# Watcher is getting http status code \[401\]

**URL:** <https://discuss.elastic.co/t/watcher-is-getting-http-status-code-401/31558>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [October 2, 2015, 5:14pm UTC](https://discuss.elastic.co/t/watcher-is-getting-http-status-code-401/31558 "2015-10-02T17:14:03Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![chaudharikiranp](https://avatars.discourse-cdn.com/v4/letter/c/71c47a/32.png) [@chaudharikiranp](https://discuss.elastic.co/u/chaudharikiranp)\
**Post date:** [October 2, 2015, 5:14pm UTC](https://discuss.elastic.co/t/watcher-is-getting-http-status-code-401/31558/1 "2015-10-02T17:14:03Z")

</div>

Hi, does anyone have the sample role configuration for watcher roles with shield. I can not see anywhere in the elasticsearch documentation the roles to be added for watcher in roles.yml. Very less information is available.  
I installed shield first and then watcher. Ideally even though I installed watcher later the shield should have created the default roles in roles.yml but it didn't add any role. I tried to add the role 'watcher\_admin' in the roles.yml file then created the user '\_watcher\_user' and make it admin in esusers realm but still getting 401 error while executing a watch.

Role added in roles.yml:  
watcher\_admin:  
cluster: manage\_watcher

User added:  
./bin/shield/esusers useradd \_watcher\_user -p password -r watcher\_admin

---

<div class="post-metadata">

**Author:** ![chaudharikiranp](https://avatars.discourse-cdn.com/v4/letter/c/71c47a/32.png) [@chaudharikiranp](https://discuss.elastic.co/u/chaudharikiranp)\
**Post date:** [October 2, 2015, 8:48pm UTC](https://discuss.elastic.co/t/watcher-is-getting-http-status-code-401/31558/2 "2015-10-02T20:48:56Z")

</div>

Nevermind, I think I resolved the issue.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 3, 2015, 11:52pm UTC](https://discuss.elastic.co/t/watcher-is-getting-http-status-code-401/31558/3 "2015-10-03T23:52:40Z")

</div>

What was the issue?

---

<div class="post-metadata">

**Author:** ![ksoucy](https://avatars.discourse-cdn.com/v4/letter/k/dc4da7/32.png) [@ksoucy](https://discuss.elastic.co/u/ksoucy)\
**Post date:** [February 26, 2016, 8:44pm UTC](https://discuss.elastic.co/t/watcher-is-getting-http-status-code-401/31558/4 "2016-02-26T20:44:54Z")

</div>

Can you share what the issue was? I too am getting 401 errs even though i have same watcher role, have a user mapped to that role, and create my watchess with that user. Also tried using the \_\_watcher\_user (adding to es realm, mapping to role, and creating watches with that id), since that id was highlighted in the Watcher docs. Neither method works. THks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:46pm UTC](https://discuss.elastic.co/t/watcher-is-getting-http-status-code-401/31558/5 "2017-07-06T13:46:51Z")

</div>


