# SSL Connection in watcher using Teams

**URL:** <https://discuss.elastic.co/t/ssl-connection-in-watcher-using-teams/250129>\
**Category:** Elastic Observability\
**Tags:** elastic-stack-alerting\
**Created:** [September 28, 2020, 6:18am UTC](https://discuss.elastic.co/t/ssl-connection-in-watcher-using-teams/250129 "2020-09-28T06:18:12Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kirtash](https://avatars.discourse-cdn.com/v4/letter/k/a8b319/32.png) [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Post date:** [September 28, 2020, 6:18am UTC](https://discuss.elastic.co/t/ssl-connection-in-watcher-using-teams/250129/1 "2020-09-28T06:18:12Z")

</div>

Good morning,

I'm using watcher to send messages using the application "TEAMS" connected by a webhook, but when if I execute the action run perfectly, but when it is fire I have the next message:

```auto

"actions": [
      {
        "id": "MS_Teams",
        "type": "webhook",
        "status": "failure",
        "error": {
          "root_cause": [
            {
              "type": "s_s_l_exception",
              "reason": "Connection reset"
            }
          ],
          "type": "s_s_l_exception",
          "reason": "Connection reset",
          "caused_by": {
            "type": "socket_exception",
            "reason": "Connection reset"
          },
          "suppressed": [
            {
              "type": "socket_exception",
              "reason": "Broken pipe"
            }
          ]
        }
      }
    ]

```

Thanks!!

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 28, 2020, 8:18am UTC](https://discuss.elastic.co/t/ssl-connection-in-watcher-using-teams/250129/2 "2020-09-28T08:18:22Z")

</div>

Have you imported SSL certs to make this work? If so, did you do this on all nodes?

Also, are all nodes allowed to connect to the teams endpoint? Or is there maybe a firewall stopping this.

Keep in mind that testing a watch via kibana or via the execute watch API might mean, that it is executed somewhere else, as if running in the background.

Hope that helps as a debugging start.

---

<div class="post-metadata">

**Author:** ![Kirtash](https://avatars.discourse-cdn.com/v4/letter/k/a8b319/32.png) [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Post date:** [September 28, 2020, 1:11pm UTC](https://discuss.elastic.co/t/ssl-connection-in-watcher-using-teams/250129/3 "2020-09-28T13:11:15Z")

</div>

Hi @spinscale,

First of all thanks for the answer 🙂 I don't know where I can configure it... When I make the next instruction to get the differents certificates (GET \_ssl/certificates) I get 2 PEMs + 1 internal certificate, but the node's certificate changes when I repeat the query....

```auto
    "path" : "node.crt",
    "format" : "PEM",
    "alias" : null,
    "subject_dn" : "CN=instance-0000000000.node.XXXX.cluster.local",
    "serial_number" : "YYYY",
    "has_private_key" : true,
    "expiry" : "2021-08-26T13:17:36.000Z"

-------

    "path" : "node.crt",
    "format" : "PEM",
    "alias" : null,
    "subject_dn" : "CN=instance-0000000004.node.XXXXX.cluster.local",
    "serial_number" : "YYYY",
    "has_private_key" : true,
    "expiry" : "2021-09-28T04:06:56.000Z"

```

Thanks!

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 28, 2020, 1:22pm UTC](https://discuss.elastic.co/t/ssl-connection-in-watcher-using-teams/250129/4 "2020-09-28T13:22:46Z")

</div>

Hm, that _might_ indicate, that you have a different setup on each of your nodes. Maybe go with curl on the commandline run this against each of your nodes and compare the output.

---

<div class="post-metadata">

**Author:** ![Kirtash](https://avatars.discourse-cdn.com/v4/letter/k/a8b319/32.png) [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Post date:** [September 28, 2020, 2:13pm UTC](https://discuss.elastic.co/t/ssl-connection-in-watcher-using-teams/250129/5 "2020-09-28T14:13:53Z")

</div>

These nodes are in elastic cloud, is possible get this information?

---

<div class="post-metadata">

**Author:** ![gkahn](https://avatars.discourse-cdn.com/v4/letter/g/5daacb/32.png) [@gkahn](https://discuss.elastic.co/u/gkahn)\
**Post date:** [November 20, 2020, 1:43pm UTC](https://discuss.elastic.co/t/ssl-connection-in-watcher-using-teams/250129/6 "2020-11-20T13:43:23Z")

</div>

We are having the same problems. Elastic cloud, watcher actions with webhook to teams. Sometimes it works, sometimes we get the broken pipe exception. Elastic (platinum) support so far failed to provide a feasible solution for this problem. Did you manage to get it to work somehow?

---

<div class="post-metadata">

**Author:** ![korben](https://avatars.discourse-cdn.com/v4/letter/k/c6cbf5/32.png) [@korben](https://discuss.elastic.co/u/korben)\
**Post date:** [July 8, 2021, 8:48am UTC](https://discuss.elastic.co/t/ssl-connection-in-watcher-using-teams/250129/7 "2021-07-08T08:48:18Z")

</div>

Our team had the same problem. Had to create a workaround by executing the watchers through a script. I'm still not 100% sure but I think the problem is with Teams. They sometimes fail to properly parse the webhook URL so I ended up manually prepending the schema whenever a MissingSchema exception was raised.

---

<div class="post-metadata">

**Author:** ![qianhong\_wu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/qianhong_wu/32/109691_2.png) [@qianhong\_wu](https://discuss.elastic.co/u/qianhong_wu)\
**Post date:** [August 16, 2022, 9:51am UTC](https://discuss.elastic.co/t/ssl-connection-in-watcher-using-teams/250129/8 "2022-08-16T09:51:15Z")

</div>

I also having the same problems. I guess that

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:14am UTC](https://discuss.elastic.co/t/ssl-connection-in-watcher-using-teams/250129/9 "2022-11-04T08:14:07Z")

</div>


