# Watcher: Error 500 Internal Server Error: An internal server error occurred

**URL:** https://discuss.elastic.co/t/watcher-error-500-internal-server-error-an-internal-server-error-occurred/109624
**Category:** Kibana
**Created:** [November 29, 2017, 4:43pm UTC](https://discuss.elastic.co/t/watcher-error-500-internal-server-error-an-internal-server-error-occurred/109624 "2017-11-29T16:43:45Z")
**Posts on this page:** 12
**Page:** 1

<div class="post-metadata">

### Author: ![Jasonespo](https://avatars.discourse-cdn.com/v4/letter/j/898d66/32.png) [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)
#### Post date: [November 29, 2017, 4:43pm UTC](https://discuss.elastic.co/t/watcher-error-500-internal-server-error-an-internal-server-error-occurred/109624/1 "2017-11-29T16:43:46Z")

</div>

Hi there, I have just installed the 6.0 update and when navigating to my watchers I am receiving an internal server error, does anybody know a fix for this? Or any possible reasons why I might be receiving this error?

Thank you in advance,

Jason

---

<div class="post-metadata">

### Author: ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)
#### Post date: [November 29, 2017, 8:46pm UTC](https://discuss.elastic.co/t/watcher-error-500-internal-server-error-an-internal-server-error-occurred/109624/2 "2017-11-29T20:46:05Z")

</div>

Hey,

Are there any logs that go with the 500 error? Was this an upgrade to 6.0 or a fresh install?

---

<div class="post-metadata">

### Author: ![Jasonespo](https://avatars.discourse-cdn.com/v4/letter/j/898d66/32.png) [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)
#### Post date: [November 30, 2017, 10:13am UTC](https://discuss.elastic.co/t/watcher-error-500-internal-server-error-an-internal-server-error-occurred/109624/3 "2017-11-30T10:13:36Z")

</div>

Hi Jon,

This is an upgrade to 6.0. I know that there are breaking changes for the watchers after this update but I can't access them to make the updates.

Some logs:

[2017-11-30T09:49:14,164][ERROR][org.elasticsearch.xpack.watcher.input.search.ExecutableSearchInput] failed to execute [search] input for watch [Compromised\_Host\_Detected], reason [all shards failed]

[org.elasticsearch.xpack.monitoring.exporter.http.VersionHttpResource] version [5.6.2] \< [6.0.0-alpha1] and NOT supported for [xpack.monitoring.exporters.found-user-defined]

Could this error be caused by version mismatches?

I know that Elasticsearch is v6.0. Kibana is v6.0 (managed in the cloud). I have run a sudo yum update on my ec2 instance that is running Logstash and it is fully updated.

Jason

---

<div class="post-metadata">

### Author: ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)
#### Post date: [November 30, 2017, 7:33pm UTC](https://discuss.elastic.co/t/watcher-error-500-internal-server-error-an-internal-server-error-occurred/109624/4 "2017-11-30T19:33:57Z")

</div>

Monitoring creates watches and it sounds like the monitoring cluster is on 5.6 still, possibly causing UI errors. You mentioned managed in the cloud, are you using Elastic Cloud? If so can you open a support ticket at [support.elastic.co](http://support.elastic.co)? They'll be able to take a look at the versions upgraded.

---

<div class="post-metadata">

### Author: ![Jasonespo](https://avatars.discourse-cdn.com/v4/letter/j/898d66/32.png) [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)
#### Post date: [December 7, 2017, 5:27pm UTC](https://discuss.elastic.co/t/watcher-error-500-internal-server-error-an-internal-server-error-occurred/109624/5 "2017-12-07T17:27:20Z")

</div>

Hi @jbudz

I took this up with the elastic cloud team and we have managed to get all of my versions upgraded to 6.0 but this still hasn't fixed the internal server error that I am facing.

Do you know if there is any other reasons why I could be getting this error?

Jason

---

<div class="post-metadata">

### Author: ![jamesspi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamesspi/32/24479_2.png) [@jamesspi](https://discuss.elastic.co/u/jamesspi)
#### Post date: [December 12, 2017, 12:39pm UTC](https://discuss.elastic.co/t/watcher-error-500-internal-server-error-an-internal-server-error-occurred/109624/6 "2017-12-12T12:39:40Z")

</div>

I also have this exact issue.

New GCP cluster on 6.0 (now on 6.0.1). Trying to access the watches in management gives me the same 500 error code.

Watches still fire, and I can create/modify existing watches through the console without issue (which is what I have been doing).

Thanks,  
James

---

<div class="post-metadata">

### Author: ![Jasonespo](https://avatars.discourse-cdn.com/v4/letter/j/898d66/32.png) [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)
#### Post date: [December 12, 2017, 1:44pm UTC](https://discuss.elastic.co/t/watcher-error-500-internal-server-error-an-internal-server-error-occurred/109624/7 "2017-12-12T13:44:59Z")

</div>

Hi @jamesspi,

It's been reported that if the watches have an email action, but the action does not contain a `body` property then it will cause this sort of error.

Or if you haven't specified your 'watch' logging action text.

This is the feedback I got from the cloud team.

Jason

---

<div class="post-metadata">

### Author: ![jamesspi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamesspi/32/24479_2.png) [@jamesspi](https://discuss.elastic.co/u/jamesspi)
#### Post date: [December 12, 2017, 1:58pm UTC](https://discuss.elastic.co/t/watcher-error-500-internal-server-error-an-internal-server-error-occurred/109624/8 "2017-12-12T13:58:24Z")

</div>

Hey @Jasonespo

I'm actually using slack notifications, not e-mail, so not sure this is valid in my case.

Thanks though!

James

---

<div class="post-metadata">

### Author: ![jamesspi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamesspi/32/24479_2.png) [@jamesspi](https://discuss.elastic.co/u/jamesspi)
#### Post date: [December 12, 2017, 2:12pm UTC](https://discuss.elastic.co/t/watcher-error-500-internal-server-error-an-internal-server-error-occurred/109624/9 "2017-12-12T14:12:49Z")

</div>

@Jasonespo - actually, thanks! This led me to check my slack settings - I didn't have the message text set, just the attachment text. Added this to all my watches and it works now!

---

<div class="post-metadata">

### Author: ![Jasonespo](https://avatars.discourse-cdn.com/v4/letter/j/898d66/32.png) [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)
#### Post date: [December 12, 2017, 2:28pm UTC](https://discuss.elastic.co/t/watcher-error-500-internal-server-error-an-internal-server-error-occurred/109624/10 "2017-12-12T14:28:41Z")

</div>

@jamesspi

No worries 😄

I have over 150 watchers to look through.. I'm not sure the exact config of each one..

Is there an easy way to view them? I have them saved in GitHub but I would have to pull them in and manually run them one by one to update the watchers in management.

Jason

---

<div class="post-metadata">

### Author: ![jamesspi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamesspi/32/24479_2.png) [@jamesspi](https://discuss.elastic.co/u/jamesspi)
#### Post date: [December 12, 2017, 2:33pm UTC](https://discuss.elastic.co/t/watcher-error-500-internal-server-error-an-internal-server-error-occurred/109624/11 "2017-12-12T14:33:29Z")

</div>

@Jasonespo

Thankfully, I only had a handful. I run:

GET .watches/\_search/ - this will list your watches and their metadata. You can grab the watch configs out of their, add the missing info and resubmit them. This is what I did.

Might be a pain with 150 though!

James

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 9, 2018, 2:33pm UTC](https://discuss.elastic.co/t/watcher-error-500-internal-server-error-an-internal-server-error-occurred/109624/12 "2018-01-09T14:33:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
