# Sending e-mail with generated report fails

**URL:** <https://discuss.elastic.co/t/sending-e-mail-with-generated-report-fails/60263>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [September 12, 2016, 8:17am UTC](https://discuss.elastic.co/t/sending-e-mail-with-generated-report-fails/60263 "2016-09-12T08:17:11Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marten](https://avatars.discourse-cdn.com/v4/letter/m/4af34b/32.png) [@Marten](https://discuss.elastic.co/u/Marten)\
**Post date:** [September 12, 2016, 8:17am UTC](https://discuss.elastic.co/t/sending-e-mail-with-generated-report-fails/60263/1 "2016-09-12T08:17:11Z")

</div>

Hi there,

I'm trying to use the new Reporting feature in combination with Watcher on Elastic Cloud.  
I want to generate a report and e-mail it to a whitelisted e-mail address.  
The report is being generated, which takes about 2 minutes.  
Sending the report through e-mail generates an error:

watch\_id:daily\_report state:executed trigger\_event.type:schedule trigger\_event.triggered\_time:September 12th 2016, 10:01:33.865 trigger\_event.schedule.scheduled\_time:September 12th 2016, 10:01:33.864 messages: result.execution\_time:September 12th 2016, 10:01:33.865 result.execution\_duration:120,770 result.input.type:none result.input.status:success result.condition.type:always result.condition.status:success result.condition.met:true result.actions:{ "id": "email\_admin", "type": "email", "status": "failure", "reason": "Unable to get attachment of type [http] with id [Verkopen 2016.pdf] in watch [daily\_report] aborting watch execution" } \_id:daily\_report\_1-2016-09-12T08:01:33.865Z \_type:watch\_record \_index:.watch\_history-2016.09.12 \_score:1

Can somebody help me with this please?

Thanks,

Marten

---

<div class="post-metadata">

**Author:** ![Marten](https://avatars.discourse-cdn.com/v4/letter/m/4af34b/32.png) [@Marten](https://discuss.elastic.co/u/Marten)\
**Post date:** [September 12, 2016, 10:02am UTC](https://discuss.elastic.co/t/sending-e-mail-with-generated-report-fails/60263/2 "2016-09-12T10:02:09Z")

</div>

Did some additional testing and it seems to be a performance issue.  
With a 5 min interval, sometimes it sends an e-mail, sometimes it doesn't.  
Is there a setting in Watcher so I can delay the e-mail sending until the report generation is finished?

Marten

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 12, 2016, 10:04am UTC](https://discuss.elastic.co/t/sending-e-mail-with-generated-report-fails/60263/3 "2016-09-12T10:04:06Z")

</div>

Hey,

using the log-view you can check out the log files and there you should find a reason, why the watch could not be executed. A couple of possible reasons

1. An empty response body was returned, nothing to attach
2. The HTTP response status did no start with a `2`, so some error was likely returned
3. An exception occured when the content was downloaded

I will add some more information into that history message, so you dont need to take a look into the logs in the future.

--Alex

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 12, 2016, 10:06am UTC](https://discuss.elastic.co/t/sending-e-mail-with-generated-report-fails/60263/4 "2016-09-12T10:06:33Z")

</div>

Hey,

you replied faster than I did... what you can do is increasing the timeouts for the HTTP requests, see [https://www.elastic.co/guide/en/watcher/2.4/actions.html#webhook-action-attributes](https://www.elastic.co/guide/en/watcher/2.4/actions.html#webhook-action-attributes)

I assume the report generation takes longer than the timeout has been configured for the HTTP client (wild guess for now).

--Alex

---

<div class="post-metadata">

**Author:** ![Marten](https://avatars.discourse-cdn.com/v4/letter/m/4af34b/32.png) [@Marten](https://discuss.elastic.co/u/Marten)\
**Post date:** [September 12, 2016, 10:21am UTC](https://discuss.elastic.co/t/sending-e-mail-with-generated-report-fails/60263/5 "2016-09-12T10:21:36Z")

</div>

Hi Alex,

Thanks for your reply.  
I can find the timeout parm for webhooks, but I can't find a parm for setting e-mail action timeouts.  
Do you know an alternative?

Marten

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 12, 2016, 11:32am UTC](https://discuss.elastic.co/t/sending-e-mail-with-generated-report-fails/60263/6 "2016-09-12T11:32:11Z")

</div>

Hey,

sorry for not being clear here.

So, when you call a `http` attachment like this, inside of the attachment you just specify a `request` object, and this object can take the same parameters than the webhook, because we are using the same code internally. I hope this makes it more clear.

```auto
"actions" : {
  "email_admin" : {
    "email": {
      "to": "'John Doe <john.doe@example.com>'",
      "attachments" : {
        "my_report.pdf" : { 
          "http" : { 
            "content_type" : "application/pdf",
            "request" : {
              "HERE GO ALL THE WEBHOOK PARAMETERS",
              "url": "http://example.org/foo/my-report" 
            }
          }
        }
      }
    }
  }
}

```

Hope this clears it up. Otherwise feel free to ask further!

--Alex

---

<div class="post-metadata">

**Author:** ![Marten](https://avatars.discourse-cdn.com/v4/letter/m/4af34b/32.png) [@Marten](https://discuss.elastic.co/u/Marten)\
**Post date:** [September 12, 2016, 12:33pm UTC](https://discuss.elastic.co/t/sending-e-mail-with-generated-report-fails/60263/7 "2016-09-12T12:33:03Z")

</div>

Hi Alex,

Thanks for clarification.  
Unfortunately it doesn't solve the problem.  
I've put both timeouts to 300s but I don't always receive an e-mail.  
Generating the report takes about 2 mins.  
Only solution seems to be to reduce the number of visualisations on the report.

Marten

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 12, 2016, 12:53pm UTC](https://discuss.elastic.co/t/sending-e-mail-with-generated-report-fails/60263/8 "2016-09-12T12:53:08Z")

</div>

Hey,

have you checked the logs? Anything in there?

--Alex

---

<div class="post-metadata">

**Author:** ![Marten](https://avatars.discourse-cdn.com/v4/letter/m/4af34b/32.png) [@Marten](https://discuss.elastic.co/u/Marten)\
**Post date:** [September 12, 2016, 1:55pm UTC](https://discuss.elastic.co/t/sending-e-mail-with-generated-report-fails/60263/9 "2016-09-12T13:55:23Z")

</div>

I did, but it doesn't say much:

[2016-09-12 13:53:07,690][ERROR][watcher.actions.email.service.attachment] Error getting http response: [host[[7d783a40a428622c0ee62727f07cd1bd.eu-west-1.aws.found.io](http://7d783a40a428622c0ee62727f07cd1bd.eu-west-1.aws.found.io)], port[443], method[POST], path[/api/reporting/generate/dashboard/Verkopen-2016]: response status [502]

That's the only thing in the log regarding this report.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 12, 2016, 2:58pm UTC](https://discuss.elastic.co/t/sending-e-mail-with-generated-report-fails/60263/10 "2016-09-12T14:58:19Z")

</div>

Hey,

thats better than nothing as it shows that there is a 502 (bad gateway) status code returned by kibana or a proxy inbetween. I would like to get the Elastic Cloud team involved into this. Would you mind sending me some data via email (like the watch you setup and your email address you are using for cloud), so I can forward this to the cloud team.

My email address is $firstname.$lastname@elastic.co

--Alex

---

<div class="post-metadata">

**Author:** ![Marten](https://avatars.discourse-cdn.com/v4/letter/m/4af34b/32.png) [@Marten](https://discuss.elastic.co/u/Marten)\
**Post date:** [September 12, 2016, 3:09pm UTC](https://discuss.elastic.co/t/sending-e-mail-with-generated-report-fails/60263/11 "2016-09-12T15:09:10Z")

</div>

Sure, I'll send you a mail wih the details

---

<div class="post-metadata">

**Author:** ![alexbrasetvik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexbrasetvik/32/15538_2.png) [@alexbrasetvik](https://discuss.elastic.co/u/alexbrasetvik)\
**Post date:** [September 15, 2016, 5:39pm UTC](https://discuss.elastic.co/t/sending-e-mail-with-generated-report-fails/60263/12 "2016-09-15T17:39:45Z")

</div>

We've identified the root cause of this issue and are working on a fix.

---

<div class="post-metadata">

**Author:** ![Marten](https://avatars.discourse-cdn.com/v4/letter/m/4af34b/32.png) [@Marten](https://discuss.elastic.co/u/Marten)\
**Post date:** [September 16, 2016, 6:20am UTC](https://discuss.elastic.co/t/sending-e-mail-with-generated-report-fails/60263/13 "2016-09-16T06:20:27Z")

</div>

Thanks 15.09.2016, 19:50, "Alex Brasetvik" \<elastic@discoursemail.com\>:

> [alexbrasetvik](https://discuss.elastic.co/users/alexbrasetvik)
> 
> September 15
> 
> We've identified the root cause of this issue and are working on a fix.
> 
> * * *
> 
> [Visit Topic](https://discuss.elastic.co/t/sending-e-mail-with-generated-report-fails/60263/12) or reply to this email to respond.
> 
> To unsubscribe from these emails, [click here](https://discuss.elastic.co/email/unsubscribe/9262377b515487ea2b2dfe21631856a81eddd8169cba57c020c0484e6ed04ef2).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:42pm UTC](https://discuss.elastic.co/t/sending-e-mail-with-generated-report-fails/60263/14 "2017-07-06T13:42:52Z")

</div>


