# Proper Configuration for SMTP Email Action in Watcher?

**URL:** <https://discuss.elastic.co/t/proper-configuration-for-smtp-email-action-in-watcher/92114>\
**Category:** Elasticsearch\
**Created:** [July 6, 2017, 1:40pm UTC](https://discuss.elastic.co/t/proper-configuration-for-smtp-email-action-in-watcher/92114 "2017-07-06T13:40:13Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![ccampbell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ccampbell/32/15320_2.png) [@ccampbell](https://discuss.elastic.co/u/ccampbell)\
**Post date:** [July 6, 2017, 1:40pm UTC](https://discuss.elastic.co/t/proper-configuration-for-smtp-email-action-in-watcher/92114/1 "2017-07-06T13:40:13Z")

</div>

I've been digging through the forum and the X-Pack Documentation but can't seem to find the right configuration for Watcher to send email through an SMTP connection. The Watch is executing correctly, but it cannot seem to find my configured SMTP email account in the elasticsearch.yml file:

Watch Configuration:

```
 "actions": {
    "log": {
      "logging": {
        "level": "info",
        "text": "{{ctx.payload.hits.total}} 4634 events have occured in the logs:{{#ctx.payload.hits.hits}}{{_id}}:{{/ctx.payload.hits.hits}}"
      }
    },
    "send_email": {
      "email": {
        "profile": "standard",
        "to": [
          "ccampbell@convexitycapital.com"
        ],
        "subject": "Test Watch Notification",
        "body": {
          "text": "{{ctx.payload.hits.total}} 4634 events have occured in the logs:{{#ctx.payload.hits.hits}}{{_id}}:{{/ctx.payload.hits.hits}}"
        }
      }
    }
  },

```

Elasticsearch.yml - relevant configuration:

```
# ------------- XPack Settings
#
xpack.monitoring.enabled: false
xpack.security.enabled: false
#
xpack.notification.email: 
    default_account: smtp_account
    account: 
        smtp_account:
            profile: standard
            smtp:
                host: smtp.xxxx.com
                user: noc@xxxx.com
                from: ccampbell@xxxx.com

```

Elasticsearch is running on a Windows 2012 server, the SMTP server is an Exchange server, with no authentication requirements. The error in the Watch execution output is:

```
{
        "id": "send_email",
        "type": "email",
        "status": "failure",
        "reason": "IllegalArgumentException[no account found for name: [null]]"
}

```

What am I missing? I've tried adding a line '"account": "smtp\_account",' into the Watch, but then I get the error '"IllegalArgumentException[no account found for name: [smtp\_account]]"'

---

<div class="post-metadata">

**Author:** ![Charles.w](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/charles.w/32/15486_2.png) [@Charles.w](https://discuss.elastic.co/u/Charles.w)\
**Post date:** [July 6, 2017, 1:49pm UTC](https://discuss.elastic.co/t/proper-configuration-for-smtp-email-action-in-watcher/92114/2 "2017-07-06T13:49:14Z")

</div>

Hi,

It seems like your mail server didn't recognize the user you were using. Though no authentication is required to connect to your server, it might no accept to send mail from "dummy" / "unknown" users.

Do you observe the same behavior with an existing user on this server ?

Best regards,

Charles.w

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [July 6, 2017, 2:18pm UTC](https://discuss.elastic.co/t/proper-configuration-for-smtp-email-action-in-watcher/92114/3 "2017-07-06T14:18:04Z")

</div>

Hey,

did you restart your node (or more important, all the nodes in your cluster), after you did those changes to the YAML configuration file?

Can you paste the output of the following calls?

```auto
GET _cat/nodes

GET _nodes?filter_path=**.xpack.notification

```

Thanks!

--Alex

---

<div class="post-metadata">

**Author:** ![ccampbell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ccampbell/32/15320_2.png) [@ccampbell](https://discuss.elastic.co/u/ccampbell)\
**Post date:** [July 6, 2017, 6:13pm UTC](https://discuss.elastic.co/t/proper-configuration-for-smtp-email-action-in-watcher/92114/4 "2017-07-06T18:13:08Z")

</div>

I've only made the changes to one of the Elasticsearch nodes (WINES5-INFR) - that's the same node that I'm working in Kibana on and doing the Watch configuration on. Do I need to restart all 3 nodes ES instances?

GET \_cat/nodes

```
10.1.55.32 54 78 13 mdi - WINES6-INFR
10.1.55.33 49 71 98 mdi * VM-WINES7-INFR
10.1.55.31 9 61 14 mdi - WINES5-INFR

```

GET \_nodes?filter\_path=\*\*.xpack.notification

```
{
  "nodes": {
    "81rn8YPrSlOyNUzPEqsycg": {
      "settings": {
        "xpack": {
          "notification": {
            "email": {
              "account": {
                "smtp_account": {
                  "profile": "standard",
                  "smtp": {
                    "host": "smtp.xxxx.com",
                    "user": "noc@xxxx.com",
                    "from": "ccampbell@xxxx.com"
                  }
                }
              },
              "default_account": "smtp_account"
            }
          }
        }
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![ccampbell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ccampbell/32/15320_2.png) [@ccampbell](https://discuss.elastic.co/u/ccampbell)\
**Post date:** [July 6, 2017, 6:27pm UTC](https://discuss.elastic.co/t/proper-configuration-for-smtp-email-action-in-watcher/92114/5 "2017-07-06T18:27:03Z")

</div>

That actually is a user on the server - or at least it's a dummy user used by other services in our environment - a valid user name has never been a problem in previous SMTP configuration on our Exchange setup.

---

<div class="post-metadata">

**Author:** ![Charles.w](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/charles.w/32/15486_2.png) [@Charles.w](https://discuss.elastic.co/u/Charles.w)\
**Post date:** [July 6, 2017, 6:30pm UTC](https://discuss.elastic.co/t/proper-configuration-for-smtp-email-action-in-watcher/92114/6 "2017-07-06T18:30:45Z")

</div>

Ok, I was asking that because in the past I had issues with picky servers on this topic 😉

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [July 6, 2017, 8:23pm UTC](https://discuss.elastic.co/t/proper-configuration-for-smtp-email-action-in-watcher/92114/7 "2017-07-06T20:23:27Z")

</div>

Hey,

yes, that configuration has to be applied on all nodes. Watcher runs on the master node, so this is where the configuration has to exist.

You could have used the [cluster update settings API](https://www.elastic.co/guide/en/elasticsearch/reference/5.5/cluster-update-settings.html) to configure those settings dynamically, but then you have to make sure those settings are persistent, and they require some more time to look them up instead of just peeking into the configuration file.

Hope this helps!

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 3, 2017, 8:23pm UTC](https://discuss.elastic.co/t/proper-configuration-for-smtp-email-action-in-watcher/92114/8 "2017-08-03T20:23:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
