# Slack notifications

**URL:** <https://discuss.elastic.co/t/slack-notifications/258104>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [December 9, 2020, 10:20am UTC](https://discuss.elastic.co/t/slack-notifications/258104 "2020-12-09T10:20:11Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![werner.fletcher](https://avatars.discourse-cdn.com/v4/letter/w/bb73d2/32.png) [@werner.fletcher](https://discuss.elastic.co/u/werner.fletcher)\
**Post date:** [December 9, 2020, 10:20am UTC](https://discuss.elastic.co/t/slack-notifications/258104/1 "2020-12-09T10:20:12Z")

</div>

Good day,

I am trying to set up Watcher Slack notifications, but I have some questions that your documentation are not clear on.

According to [this](https://www.elastic.co/guide/en/elasticsearch/reference/current/actions-slack.html#configuring-slack) article I am supposed to use the keystore tool to add the account name and URL to the keystore, but how do I go about using the keystore tool? The example shows:  
`bin/elasticsearch-keystore add xpack.notification.slack.account.monitoring.secure_url`

- Where and how do I run this command if our stack is in the cloud?
- What is the syntax of this command when adding a setting? Is it  
`bin/elasticsearch-keystore add xpack.notification.slack.account.monitoring.secure_url=https://hooks.slack.com/services/TOKEN` ?

After this is all done, how do I proceed from here to get the notifications to Slack? Your documentation states:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/0/e0f906db6db32ab48458dafa09a5ca2083f0786b.png)

Thank you.

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [December 9, 2020, 5:36pm UTC](https://discuss.elastic.co/t/slack-notifications/258104/2 "2020-12-09T17:36:55Z")

</div>

> [@werner.fletcher](#):
>
> ions, but I have some questions that your documentation are not clear on.

cc @Larry_Gregory would you happen to know about this?

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [December 9, 2020, 6:07pm UTC](https://discuss.elastic.co/t/slack-notifications/258104/3 "2020-12-09T18:07:53Z")

</div>

Hi @werner.fletcher,

Your Elasticsearch keystore settings can be managed in your Cloud Console under the `Security` submenu of your deployment:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/6/369c76638e2005f4cec7587c1ff3103dbf836a66.png)

The docs for this are located at [https://www.elastic.co/guide/en/cloud/current/ec-configuring-keystore.html](https://www.elastic.co/guide/en/cloud/current/ec-configuring-keystore.html)

---

<div class="post-metadata">

**Author:** ![werner.fletcher](https://avatars.discourse-cdn.com/v4/letter/w/bb73d2/32.png) [@werner.fletcher](https://discuss.elastic.co/u/werner.fletcher)\
**Post date:** [December 10, 2020, 6:43am UTC](https://discuss.elastic.co/t/slack-notifications/258104/4 "2020-12-10T06:43:38Z")

</div>

Hi Larry,

Thank you, I got it working. I do however have another question for you. The Slack alert does not want to display the message when I use:

```auto
{{ctx.payload.hits.hits.0._source.agent.message}}

```

It works for the email and I can see the message, but it's not displaying anything in Slack. Is there perhaps another way to extract the message so that I can display it in Slack?

Thank you.

---

<div class="post-metadata">

**Author:** ![werner.fletcher](https://avatars.discourse-cdn.com/v4/letter/w/bb73d2/32.png) [@werner.fletcher](https://discuss.elastic.co/u/werner.fletcher)\
**Post date:** [December 10, 2020, 6:50am UTC](https://discuss.elastic.co/t/slack-notifications/258104/5 "2020-12-10T06:50:47Z")

</div>

Please disregard the above post, I managed to figure out why it was not working, it had to be:

```auto
{{ctx.payload.hits.hits.0._source.message}}

```

You may close the ticket, thanks for your help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 7, 2021, 6:50am UTC](https://discuss.elastic.co/t/slack-notifications/258104/6 "2021-01-07T06:50:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
