-11T01:49:41Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [March 11, 2018, 1:49am UTC](https://discuss.elastic.co/t/list-backup-restore-watchers/123403/1 "2018-03-11T01:49:41Z")

</div>

I created several Watches via Kibana and after looking over at [Watcher APIs | Elasticsearch Reference [6.2] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/watcher-api.html)

I have following questions:

1. Is there a way to get list all watchers?
2. Is there a way to GET watcher (for backup purpose)?
3. Is there a way to PUT watcher (restore from backup)?

---

<div class="post-metadata">

**Author:** ![Bill\_McConaghy](https://avatars.discourse-cdn.com/v4/letter/b/ed655f/32.png) [@Bill\_McConaghy](https://discuss.elastic.co/u/Bill_McConaghy)\
**Post date:** [March 15, 2018, 7:49pm UTC](https://discuss.elastic.co/t/list-backup-restore-watchers/123403/2 "2018-03-15T19:49:52Z")

</div>

Sorry for the delay in response.

1. do a search against the .watches index
2. [https://www.elastic.co/guide/en/elasticsearch/reference/current/watcher-api-get-watch.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/watcher-api-get-watch.html)
3. [https://www.elastic.co/guide/en/elasticsearch/reference/current/watcher-api-put-watch.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/watcher-api-put-watch.html)

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 15, 2018, 9:12pm UTC](https://discuss.elastic.co/t/list-backup-restore-watchers/123403/3 "2018-03-15T21:12:02Z")

</div>

as the watches are just stored in an index. you can treat them as such.

You can run a snapshot operation against this index as well as a restore operation. You should however ensure that watcher is stopped when restoring and make sure the index does not exist, as the restore would fail otherwise. If you use monitoring, you might also disable monitoring for that time as it tries to store watches in the .watches index.

Hope that helps.

--Alex

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [April 10, 2018, 2:58pm UTC](https://discuss.elastic.co/t/list-backup-restore-watchers/123403/4 "2018-04-10T14:58:24Z")

</div>

@spinscale How do I stop Watcher/Monitoring?

---

<div class="post-metadata">

**Author:** ![Constantin07](https://avatars.discourse-cdn.com/v4/letter/c/df788c/32.png) [@Constantin07](https://discuss.elastic.co/u/Constantin07)\
**Post date:** [April 12, 2018, 9:35am UTC](https://discuss.elastic.co/t/list-backup-restore-watchers/123403/5 "2018-04-12T09:35:50Z")

</div>

Is there a way to stop or disable default watchers ?  
The GUI doesn't allow to do this.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 12, 2018, 2:23pm UTC](https://discuss.elastic.co/t/list-backup-restore-watchers/123403/6 "2018-04-12T14:23:53Z")

</div>

you can disable monitoring in the YAML configuration `xpack.monitoring.enabled: false`

After disabling you could either just delete these watches or [deactivate them](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/watcher-api-deactivate-watch.html)

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [April 12, 2018, 2:42pm UTC](https://discuss.elastic.co/t/list-backup-restore-watchers/123403/7 "2018-04-12T14:42:26Z")

</div>

@spinscale

I assume `xpack.monitoring.enabled` is part of `elasticsearch.yml` and therefor has to be propagated to all nodes in cluster, and after restore of `.watches` index, I'd toggle it back followed by another restart of all nodes, correct?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 12, 2018, 10:16pm UTC](https://discuss.elastic.co/t/list-backup-restore-watchers/123403/8 "2018-04-12T22:16:24Z")

</div>

@alexus I think my previous tip was wrong. It should be sufficient to stop watcher via the stop watch API and that's it.

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [April 13, 2018, 3:09am UTC](https://discuss.elastic.co/t/list-backup-restore-watchers/123403/9 "2018-04-13T03:09:38Z")

</div>

Per your latest suggestion, I tried to use [Stop API | Elasticsearch Reference [6.2] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/watcher-api-stop.html) followed by restoring `.watches` index from snapshot, yet gotten error:

```
# curl --silent --request POST --header 'Content-Type: application/json' "$ELASTICSEARCH_URI/_snapshot/repository-gcs/2018-04-10-all/_restore?wait_for_completion=true&pretty" --data '{"indices": ".watches"}'
{
  "error" : {
    "root_cause" : [
      {
        "type" : "snapshot_restore_exception",
        "reason" : "[repository-gcs:2018-04-10-all/KD9EAEDDT-a-NXvpefpYHQ] cannot restore index [.watches] because an open index with same name already exists in the cluster. Either close or delete the existing index or restore the index under a different name by providing a rename pattern and replacement name"
      }
    ],
    "type" : "snapshot_restore_exception",
    "reason" : "[repository-gcs:2018-04-10-all/KD9EAEDDT-a-NXvpefpYHQ] cannot restore index [.watches] because an open index with same name already exists in the cluster. Either close or delete the existing index or restore the index under a different name by providing a rename pattern and replacement name"
  },
  "status" : 500
}
#
```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 13, 2018, 6:34am UTC](https://discuss.elastic.co/t/list-backup-restore-watchers/123403/10 "2018-04-13T06:34:27Z")

</div>

I should not write messages at 11pm. What I meant is no need to fiddle with the monitoring configuration.

A restore operation still requires you to delete the existing index.

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [April 13, 2018, 4:28pm UTC](https://discuss.elastic.co/t/list-backup-restore-watchers/123403/11 "2018-04-13T16:28:45Z")

</div>

11pm is "almost" the most productive time of the day)

```
# curl --silent --request DELETE $ELASTICSEARCH_URI/.watches?pretty
{
  "error" : "This endpoint is not supported for DELETE on .watches index.",
  "status" : 400
}
#
```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 14, 2018, 9:44pm UTC](https://discuss.elastic.co/t/list-backup-restore-watchers/123403/12 "2018-04-14T21:44:33Z")

</div>

you can do a workaround here and specify `.watche*`, which will delete the watches index (but also all others matching that wildcard).

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 12, 2018, 9:44pm UTC](https://discuss.elastic.co/t/list-backup-restore-watchers/123403/13 "2018-05-12T21:44:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
