# Notify Slack action in watcher fails if message attachment contains actions

**URL:** <https://discuss.elastic.co/t/notify-slack-action-in-watcher-fails-if-message-attachment-contains-actions/148367>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [September 12, 2018, 6:09pm UTC](https://discuss.elastic.co/t/notify-slack-action-in-watcher-fails-if-message-attachment-contains-actions/148367 "2018-09-12T18:09:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![vicpav](https://avatars.discourse-cdn.com/v4/letter/v/9de053/32.png) [@vicpav](https://discuss.elastic.co/u/vicpav)\
**Post date:** [September 12, 2018, 6:09pm UTC](https://discuss.elastic.co/t/notify-slack-action-in-watcher-fails-if-message-attachment-contains-actions/148367/1 "2018-09-12T18:09:02Z")

</div>

Elastic cluster 6.3.2 is deployed to Elastic cloud.

While trying to animate the Slack notifications sent by our watchers I have updated the message to include a link button as per [Slack documentation](https://api.slack.com/docs/message-attachments#link_buttons) . As a result, the code looks like that

```auto
...
    "actions": {
        "notify-slack": {
            "throttle_period_in_millis": 600000,
            "slack": {
                "account": "monitoring",
                "message": {
                    "from": "watcher",
                    "to": [
                        "#slack-channel"
                    ],
                    "text": "Something bad has happened",
                    "attachments": [
                        {
                            "color": "danger",
                            "fallback": "During last 5 mins, something bad has happened - Server has reported {{ctx.payload.hits.total}} times for {{ctx.payload.aggregations.address_pairs_count.value}} route(s) that it is not working - Check service dashboard https://dashboard.server.com/?service=bla-bla-bla",
                            "pretext": "During last 5 mins, something bad has happened",
                            "title": "It is not working",
                            "text": "Server has reported *{{ctx.payload.hits.total}} times* for *{{ctx.payload.aggregations.address_pairs_count.value}} route(s)* that it is not working",
                            "mrkdwn_in": [
                                "text"
                            ],
                            "actions": [
                                {
                                    "type": "button",
                                    "text": "Service dashboard",
                                    "url": "https://dashboard.server.com/?service=bla-bla-bla"
                                }
                            ]
                        }
                    ]
                }
            }
        }
    }
}

```

Even though the code editor parsed the code fine and the watcher status is shown as "Ok", every attempt to open that watcher fails with the response `HTTP 400 (Bad Request)`

```auto
{"statusCode":400,"error":"Bad Request","message":"[parse_exception] failed to parse [slack] action [my-watcher/notify-slack]. failed to parse [message] field"}

```

Additional experiments have shown that the problem appears as soon as I add the "actions" array into message "attachments". My guess that the watcher is mixing up its own actions and the Slack message actions.

Did anybody see that before or knows a workaround? Any ideas are very much welcome!

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 14, 2018, 1:35pm UTC](https://discuss.elastic.co/t/notify-slack-action-in-watcher-fails-if-message-attachment-contains-actions/148367/2 "2018-09-14T13:35:36Z")

</div>

Hey,

unfortunately we have a strict parsing mechanism currently with slack messages, that is a bit behind the features the slack actions allow you to do. What this means is, that Slack at some point added a `type: button` field to their API, which we have not added to our watch parsing mechanism. This is the reason for the failure. If you omit the type field, everything should work - but of course you are missing the button in the slack message.

There is an issue for this already, see [https://github.com/elastic/elasticsearch/issues/31032](https://github.com/elastic/elasticsearch/issues/31032)

--Alex

---

<div class="post-metadata">

**Author:** ![vicpav](https://avatars.discourse-cdn.com/v4/letter/v/9de053/32.png) [@vicpav](https://discuss.elastic.co/u/vicpav)\
**Post date:** [September 17, 2018, 6:59am UTC](https://discuss.elastic.co/t/notify-slack-action-in-watcher-fails-if-message-attachment-contains-actions/148367/3 "2018-09-17T06:59:54Z")

</div>

Hi Alex,

Thank you for pointing out the GitHub issue! It did not occur to me to check the `elasticsearch` project.

I'll avoid using buttons for now until that issue is fixed.

Victor

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 15, 2018, 6:59am UTC](https://discuss.elastic.co/t/notify-slack-action-in-watcher-fails-if-message-attachment-contains-actions/148367/4 "2018-10-15T06:59:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
