# Watcher Email Output Not Preserving HTML Cell Colors

**URL:** <https://discuss.elastic.co/t/watcher-email-output-not-preserving-html-cell-colors/379939>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [July 9, 2025, 10:49am UTC](https://discuss.elastic.co/t/watcher-email-output-not-preserving-html-cell-colors/379939 "2025-07-09T10:49:12Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [July 9, 2025, 10:49am UTC](https://discuss.elastic.co/t/watcher-email-output-not-preserving-html-cell-colors/379939/1 "2025-07-09T10:49:12Z")

</div>

Hello Team,

Could you please share if it is possible to have color coding while sending email via Watcher?  
Like if OK = the cell should be Green in the table which is sent via Watcher & for NOT OK = Red.

I tried but it seems the style parameters are being dropped even tried updating the elasticsearch.yml with below config but it did not help :

```auto
xpack.notification.email.html.sanitization.allow: _tables, _blocks, _formatting, _links, img:embedded
xpack.notification.email.html.sanitization.disallow: script, style

```

Any pointers on how to proceed or if it is possible or not?

Thank you !

---

<div class="post-metadata">

**Author:** ![Keith\_Massey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keith_massey/32/83666_2.png) [@Keith\_Massey](https://discuss.elastic.co/u/Keith_Massey)\
**Post date:** [July 9, 2025, 9:58pm UTC](https://discuss.elastic.co/t/watcher-email-output-not-preserving-html-cell-colors/379939/2 "2025-07-09T21:58:50Z")

</div>

Could you post a watch that reproduces this? Have you tried setting `xpack.notification.email.html.sanitization.enabled` to false, just to see if that solves the problem (I understand that you probably don't want to do that in production, but I'm just curious if it solves the problem).

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [July 11, 2025, 12:23pm UTC](https://discuss.elastic.co/t/watcher-email-output-not-preserving-html-cell-colors/379939/3 "2025-07-11T12:23:49Z")

</div>

Thank you @Keith_Massey

Yes, using this option color coding works as required. But how to make it happen in Production?

Thanks!!

---

<div class="post-metadata">

**Author:** ![Keith\_Massey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keith_massey/32/83666_2.png) [@Keith\_Massey](https://discuss.elastic.co/u/Keith_Massey)\
**Post date:** [July 11, 2025, 1:12pm UTC](https://discuss.elastic.co/t/watcher-email-output-not-preserving-html-cell-colors/379939/4 "2025-07-11T13:12:17Z")

</div>

I'm not sure yet. Can you post a watch that reproduces this?

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [July 11, 2025, 1:42pm UTC](https://discuss.elastic.co/t/watcher-email-output-not-preserving-html-cell-colors/379939/5 "2025-07-11T13:42:46Z")

</div>

Sure.

Please find below details :

**Test Watcher :**

```auto
{
  "trigger": {
    "schedule": {
      "interval": "1m"
    }
  },
  "input": {
    "none": {}
  },
  "condition": {
    "always": {}
  },
  "actions": {
    "send_email": {
      "email": {
        "profile": "standard",
        "to": [
          "myemail@id.com"
        ],
        "subject": "Hello World Watch",
        "body": {
          "html": """
            <html>
              <body>
                <h3>Notification Table</h3>
                <table border="1" cellpadding="5" cellspacing="0" style="border-collapse: collapse; width: 100%; text-align: center;">
                  <tr style="background-color: #f2f2f2;">
                    <th style="width: 50%;">Critical Alerts</th>
                    <th style="width: 50%;">Normal Updates</th>
                  </tr>
                  <tr>
                    <td style="background-color: #F44336; color: white;">This is a critical alert!</td>
                    <td style="background-color: #4CAF50; color: white;">This is a normal update.</td>
                  </tr>
                </table>
                <p style="margin-top: 20px;">Thanks,<br/>ELK team</p>
              </body>
            </html>
          """
        }
      }
    }
  }
}

```

**elasticsearch.yml setting :**

`xpack.notification.email.html.sanitization.enabled : false`

**Sample email received :**

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/3/03158474918593d748e968cd96f359efe51d0cee.png)

**If i remove the above entry from elasticsearch.yml :**

**Sample email received :**

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/4/9425435dd8847ded49291c38e08fd90ecb5fa719.png)

Thanks!!

---

<div class="post-metadata">

**Author:** ![angelo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/angelo/32/61325_2.png) [@angelo](https://discuss.elastic.co/u/angelo)\
**Post date:** [July 14, 2025, 3:30pm UTC](https://discuss.elastic.co/t/watcher-email-output-not-preserving-html-cell-colors/379939/6 "2025-07-14T15:30:58Z")

</div>

You need to add `_styles` to your 'allow' setting as documented [here](https://www.elastic.co/guide/en/elasticsearch/reference/8.18/notification-settings.html#email-notification-settings).

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [July 15, 2025, 3:21am UTC](https://discuss.elastic.co/t/watcher-email-output-not-preserving-html-cell-colors/379939/7 "2025-07-15T03:21:00Z")

</div>

Thanks @angelo for the suggestion.

Using styles , i confirm it is working as expected.

`xpack.notification.email.html.sanitization.allow: _tables, _formatting, _styles`

Thanks!!
