# ML watcher error

**URL:** <https://discuss.elastic.co/t/ml-watcher-error/202994>\
**Category:** Kibana\
**Tags:** elastic-stack-machine-learning\
**Created:** [October 10, 2019, 9:52am UTC](https://discuss.elastic.co/t/ml-watcher-error/202994 "2019-10-10T09:52:46Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![sonnydoza](https://avatars.discourse-cdn.com/v4/letter/s/b9bd4f/32.png) [@sonnydoza](https://discuss.elastic.co/u/sonnydoza)\
**Post date:** [October 10, 2019, 9:52am UTC](https://discuss.elastic.co/t/ml-watcher-error/202994/1 "2019-10-10T09:52:46Z")

</div>

Hiya,

I created a watcher for alerting when anomalies happens in a machine learning job, I also changed the action to alert through slack instead of mail. But when trying to simulate I get an error, I am still a noobie about this so I would really aprecciate your help.  
Version 7.2.0

The output when I simulate it:

```
 "actions": [
      {
        "id": "log",
        "type": "logging",
        "status": "failure",
        "error": {
          "root_cause": [
            {
              "type": "general_script_exception",
              "reason": "Error running com.github.mustachejava.codes.DefaultMustache@a569020"
            }
          ],
          "type": "general_script_exception",
          "reason": "Error running com.github.mustachejava.codes.DefaultMustache@a569020",
          "caused_by": {
            "type": "mustache_exception",
            "reason": "Failed to get value for ctx.payload.aggregations.bucket_results.top_bucket_hits.hits.hits.0._source.job_id @[query-template:1]",
            "caused_by": {
              "type": "mustache_exception",
              "reason": "0 @[query-template:1]",
              "caused_by": {
                "type": "index_out_of_bounds_exception",
                "reason": "0"
              }
            }
          }
        }
      },
      {
        "id": "slack_2",
        "type": "slack",
        "status": "failure",
        "error": {
          "root_cause": [
            {
              "type": "general_script_exception",
              "reason": "Error running com.github.mustachejava.codes.DefaultMustache@53983561"
            }
          ],
          "type": "general_script_exception",
          "reason": "Error running com.github.mustachejava.codes.DefaultMustache@53983561",
          "caused_by": {
            "type": "mustache_exception",
            "reason": "Failed to get value for ctx.payload.aggregations.bucket_results.top_bucket_hits.hits.hits.0._source.job_id @[query-template:11]",
            "caused_by": {
              "type": "mustache_exception",
              "reason": "0 @[query-template:11]",
              "caused_by": {
                "type": "index_out_of_bounds_exception",
                "reason": "0"
              }
            }
          }
        }
      }
    ]
  },
  "messages": []
}
```

---

<div class="post-metadata">

**Author:** ![sonnydoza](https://avatars.discourse-cdn.com/v4/letter/s/b9bd4f/32.png) [@sonnydoza](https://discuss.elastic.co/u/sonnydoza)\
**Post date:** [October 10, 2019, 9:58am UTC](https://discuss.elastic.co/t/ml-watcher-error/202994/2 "2019-10-10T09:58:36Z")

</div>

If info is needed about the watcher let me know what you wanna see because I can not post the whole watcher (it has more than 7000 characters)

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [October 10, 2019, 1:01pm UTC](https://discuss.elastic.co/t/ml-watcher-error/202994/3 "2019-10-10T13:01:32Z")

</div>

Hi @sonnydoza - just use an online [pastebin](https://pastebin.com) or [GitHub gist](https://gist.github.com/) or similar to post the full syntax of your watcher. Redact private info as necessary.

---

<div class="post-metadata">

**Author:** ![sonnydoza](https://avatars.discourse-cdn.com/v4/letter/s/b9bd4f/32.png) [@sonnydoza](https://discuss.elastic.co/u/sonnydoza)\
**Post date:** [October 10, 2019, 1:17pm UTC](https://discuss.elastic.co/t/ml-watcher-error/202994/4 "2019-10-10T13:17:30Z")

</div>

Thank you for the response Rich.

There it goes [https://gist.github.com/sonnydoza/1ee02261e051eeeee40a29e5a2f074ed](https://gist.github.com/sonnydoza/1ee02261e051eeeee40a29e5a2f074ed)

I created the watcher through the UI the only changes that I made are the actions to make it work with Slack and also the "size" in the body input.

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [October 10, 2019, 5:35pm UTC](https://discuss.elastic.co/t/ml-watcher-error/202994/5 "2019-10-10T17:35:20Z")

</div>

I just copied and ran your exact watch (except I took out the slack piece) and it ran just fine.

Copy the entire JSON from your watch, then go over to the DevTools console. In there, put the following:

```auto
POST _xpack/watcher/watch/_execute
{
  "watch" :  

<paste your entire watch JSON here>
}

```

and execute it (this is pretty much what the simulate does, but you don't need to formally define the watch first).

Do you still get the error?

---

<div class="post-metadata">

**Author:** ![sonnydoza](https://avatars.discourse-cdn.com/v4/letter/s/b9bd4f/32.png) [@sonnydoza](https://discuss.elastic.co/u/sonnydoza)\
**Post date:** [October 11, 2019, 8:12am UTC](https://discuss.elastic.co/t/ml-watcher-error/202994/6 "2019-10-11T08:12:15Z")

</div>

Good morning Rich.

I did run the watcher in the dev tools as you told me and it triggers the actions successfully and it sends the message to the slack channel.

Any idea why this happens?

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [October 11, 2019, 11:39am UTC](https://discuss.elastic.co/t/ml-watcher-error/202994/7 "2019-10-11T11:39:30Z")

</div>

So, given the information reported, it seems like you're all set - might have just been a fluke problem when you were trying to simulate it in the Watcher UI.

Let the watch run as scheduled and see if you occasionally get an alert notification if/when an anomaly occurs.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 8, 2019, 11:39am UTC](https://discuss.elastic.co/t/ml-watcher-error/202994/8 "2019-11-08T11:39:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
