# Watcher and Microsoft Teams webhook

**URL:** <https://discuss.elastic.co/t/watcher-and-microsoft-teams-webhook/203189>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [October 11, 2019, 8:52am UTC](https://discuss.elastic.co/t/watcher-and-microsoft-teams-webhook/203189 "2019-10-11T08:52:54Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![wellerbar](https://avatars.discourse-cdn.com/v4/letter/w/a88e57/32.png) [@wellerbar](https://discuss.elastic.co/u/wellerbar)\
**Post date:** [October 11, 2019, 8:52am UTC](https://discuss.elastic.co/t/watcher-and-microsoft-teams-webhook/203189/1 "2019-10-11T08:52:54Z")

</div>

Hi there,

I would like to use watcher UI to send messages to a microsoft teams webhook.  
However, when I send a notification, on my firewall, I find "tcp-rst-from-server". I do not understand why.  
how could I fix this problem?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 11, 2019, 12:07pm UTC](https://discuss.elastic.co/t/watcher-and-microsoft-teams-webhook/203189/2 "2019-10-11T12:07:45Z")

</div>

Hey,

I do not know the exact error message from your firewall, but it looks either as if there is no service listening on that port or if your firewall is resetting the TCP connection making it look like there is no service listening.

Can you maybe try curl or another http client on the system you are running elasticsearch and see if you can reach the endpoint manually without invoking watcher?

--Alex

---

<div class="post-metadata">

**Author:** ![wellerbar](https://avatars.discourse-cdn.com/v4/letter/w/a88e57/32.png) [@wellerbar](https://discuss.elastic.co/u/wellerbar)\
**Post date:** [October 11, 2019, 12:24pm UTC](https://discuss.elastic.co/t/watcher-and-microsoft-teams-webhook/203189/3 "2019-10-11T12:24:52Z")

</div>

Hi,

Thank you for your quick answer!

I already tried to send a http post request with Posteman to the same webhook and it works fine.  
I tried curl and it returns me "Bad payload received by generic incoming webhook."

Lucas

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 11, 2019, 1:02pm UTC](https://discuss.elastic.co/t/watcher-and-microsoft-teams-webhook/203189/4 "2019-10-11T13:02:32Z")

</div>

running postman means you are not running that request from the host where elasticsearch is running?

can you share the output of the execute watch API for that watch?

---

<div class="post-metadata">

**Author:** ![wellerbar](https://avatars.discourse-cdn.com/v4/letter/w/a88e57/32.png) [@wellerbar](https://discuss.elastic.co/u/wellerbar)\
**Post date:** [October 11, 2019, 1:30pm UTC](https://discuss.elastic.co/t/watcher-and-microsoft-teams-webhook/203189/5 "2019-10-11T13:30:13Z")

</div>

I ran Postman on another host but the curl I ran was on the same host as the elasticsearch.

Here is the output of th execute watch API :

curl -X POST "IPaddress:9200/\_watcher/watch/MY\_WATCH/\_execute?pretty"  
{  
"\_id" : "MY\_WATCH",  
"watch\_record" : {  
"watch\_id" : "MY\_WATCH",  
"node" : "YD6L9JmOQh6tQPLkTa7bDQ",  
"state" : "executed",  
"status" : {  
"state" : {  
"active" : true,  
"timestamp" : "2019-10-11T13:19:31.808Z"  
},  
"last\_checked" : "2019-10-11T13:20:03.434Z",  
"last\_met\_condition" : "2019-10-11T13:20:03.434Z",  
"actions" : {  
"webhook\_1" : {  
"ack" : {  
"timestamp" : "2019-10-11T13:20:03.434Z",  
"state" : "ackable"  
},  
"last\_execution" : {  
"timestamp" : "2019-10-11T13:20:03.434Z",  
"successful" : true  
},  
"last\_successful\_execution" : {  
"timestamp" : "2019-10-11T13:20:03.434Z",  
"successful" : true  
}  
}  
},  
"execution\_state" : "executed",  
"version" : 410  
},  
"trigger\_event" : {  
"type" : "manual",  
"triggered\_time" : "2019-10-11T13:20:03.434Z",  
"manual" : {  
"schedule" : {  
"scheduled\_time" : "2019-10-11T13:20:03.434Z"  
}  
}  
},  
"input" : {  
"search" : {  
"request" : {  
"search\_type" : "query\_then\_fetch",  
"indices" : [  
"_"  
],  
"rest\_total\_hits\_as\_int" : true,  
"body" : {  
"size" : 0,  
"query" : {  
"bool" : {  
"filter" : {  
"range" : {  
"@timestamp" : {  
"gte" : "{{ctx.trigger.scheduled\_time}}||-5m",  
"lte" : "{{ctx.trigger.scheduled\_time}}",  
"format" : "strict\_date\_optional\_time||epoch\_millis"  
}  
}  
}  
}  
}  
}  
}  
}  
},  
"condition" : {  
"script" : {  
"source" : "if (ctx.payload.hits.total \> params.threshold) { return true; } return false;",  
"lang" : "painless",  
"params" : {  
"threshold" : 200  
}  
}  
},  
"metadata" : {  
"name" : "test",  
"watcherui" : {  
"trigger\_interval\_unit" : "m",  
"agg\_type" : "count",  
"time\_field" : "@timestamp",  
"trigger\_interval\_size" : 1,  
"term\_size" : 5,  
"time\_window\_unit" : "m",  
"threshold\_comparator" : "\>",  
"index" : [  
"_"  
],  
"time\_window\_size" : 5,  
"threshold" : 200  
},  
"xpack" : {  
"type" : "threshold"  
}  
},  
"result" : {  
"execution\_time" : "2019-10-11T13:20:03.434Z",  
"execution\_duration" : 442,  
"input" : {  
"type" : "search",  
"status" : "success",  
"payload" : {  
"\_shards" : {  
"total" : 43,  
"failed" : 0,  
"successful" : 43,  
"skipped" : 0  
},  
"hits" : {  
"hits" : ,  
"total" : 3606,  
"max\_score" : null  
},  
"took" : 424,  
"timed\_out" : false  
},  
"search" : {  
"request" : {  
"search\_type" : "query\_then\_fetch",  
"indices" : [  
"\*"  
],  
"rest\_total\_hits\_as\_int" : true,  
"body" : {  
"size" : 0,  
"query" : {  
"bool" : {  
"filter" : {  
"range" : {  
"@timestamp" : {  
"gte" : "2019-10-11T13:20:03.434255Z||-5m",  
"lte" : "2019-10-11T13:20:03.434255Z",  
"format" : "strict\_date\_optional\_time||epoch\_millis"  
}  
}  
}  
}  
}  
}  
}  
}  
},  
"condition" : {  
"type" : "script",  
"status" : "success",  
"met" : true  
},  
"transform" : {  
"type" : "script",  
"status" : "success",  
"payload" : {  
"result" : 3606  
}  
},  
"actions" : [  
{  
"id" : "webhook\_1",  
"type" : "webhook",  
"status" : "success",  
"webhook" : {  
"request" : {  
"host" : "[outlook.office.com](http://outlook.office.com)",  
"port" : 80,  
"scheme" : "http",  
"method" : "post",  
"path" : "webhook/PATH\_GOES\_HERE",  
"body" : "{\r\n "@context": "[https://schema.org/extensions](https://schema.org/extensions)",\r\n "@type": "MessageCard",\r\n "themeColor": "0072C6",\r\n "title": "Test Kibana ",\r\n "text": "Le test est positif",\r\n "actions": [\r\n {\r\n "@type": "HttpPOST",\r\n "name": "Send Feedback",\r\n "isPrimary": true,\r\n "target": "http://..."\r\n }\r\n]\r\n }"  
},  
"response" : {  
"status" : 301,  
"headers" : {  
"date" : [  
"Fri, 11 Oct 2019 13:20:03 GMT"  
],  
"server" : [  
"Microsoft-IIS/10.0"  
],  
"content-length" : [  
"0"  
],  
"location" : [  
"[https://outlook.office.com:80/PATH\_GOES\_HERE](https://outlook.office.com:80/PATH_GOES_HERE)""  
],  
"x-msedge-ref" : [  
"Ref A: 33AF8E65F44D47D3A1DCF26F6319778B Ref B: PAR02EDGE0512 Ref C: 2019-10-11T13:20:03Z"  
]  
}  
}  
}  
}  
]  
},  
"messages" :   
}  
}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 14, 2019, 10:04am UTC](https://discuss.elastic.co/t/watcher-and-microsoft-teams-webhook/203189/6 "2019-10-14T10:04:21Z")

</div>

Hey,

please take the time to properly format your messages using markdown. This is super hard to read.

This is not a HTTP time out or a firewall error. The HTTP server actually returned a 301 response.

Which version are you running on? Can you update to the latest 7.4.0 version and try if that problem persists, a problem regarding URL encoding for the webhook has been fixed in that one.

--Alex

---

<div class="post-metadata">

**Author:** ![wellerbar](https://avatars.discourse-cdn.com/v4/letter/w/a88e57/32.png) [@wellerbar](https://discuss.elastic.co/u/wellerbar)\
**Post date:** [October 14, 2019, 10:14am UTC](https://discuss.elastic.co/t/watcher-and-microsoft-teams-webhook/203189/7 "2019-10-14T10:14:05Z")

</div>

Hi,

I'm really sorry for the format.

I'm running it on the 7.3.1 version, I will upgrade it to the lastest 7.4.0 version and see if the problem persists, I keep you updated.

Thank you for your answer!

Lucas

---

<div class="post-metadata">

**Author:** ![wellerbar](https://avatars.discourse-cdn.com/v4/letter/w/a88e57/32.png) [@wellerbar](https://discuss.elastic.co/u/wellerbar)\
**Post date:** [October 14, 2019, 12:33pm UTC](https://discuss.elastic.co/t/watcher-and-microsoft-teams-webhook/203189/8 "2019-10-14T12:33:29Z")

</div>

Hi again,

I did upgrade to the lastest version but the problem persists, the http server return again a 301 response.

Lucas

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 16, 2019, 12:03pm UTC](https://discuss.elastic.co/t/watcher-and-microsoft-teams-webhook/203189/9 "2019-10-16T12:03:34Z")

</div>

try using `https` as protocol instead of `http` in order to prevent the redirect.

---

<div class="post-metadata">

**Author:** ![wellerbar](https://avatars.discourse-cdn.com/v4/letter/w/a88e57/32.png) [@wellerbar](https://discuss.elastic.co/u/wellerbar)\
**Post date:** [October 16, 2019, 12:10pm UTC](https://discuss.elastic.co/t/watcher-and-microsoft-teams-webhook/203189/10 "2019-10-16T12:10:19Z")

</div>

I tried and it didn't work, here is the response :

```
{
  "watch_id": "a0ed4715-0246-433d-981b-ee69b9370ffc",
  "node": "QUApyNq4S5GyhHF-CuNjfg",
  "state": "executed",
  "status": {
    "state": {
      "active": true,
      "timestamp": "2019-10-16T12:05:22.122Z"
    },
    "last_checked": "2019-10-16T12:07:06.608Z",
    "last_met_condition": "2019-10-16T12:07:06.608Z",
    "actions": {
      "webhook_1": {
        "ack": {
          "timestamp": "2019-10-16T12:05:22.122Z",
          "state": "awaits_successful_execution"
        },
        "last_execution": {
          "timestamp": "2019-10-16T12:07:06.608Z",
          "successful": false,
          "reason": ""
        }
      }
    },
    "execution_state": "executed",
    "version": -1
  },
  "trigger_event": {
    "type": "schedule",
    "triggered_time": "2019-10-16T12:07:06.608Z",
    "schedule": {
      "scheduled_time": "2019-10-16T12:07:06.535Z"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "*"
        ],
        "rest_total_hits_as_int": true,
        "body": {
          "size": 0,
          "query": {
            "bool": {
              "filter": {
                "range": {
                  "@timestamp": {
                    "gte": "{{ctx.trigger.scheduled_time}}||-5m",
                    "lte": "{{ctx.trigger.scheduled_time}}",
                    "format": "strict_date_optional_time||epoch_millis"
                  }
                }
              }
            }
          }
        }
      }
    }
  },
  "condition": {
    "script": {
      "source": "if (ctx.payload.hits.total > params.threshold) { return true; } return false;",
      "lang": "painless",
      "params": {
        "threshold": 200
      }
    }
  },
  "metadata": {
    "name": "test",
    "watcherui": {
      "trigger_interval_unit": "m",
      "agg_type": "count",
      "time_field": "@timestamp",
      "trigger_interval_size": 1,
      "term_size": 5,
      "time_window_unit": "m",
      "threshold_comparator": ">",
      "index": [
        "*"
      ],
      "time_window_size": 5,
      "threshold": 200
    },
    "xpack": {
      "type": "threshold"
    }
  },
  "result": {
    "execution_time": "2019-10-16T12:07:06.608Z",
    "execution_duration": 10687,
    "input": {
      "type": "search",
      "status": "success",
      "payload": {
        "_shards": {
          "total": 13,
          "failed": 0,
          "successful": 13,
          "skipped": 0
        },
        "hits": {
          "hits": [],
          "total": 3564,
          "max_score": null
        },
        "took": 638,
        "timed_out": false
      },
      "search": {
        "request": {
          "search_type": "query_then_fetch",
          "indices": [
            "*"
          ],
          "rest_total_hits_as_int": true,
          "body": {
            "size": 0,
            "query": {
              "bool": {
                "filter": {
                  "range": {
                    "@timestamp": {
                      "gte": "2019-10-16T12:07:06.535Z||-5m",
                      "lte": "2019-10-16T12:07:06.535Z",
                      "format": "strict_date_optional_time||epoch_millis"
                    }
                  }
                }
              }
            }
          }
        }
      }
    },
    "condition": {
      "type": "script",
      "status": "success",
      "met": true
    },
    "transform": {
      "type": "script",
      "status": "success",
      "payload": {
        "result": 3564
      }
    },
    "actions": [
      {
        "id": "webhook_1",
        "type": "webhook",
        "status": "failure",
        "error": {
          "root_cause": [
            {
              "type": "socket_timeout_exception",
              "reason": "Read timed out"
            }
          ],
          "type": "socket_timeout_exception",
          "reason": "Read timed out"
        }
      }
    ]
  },
  "messages": []
}
```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 16, 2019, 12:33pm UTC](https://discuss.elastic.co/t/watcher-and-microsoft-teams-webhook/203189/11 "2019-10-16T12:33:28Z")

</div>

is it possible, that https cannot be reached from the node where elasticsearch is running, but HTTP works?

---

<div class="post-metadata">

**Author:** ![wellerbar](https://avatars.discourse-cdn.com/v4/letter/w/a88e57/32.png) [@wellerbar](https://discuss.elastic.co/u/wellerbar)\
**Post date:** [October 16, 2019, 12:57pm UTC](https://discuss.elastic.co/t/watcher-and-microsoft-teams-webhook/203189/12 "2019-10-16T12:57:35Z")

</div>

https can be reached from the node where elasticsearch is running

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 13, 2019, 12:57pm UTC](https://discuss.elastic.co/t/watcher-and-microsoft-teams-webhook/203189/13 "2019-11-13T12:57:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
