# Watcher error 400 webhook action

**URL:** <https://discuss.elastic.co/t/watcher-error-400-webhook-action/283959>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [September 11, 2021, 8:30pm UTC](https://discuss.elastic.co/t/watcher-error-400-webhook-action/283959 "2021-09-11T20:30:21Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Juliana\_Sabino](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juliana_sabino/32/100475_2.png) [@Juliana\_Sabino](https://discuss.elastic.co/u/Juliana_Sabino)\
**Post date:** [September 11, 2021, 8:30pm UTC](https://discuss.elastic.co/t/watcher-error-400-webhook-action/283959/1 "2021-09-11T20:30:21Z")

</div>

Hi!

I'm facing a problem when I try to run a watcher.

```auto
 "body": "{\n \"error\": {\n \"code\": 400,\n \"message\": \"Invalid JSON payload received. Unexpected token.\\nsomething\\n^\",\n \"status\": \"INVALID_ARGUMENT\"\n }\n}\n"

```

This is my actions:

```auto
 "actions": [
      {
        "id": "my_webhook",
        "type": "webhook",
        "status": "failure",
        "reason": "received [400] status code",
        "webhook": {
          "request": {
            "host": "chat.googleapis.com",
            "port": 443,
            "scheme": "https",
            "method": "post",
            "path": "v1/spaces/AAAAHS0yhM4/messages",
            "params": {
              "key": "mykey",
              "token": "mytoken"
            },
            "headers": {
              "Content-Type": "application/json"
            },
            "body": "something"
          },

```

Please, could some one give me a light on this? Thanks so much!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 12, 2021, 2:51am UTC](https://discuss.elastic.co/t/watcher-error-400-webhook-action/283959/2 "2021-09-12T02:51:49Z")

</div>

Hi @Juliana_Sabino Welcome to the community.

That webhook action looks malformed.

Here is the [spec](https://www.elastic.co/guide/en/elasticsearch/reference/current/actions-webhook.html)

First thing I notice is you have a `"request" : { ...`

Enclosing the rest of the parameters, according to the spec as far as I see that is not valid / not needed

I would fix that make sure you are using valid syntax.

Can you show your exact webhook definition (redacted credentials)

---

<div class="post-metadata">

**Author:** ![Juliana\_Sabino](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juliana_sabino/32/100475_2.png) [@Juliana\_Sabino](https://discuss.elastic.co/u/Juliana_Sabino)\
**Post date:** [September 12, 2021, 4:37pm UTC](https://discuss.elastic.co/t/watcher-error-400-webhook-action/283959/3 "2021-09-12T16:37:50Z")

</div>

Hey @stephenb , thank you so much!  
I've followed the link you gave me and now I'm getting a 404 error. I think it's better if I open up a new topic. Thank you!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 12, 2021, 4:48pm UTC](https://discuss.elastic.co/t/watcher-error-400-webhook-action/283959/4 "2021-09-12T16:48:42Z")

</div>

404 means you have an incorrect / not found URL..

You should be able to just use curl or postman to check the url creds etc before you try in watcher

---

<div class="post-metadata">

**Author:** ![Juliana\_Sabino](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juliana_sabino/32/100475_2.png) [@Juliana\_Sabino](https://discuss.elastic.co/u/Juliana_Sabino)\
**Post date:** [September 12, 2021, 7:35pm UTC](https://discuss.elastic.co/t/watcher-error-400-webhook-action/283959/5 "2021-09-12T19:35:37Z")

</div>

Hi, I'm back here hehe  
@stephenb, you're helping me a lot, thank you so much!

Im receiving the error 400 again.

This is my webhook actions:

```auto
"actions": {
    "my_webhook": {
      "webhook": {
        "scheme": "https",
        "host": "chat.googleapis.com",
        "port": 443,
        "method": "post",
        "path": "mypath",
        "params": {
          "key": "mykey",
          "token": "mytoken"
        },
        "headers": {},
        "body": "count: {{ctx.payload.hits.total}}"
      }
    }
  }

```

This is the response I'm receiving:

```auto
  "actions": [
      {
        "id": "my_webhook",
        "type": "webhook",
        "status": "failure",
        "reason": "received [400] status code",
        "webhook": {
          "request": {
            "host": "chat.googleapis.com",
            "port": 443,
            "scheme": "https",
            "method": "post",
            "path": "mypath",
            "params": {
              "key": "mykey",
              "token": "mytoken"
            },
            "body": "count: 2413"
          },
          "response": {
            "status": 400,
            "headers": {
              "date": [
                "Sun, 12 Sep 2021 19:33:28 GMT"
              ],
              "server": [
                "ESF"
              ],
              "transfer-encoding": [
                "chunked"
              ],
              "x-content-type-options": [
                "nosniff"
              ],
              "x-xss-protection": [
                "0"
              ],
              "vary": [
                "Origin",
                "X-Origin",
                "Referer"
              ],
              "x-frame-options": [
                "SAMEORIGIN"
              ],
              "content-type": [
                "application/json; charset=UTF-8"
              ],
              "cache-control": [
                "private"
              ],
              "alt-svc": [
                "h3=\":443\"; ma=2592000,h3-29=\":443\"; ma=2592000,h3-T051=\":443\"; ma=2592000,h3-Q050=\":443\"; ma=2592000,h3-Q046=\":443\"; ma=2592000,h3-Q043=\":443\"; ma=2592000,quic=\":443\"; ma=2592000; v=\"46,43\""
              ]
            },
            "body": "{\n \"error\": {\n \"code\": 400,\n \"message\": \"Invalid JSON payload received. Unexpected token.\\ncount: 2413\\n^\",\n \"status\": \"INVALID_ARGUMENT\"\n }\n}\n"
          }
        }
      }
    ]
  },
  "messages": []

```

Do you have an idea of why this is happening? I'm having this problem one week long already 😕

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 13, 2021, 6:01am UTC](https://discuss.elastic.co/t/watcher-error-400-webhook-action/283959/6 "2021-09-13T06:01:15Z")

</div>

In future please don't create multiple topics on the same question, it makes it harder for people to track and help you out 🙂

> [@Watcher error 404 webhook](https://discuss.elastic.co/t/watcher-error-404-webhook/283983):
>
> Hi guys! I'm getting the error 404 on a watcher. This is my webhook action: "actions": { "my\_webhook": { "webhook": { "scheme": "https", "host": "chat.googleapis.com", "port": 443, "method": "post", "path": "https://chat.googleapis.com/v1/spaces/AAAAHS0yhM4/messages?key=AIzaSyDdI0hCZtE6vySjMm-WEfRq3CPzqKqqsHI&token=V66l8OHmaf44qrzIbmDx8m\_KtQx0AFjtcdn7clajQqE%3D", "params": {}, "headers": {}, "body": "{{ctx.watch\_id}}:{{…

---

<div class="post-metadata">

**Author:** ![Juliana\_Sabino](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juliana_sabino/32/100475_2.png) [@Juliana\_Sabino](https://discuss.elastic.co/u/Juliana_Sabino)\
**Post date:** [September 13, 2021, 11:54am UTC](https://discuss.elastic.co/t/watcher-error-400-webhook-action/283959/7 "2021-09-13T11:54:59Z")

</div>

It's a different question @warkolm. One was 404, this one is 400.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 11, 2021, 11:55am UTC](https://discuss.elastic.co/t/watcher-error-400-webhook-action/283959/8 "2021-10-11T11:55:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
