# Watcher alerts email issue

**URL:** <https://discuss.elastic.co/t/watcher-alerts-email-issue/212008>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [December 16, 2019, 1:00pm UTC](https://discuss.elastic.co/t/watcher-alerts-email-issue/212008 "2019-12-16T13:00:50Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![vishnuvardhan](https://avatars.discourse-cdn.com/v4/letter/v/50afbb/32.png) [@vishnuvardhan](https://discuss.elastic.co/u/vishnuvardhan)\
**Post date:** [December 16, 2019, 1:00pm UTC](https://discuss.elastic.co/t/watcher-alerts-email-issue/212008/1 "2019-12-16T13:00:50Z")

</div>

Hi,  
actually i created watcher alerts in my ml jobs anomaly score reaches above 70 but i am not getting email notification showing the socket timed out exception

how to resolve this issue ?

elasticsearch .yml watcher settings :  
xpack.notification.email.account:  
exchange\_account:  
profile: outlook  
email\_defaults:  
from: [mejari.vishnu.vardhan@domain.com](mailto:mejari.vishnu.vardhan@domain.com)  
smtp:  
auth: true  
starttls.enable: true  
host: [smtp.office365.com](http://smtp.office365.com)  
port: 587  
user: [mejari.vishnu.vardhan@domain.com](mailto:mejari.vishnu.vardhan@domain.com)

error in watcher :

{  
"watch\_id": "22bb41d4-09e5-4c86-81e6-f2f7aef2b402",  
"node": "Ewo-SXYbROyijWhkmirJPw",  
"state": "executed",  
"status": {  
"state": {  
"active": true,  
"timestamp": "2019-12-16T12:41:18.996Z"  
},  
"last\_checked": "2019-12-16T12:42:43.418Z",  
"last\_met\_condition": "2019-12-16T12:42:43.418Z",  
"actions": {  
"email\_1": {  
"ack": {  
"timestamp": "2019-12-16T12:41:18.996Z",  
"state": "awaits\_successful\_execution"  
},  
"last\_execution": {  
"timestamp": "2019-12-16T12:42:43.418Z",  
"successful": false,  
"reason": ""  
}  
}  
},  
"execution\_state": "executed",  
"version": -1  
},  
"trigger\_event": {  
"type": "schedule",  
"triggered\_time": "2019-12-16T12:42:43.417Z",  
"schedule": {  
"scheduled\_time": "2019-12-16T12:42:43.051Z"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
".ml-anomalies-_"  
],  
"rest\_total\_hits\_as\_int": true,  
"body": {  
"size": 0,  
"query": {  
"bool": {  
"filter": {  
"range": {  
"timestamp": {  
"gte": "{{ctx.trigger.scheduled\_time}}||-100d",  
"lte": "{{ctx.trigger.scheduled\_time}}",  
"format": "strict\_date\_optional\_time||epoch\_millis"  
}  
}  
}  
}  
},  
"aggs": {  
"metricAgg": {  
"max": {  
"field": "anomaly\_score"  
}  
}  
}  
}  
}  
}  
},  
"condition": {  
"script": {  
"source": "if (ctx.payload.aggregations.metricAgg.value \> params.threshold) { return true; } return false;",  
"lang": "painless",  
"params": {  
"threshold": 69  
}  
}  
},  
"metadata": {  
"name": "Alert\_watcher\_demo",  
"watcherui": {  
"trigger\_interval\_unit": "m",  
"agg\_type": "max",  
"time\_field": "timestamp",  
"trigger\_interval\_size": 1,  
"term\_size": 5,  
"time\_window\_unit": "d",  
"threshold\_comparator": "\>",  
"term\_field": null,  
"index": [  
".ml-anomalies-_"  
],  
"time\_window\_size": 100,  
"threshold": 69,  
"agg\_field": "anomaly\_score"  
},  
"xpack": {  
"type": "threshold"  
}  
},  
"result": {  
"execution\_time": "2019-12-16T12:42:43.418Z",  
"execution\_duration": 120227,  
"input": {  
"type": "search",  
"status": "success",  
"payload": {  
"\_shards": {  
"total": 1,  
"failed": 0,  
"successful": 1,  
"skipped": 0  
},  
"hits": {  
"hits": ,  
"total": 2231,  
"max\_score": null  
},  
"took": 21,  
"timed\_out": false,  
"aggregations": {  
"metricAgg": {  
"value": 93.91975  
}  
}  
},  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
".ml-anomalies-\*"  
],  
"rest\_total\_hits\_as\_int": true,  
"body": {  
"size": 0,  
"query": {  
"bool": {  
"filter": {  
"range": {  
"timestamp": {  
"gte": "2019-12-16T12:42:43.051Z||-100d",  
"lte": "2019-12-16T12:42:43.051Z",  
"format": "strict\_date\_optional\_time||epoch\_millis"  
}  
}  
}  
}  
},  
"aggs": {  
"metricAgg": {  
"max": {  
"field": "anomaly\_score"  
}  
}  
}  
}  
}  
}  
},  
"condition": {  
"type": "script",  
"status": "success",  
"met": true  
},  
"transform": {  
"type": "script",  
"status": "success",  
"payload": {  
"result": 93.91975  
}  
},  
"actions": [  
{  
"id": "email\_1",  
"type": "email",  
"status": "failure",  
"error": {  
"root\_cause": [  
{  
"type": "messaging\_exception",  
"reason": "failed to send email with subject [Watch [Alert\_watcher\_demo] has exceeded the threshold] via account [exchange\_account]"  
}  
],  
"type": "messaging\_exception",  
"reason": "failed to send email with subject [Watch [Alert\_watcher\_demo] has exceeded the threshold] via account [exchange\_account]",  
"caused\_by": {  
"type": "mail\_connect\_exception",  
"reason": "Couldn't connect to host, port: [smtp.office365.com](http://smtp.office365.com), 587; timeout 120000",  
"caused\_by": {  
"type": "socket\_timeout\_exception",  
"reason": "connect timed out"  
}  
}  
}  
}  
]  
},  
"messages":   
}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [December 16, 2019, 5:06pm UTC](https://discuss.elastic.co/t/watcher-alerts-email-issue/212008/2 "2019-12-16T17:06:47Z")

</div>

please take the time to properly format your messages. This forum supports markdown and thus code snippets, which will make configuration snippets or JSON much easier to read. Thanks!

> Couldn't connect to host, port: [smtp.office365.com](http://smtp.office365.com/), 587; timeout 120000

This means, that the office365 could not be connected to from the node which executed the watch, a data node, if you are using Elasticsearch 6 and above. Can you ensure that every data node can connect to the mailserver - which might mean asking your network administrator if there is a firewall issue.

---

<div class="post-metadata">

**Author:** ![vishnuvardhan](https://avatars.discourse-cdn.com/v4/letter/v/50afbb/32.png) [@vishnuvardhan](https://discuss.elastic.co/u/vishnuvardhan)\
**Post date:** [December 17, 2019, 2:19am UTC](https://discuss.elastic.co/t/watcher-alerts-email-issue/212008/3 "2019-12-17T02:19:09Z")

</div>

Hi ,  
In my cluster there 5 nodes { 2 master, 2 data ,1 ml ) shall i configure email on all the nodes right ?  
how to check firewall issue there or not ?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [December 17, 2019, 12:11pm UTC](https://discuss.elastic.co/t/watcher-alerts-email-issue/212008/4 "2019-12-17T12:11:54Z")

</div>

the easiest is to have the same configuration of all nodes.

regarding the firewall issue, please check my comment above about talking to your network administrator. You can help the administrator by trying to use telnet to connect to the SMTP server and see if that works.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 14, 2020, 12:12pm UTC](https://discuss.elastic.co/t/watcher-alerts-email-issue/212008/5 "2020-01-14T12:12:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
