# Slack alert not triggering to particular channel

**URL:** <https://discuss.elastic.co/t/slack-alert-not-triggering-to-particular-channel/220970>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [February 26, 2020, 8:04am UTC](https://discuss.elastic.co/t/slack-alert-not-triggering-to-particular-channel/220970 "2020-02-26T08:04:20Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![mathur7vidit](https://avatars.discourse-cdn.com/v4/letter/m/d07c76/32.png) [@mathur7vidit](https://discuss.elastic.co/u/mathur7vidit)\
**Post date:** [February 26, 2020, 8:04am UTC](https://discuss.elastic.co/t/slack-alert-not-triggering-to-particular-channel/220970/1 "2020-02-26T08:04:20Z")

</div>

Team, we have slack integrated and we are using it for sending alerts to multiple slack channels. currently we created few new channels and slack alerts are not being received in those channels. same watcher is sending alerts to remaining other channels properly.  
Any clue on this part?

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [February 26, 2020, 5:15pm UTC](https://discuss.elastic.co/t/slack-alert-not-triggering-to-particular-channel/220970/2 "2020-02-26T17:15:23Z")

</div>

Which version of the Elastic stack are you running?

Do you have kibana logs from the time when these message should be sent?

---

<div class="post-metadata">

**Author:** ![mathur7vidit](https://avatars.discourse-cdn.com/v4/letter/m/d07c76/32.png) [@mathur7vidit](https://discuss.elastic.co/u/mathur7vidit)\
**Post date:** [February 27, 2020, 7:18am UTC](https://discuss.elastic.co/t/slack-alert-not-triggering-to-particular-channel/220970/3 "2020-02-27T07:18:51Z")

</div>

hi matt, its 7.4.2.. All my watcher alerts are working fine.. even i am able to send slack alerts to multiple slack channels together.. its just 2-3 specific channel which are not receiving these alerts... logs shows channel not found..  
adding to it, i am successfully able to send slack alerts to both public and private channels except those 2-3 channels

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [February 27, 2020, 4:28pm UTC](https://discuss.elastic.co/t/slack-alert-not-triggering-to-particular-channel/220970/4 "2020-02-27T16:28:24Z")

</div>

@mathur7vidit

Can you share your configuration?

---

<div class="post-metadata">

**Author:** ![mathur7vidit](https://avatars.discourse-cdn.com/v4/letter/m/d07c76/32.png) [@mathur7vidit](https://discuss.elastic.co/u/mathur7vidit)\
**Post date:** [February 27, 2020, 4:44pm UTC](https://discuss.elastic.co/t/slack-alert-not-triggering-to-particular-channel/220970/5 "2020-02-27T16:44:27Z")

</div>

{  
"trigger": {  
"schedule": {  
"interval": "1m"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"vpn-\*"  
],  
"rest\_total\_hits\_as\_int": true,  
"body": {  
"size": 1,  
"query": {  
"bool": {  
"must": ,  
"filter": [  
{  
"bool": {  
"filter": [  
{  
"bool": {  
"should": [  
{  
"match": {  
"Event ID": "globalprotectportal-auth-fail"  
}  
}  
],  
"minimum\_should\_match": 1  
}  
}  
]  
}  
},  
{  
"range": {  
"@timestamp": {  
"from": "now-1m",  
"to": "now"  
}  
}  
}  
],  
"should": ,  
"must\_not":   
}  
}  
}  
}  
}  
},  
"condition": {  
"compare": {  
"ctx.payload.hits.total": {  
"gte": 1  
}  
}  
},  
"actions": {  
"notify-slack": {  
"throttle\_period\_in\_millis": 300000,  
"slack": {  
"account": "team1",  
"message": {  
"to": [  
"@vidit.mathur",  
"siem-infosec-alerts"  
],  
"text": "{{ctx.payload.hits.hits.0.\_source.Device Name}}: {{ctx.payload.hits.hits.0.\_source.Description}}"  
}  
}  
},  
"send\_email": {  
"email": {  
"profile": "standard",  
"from": "[elk@xyz.com](mailto:elk@xyz.com)",  
"to": [  
"[vidit.mathur@xyz.com](mailto:vidit.mathur@xyz.com)"  
],  
"subject": "CF: VPN Login Failure Alert",  
"body": {  
"text": "{{ctx.payload.hits.hits.0.\_source.Device Name}}: {{ctx.payload.hits.hits.0.\_source.Description}}"  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [February 27, 2020, 5:16pm UTC](https://discuss.elastic.co/t/slack-alert-not-triggering-to-particular-channel/220970/6 "2020-02-27T17:16:01Z")

</div>

You config looks good.

Have you tried recreating the slack webhook?

---

<div class="post-metadata">

**Author:** ![mathur7vidit](https://avatars.discourse-cdn.com/v4/letter/m/d07c76/32.png) [@mathur7vidit](https://discuss.elastic.co/u/mathur7vidit)\
**Post date:** [February 27, 2020, 5:18pm UTC](https://discuss.elastic.co/t/slack-alert-not-triggering-to-particular-channel/220970/7 "2020-02-27T17:18:11Z")

</div>

you mean slack webhook which we place in elasticsearch.yml? we have 1 placed since long.. and currently we are already sending slack alerts to multiple channel. so i dont think we need to update slack webhook url

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [February 27, 2020, 5:21pm UTC](https://discuss.elastic.co/t/slack-alert-not-triggering-to-particular-channel/220970/8 "2020-02-27T17:21:11Z")

</div>

Its possible that its a permissions issue with the slack api. Perhaps the existing webhook had permission to post to the previous set of channels but not the new channels.

---

<div class="post-metadata">

**Author:** ![mathur7vidit](https://avatars.discourse-cdn.com/v4/letter/m/d07c76/32.png) [@mathur7vidit](https://discuss.elastic.co/u/mathur7vidit)\
**Post date:** [February 27, 2020, 5:29pm UTC](https://discuss.elastic.co/t/slack-alert-not-triggering-to-particular-channel/220970/9 "2020-02-27T17:29:03Z")

</div>

yes.. i am suspecting the same.. any idea on how it can be fixed or do we again need to create new webhook?

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [March 3, 2020, 3:32pm UTC](https://discuss.elastic.co/t/slack-alert-not-triggering-to-particular-channel/220970/10 "2020-03-03T15:32:18Z")

</div>

I might be overlooking it, but I don't see a way to edit a slack webhook. I think you need to create a new one.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 12, 2020, 10:10am UTC](https://discuss.elastic.co/t/slack-alert-not-triggering-to-particular-channel/220970/11 "2020-03-12T10:10:57Z")

</div>

You can check the watcher history or run the [Execute Watch API](https://www.elastic.co/guide/en/elasticsearch/reference/7.6/watcher-api-execute-watch.html) and share that output to see, what the HTTP call to slack has returned. This should ease debugging a bit.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 9, 2020, 10:11am UTC](https://discuss.elastic.co/t/slack-alert-not-triggering-to-particular-channel/220970/12 "2020-04-09T10:11:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
