# Watcher Notifications via email and Slack

**URL:** <https://discuss.elastic.co/t/watcher-notifications-via-email-and-slack/205931>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting, docker\
**Created:** [October 30, 2019, 6:21pm UTC](https://discuss.elastic.co/t/watcher-notifications-via-email-and-slack/205931 "2019-10-30T18:21:46Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mauricio\_Borges](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mauricio_borges/32/54964_2.png) [@Mauricio\_Borges](https://discuss.elastic.co/u/Mauricio_Borges)\
**Post date:** [October 30, 2019, 6:21pm UTC](https://discuss.elastic.co/t/watcher-notifications-via-email-and-slack/205931/1 "2019-10-30T18:21:46Z")

</div>

Hi Everyone!  
I am using ELK via Docker Compose and I am interesting to setup Watcher Notifications via email and integrated with Slack. Any step by step procedure to I achieve that ?

When I set commented lines below from elasticsearch.yml Kibana stay inaccessible ☹ I need setup my local server that has posfix workfing fine and relaying our outbounding messages. So idea here is not setup gmail, aws or outlook.

I am using any wrong parameter ?

xpack.license.self\_generated.type: trial  
xpack.security.enabled: true  
xpack.monitoring.collection.enabled: true  
#xpack.notification.email:

# default\_account:

# profile: standard

# smtp:

# auth: true

# starttls.enable: false

# host: localhost

# port: 25

# smtp\_user: borgesm

# password: blalalala

I am getting that output into elasticseach:  
elasticsearch\_1 | "Suppressed: java.lang.IllegalArgumentException: unknown setting [xpack.notification.email.default\_account.smtp.host]  
did you mean any of [xpack.notification.email.default\_account, xpack.notification.slack.default\_account]?",  
Appreciate any help!  
Mauricio

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 31, 2019, 12:33pm UTC](https://discuss.elastic.co/t/watcher-notifications-via-email-and-slack/205931/2 "2019-10-31T12:33:37Z")

</div>

Watcher requires a gold/platinum or trial license. Are you using one of those licenses?

Also, please share your configuration file in a gist, so it is possible to follow indentation as this is crucially important to spot mistakes.

Lastly the Elasticsearch version being in use, would help a lot!

Thanks a lot!

---

<div class="post-metadata">

**Author:** ![Mauricio\_Borges](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mauricio_borges/32/54964_2.png) [@Mauricio\_Borges](https://discuss.elastic.co/u/Mauricio_Borges)\
**Post date:** [October 31, 2019, 1:38pm UTC](https://discuss.elastic.co/t/watcher-notifications-via-email-and-slack/205931/3 "2019-10-31T13:38:09Z")

</div>

Hello Alexander!  
1 - we are using trial version (v 7.3.1). Is valid till end of November.

Your Trial license is active  
Your license will expire on **November 28, 2019 9:59 PM -02**

2 - Follow below elasticsearch.yml file content. if you need more config files I can attach at my google drive ...

# cat elasticsearch.yml

* * *

## Default Elasticsearch configuration from Elasticsearch base image.

## [https://github.com/elastic/elasticsearch/blob/master/distribution/docker/src/docker/config/elasticsearch.yml](https://github.com/elastic/elasticsearch/blob/master/distribution/docker/src/docker/config/elasticsearch.yml)

# 

cluster.name: "docker-cluster"  
network.host: 0.0.0.0

## Use single node discovery in order to disable production mode and avoid bootstrap checks

## see [https://www.elastic.co/guide/en/elasticsearch/reference/current/bootstrap-checks.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/bootstrap-checks.html)

# 

discovery.type: single-node

## X-Pack settings

## see [https://www.elastic.co/guide/en/elasticsearch/reference/current/setup-xpack.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/setup-xpack.html)

# 

xpack.license.self\_generated.type: trial  
xpack.security.enabled: true  
xpack.monitoring.collection.enabled: true  
#xpack.notification.email.account:

# default\_account:

# profile: standard

# smtp:

# auth: false

# starttls.enable: false

# host: localhost

# port: 25

# smtp\_user: cloud\_user

# password: Jxxxxxa

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 31, 2019, 2:59pm UTC](https://discuss.elastic.co/t/watcher-notifications-via-email-and-slack/205931/4 "2019-10-31T14:59:38Z")

</div>

as already stated in my last post, please put your configuration in a gist or pastebin, the formatting here makes it impossible to read it or figure out its indentation.

---

<div class="post-metadata">

**Author:** ![Mauricio\_Borges](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mauricio_borges/32/54964_2.png) [@Mauricio\_Borges](https://discuss.elastic.co/u/Mauricio_Borges)\
**Post date:** [October 31, 2019, 4:45pm UTC](https://discuss.elastic.co/t/watcher-notifications-via-email-and-slack/205931/5 "2019-10-31T16:45:30Z")

</div>

[https://pastebin.com/4THesYaK](https://pastebin.com/4THesYaK)

---

<div class="post-metadata">

**Author:** ![Mauricio\_Borges](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mauricio_borges/32/54964_2.png) [@Mauricio\_Borges](https://discuss.elastic.co/u/Mauricio_Borges)\
**Post date:** [October 31, 2019, 4:46pm UTC](https://discuss.elastic.co/t/watcher-notifications-via-email-and-slack/205931/6 "2019-10-31T16:46:13Z")

</div>

Sorry Alexander, now I gotcha...see if previous post from pastebin works. Thanks, Mauricio

---

<div class="post-metadata">

**Author:** ![Mauricio\_Borges](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mauricio_borges/32/54964_2.png) [@Mauricio\_Borges](https://discuss.elastic.co/u/Mauricio_Borges)\
**Post date:** [November 2, 2019, 1:32am UTC](https://discuss.elastic.co/t/watcher-notifications-via-email-and-slack/205931/7 "2019-11-02T01:32:51Z")

</div>

Hi Alexander!  
1 - Good news for " **standard e-mail notifications**"!  
After remove entries smtp\_users and password it's working properly!  
[https://pastebin.com/Xmu5fQy2](https://pastebin.com/Xmu5fQy2)  
1.1 - For Gmail or Outlook I get message "no password specified" even have followed procedures below. However, since item 1 is working I am okay.  
Here the logs ==\> [https://pastebin.com/CEXfAjew](https://pastebin.com/CEXfAjew)  
[https://www.elastic.co/guide/en/elasticsearch/reference/7.3/actions-email.html#gmail](https://www.elastic.co/guide/en/elasticsearch/reference/7.3/actions-email.html#gmail)  
[https://www.elastic.co/guide/en/elasticsearch/reference/7.3/actions-email.html#outlook](https://www.elastic.co/guide/en/elasticsearch/reference/7.3/actions-email.html#outlook)

2 - Slack integration :  
I have follow procedure to [Configure Slack Account] , use keystore method to store secure slack url, however still facing "Erro testing action / An internal server error occurred at Kibana. Here more info about elasticsearch.yml, commands and outputs [https://pastebin.com/edit/etWPVKWi](https://pastebin.com/edit/etWPVKWi)

I see "invalid slack [monitoring] account settings." in the logs...

Appreciate any help!  
Thanks, Mauricio

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 4, 2019, 9:55am UTC](https://discuss.elastic.co/t/watcher-notifications-via-email-and-slack/205931/8 "2019-11-04T09:55:35Z")

</div>

Glad you advanced!

the pastebin website requires a login, can you put it somewhere public?

---

<div class="post-metadata">

**Author:** ![Mauricio\_Borges](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mauricio_borges/32/54964_2.png) [@Mauricio\_Borges](https://discuss.elastic.co/u/Mauricio_Borges)\
**Post date:** [November 4, 2019, 11:23am UTC](https://discuss.elastic.co/t/watcher-notifications-via-email-and-slack/205931/9 "2019-11-04T11:23:30Z")

</div>

Hi Alexander!  
Weird, it's set public, maybe it's forcing you sign up. I have put [here](https://1drv.ms/u/s!Au67NPSzqSWRgY5_TR4C0cEBHclgtg?e=2ackhQ).

Thanks again, Mauricio

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 4, 2019, 1:40pm UTC](https://discuss.elastic.co/t/watcher-notifications-via-email-and-slack/205931/10 "2019-11-04T13:40:12Z")

</div>

See this slack error

```auto
[settings_exception] invalid slack [monitoring] account settings. missing required
       │ [secure_url]

```

How did you set up your slack account? Did you setup the `secure_url` on every keystore on all nodes in your cluster?

--Alex

---

<div class="post-metadata">

**Author:** ![Mauricio\_Borges](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mauricio_borges/32/54964_2.png) [@Mauricio\_Borges](https://discuss.elastic.co/u/Mauricio_Borges)\
**Post date:** [November 8, 2019, 10:35pm UTC](https://discuss.elastic.co/t/watcher-notifications-via-email-and-slack/205931/11 "2019-11-08T22:35:07Z")

</div>

Hi Alexander!  
It's working fine now! I have set the slack keystore into container, copied to host and target it into my [compose file](https://pastebin.com/UmS3xcp9) the keystore file. Thank you!  
Mauricio

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 6, 2019, 10:35pm UTC](https://discuss.elastic.co/t/watcher-notifications-via-email-and-slack/205931/12 "2019-12-06T22:35:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
