# Watcher reporting basic auth not working, password not saved

**URL:** <https://discuss.elastic.co/t/watcher-reporting-basic-auth-not-working-password-not-saved/108597>\
**Category:** Elasticsearch\
**Created:** [November 21, 2017, 5:07pm UTC](https://discuss.elastic.co/t/watcher-reporting-basic-auth-not-working-password-not-saved/108597 "2017-11-21T17:07:56Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tommaso](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tommaso/32/24519_2.png) [@Tommaso](https://discuss.elastic.co/u/Tommaso)\
**Post date:** [November 21, 2017, 5:07pm UTC](https://discuss.elastic.co/t/watcher-reporting-basic-auth-not-working-password-not-saved/108597/1 "2017-11-21T17:07:57Z")

</div>

Hello,

this watcher below is not working for me. Whenever I add the password field, it doesn't get saved. I thought it was only hidden, but running the watcher returns: "Watcher: [parse\_exception] password is a required option".  
I can send other emails with the same default account with no issues, but I can't generate reports if I can't authenticate.

{  
"trigger": {  
"schedule": {  
"interval": "1m"  
}  
},  
"input": {  
"none": {}  
},  
"condition": {  
"always": {}  
},  
"actions": {  
"send\_email": {  
"email": {  
"profile": "standard",  
"attachments": {  
"SDC\_daily\_count.pdf": {  
"reporting": {  
"url": "[http://x.x.x.x/api/reporting/generate/dashboard/SDC-daily-count](http://x.x.x.x/api/reporting/generate/dashboard/SDC-daily-count)",  
"auth": {  
"basic": {  
"username": "elastic",  
"password": "changeme" ###THIS GETS REMOVED###  
}  
}  
}  
}  
},  
"to": [  
"aaa@bbb.com"  
],  
"subject": "SDC daily counts"  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 21, 2017, 5:25pm UTC](https://discuss.elastic.co/t/watcher-reporting-basic-auth-not-working-password-not-saved/108597/2 "2017-11-21T17:25:44Z")

</div>

can you create a full reproduction case, including the complete API calls to create the watch and the output of the execute watch API?

Also, what Elasticsearch version is this?

--Alex

---

<div class="post-metadata">

**Author:** ![Tommaso](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tommaso/32/24519_2.png) [@Tommaso](https://discuss.elastic.co/u/Tommaso)\
**Post date:** [November 21, 2017, 5:33pm UTC](https://discuss.elastic.co/t/watcher-reporting-basic-auth-not-working-password-not-saved/108597/3 "2017-11-21T17:33:54Z")

</div>

Hello Alex,  
thank you for your prompt reply!

I am using v5.6.4 of ES and Kibana.  
This is the execution output:

{  
"watch\_id": "SDC\_test\_daily",  
"state": "executed",  
"status": {  
"state": {  
"active": true,  
"timestamp": "2017-11-21T16:48:48.539Z"  
},  
"last\_checked": "2017-11-21T17:09:00.612Z",  
"last\_met\_condition": "2017-11-21T17:09:00.612Z",  
"actions": {  
"send\_email": {  
"ack": {  
"timestamp": "2017-11-21T16:48:48.539Z",  
"state": "awaits\_successful\_execution"  
},  
"last\_execution": {  
"timestamp": "2017-11-21T17:09:00.612Z",  
"successful": false,  
"reason": "Connection refused"  
}  
}  
}  
},  
"trigger\_event": {  
"type": "schedule",  
"triggered\_time": "2017-11-21T17:09:00.612Z",  
"schedule": {  
"scheduled\_time": "2017-11-21T17:09:00.567Z"  
}  
},  
"input": {  
"none": {}  
},  
"condition": {  
"always": {}  
},  
"result": {  
"execution\_time": "2017-11-21T17:09:00.612Z",  
"execution\_duration": 2,  
"input": {  
"type": "none",  
"status": "success",  
"payload": {}  
},  
"condition": {  
"type": "always",  
"status": "success",  
"met": true  
},  
"actions": [  
{  
"id": "send\_email",  
"type": "email",  
"status": "failure",  
"reason": "Connection refused"  
}  
]  
},  
"messages": []  
}

To create the watch, I just used the json in my previous post in the kibana GUI. It doesn't give any syntax error. If I go back to edit the watch, the password field is gone.

Thanks,  
Tommaso

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 21, 2017, 5:38pm UTC](https://discuss.elastic.co/t/watcher-reporting-basic-auth-not-working-password-not-saved/108597/4 "2017-11-21T17:38:45Z")

</div>

the error message from what you pasted is not what you referred to before. Has anything changed? Seems like kibana is not reachable or the mail server.

---

<div class="post-metadata">

**Author:** ![Tommaso](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tommaso/32/24519_2.png) [@Tommaso](https://discuss.elastic.co/u/Tommaso)\
**Post date:** [November 21, 2017, 5:43pm UTC](https://discuss.elastic.co/t/watcher-reporting-basic-auth-not-working-password-not-saved/108597/5 "2017-11-21T17:43:15Z")

</div>

The error message comes from that watch scheduled execution.  
If I simulate the watch from kibana, I get:

Watcher: [parse\_exception] password is a required option

---

<div class="post-metadata">

**Author:** ![Tommaso](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tommaso/32/24519_2.png) [@Tommaso](https://discuss.elastic.co/u/Tommaso)\
**Post date:** [November 21, 2017, 5:45pm UTC](https://discuss.elastic.co/t/watcher-reporting-basic-auth-not-working-password-not-saved/108597/6 "2017-11-21T17:45:35Z")

</div>

While troubleshooting, I created another watch, just to test the email server. This one works just fine and I ge the email in my inbox:

{  
"trigger": {  
"schedule": {  
"interval": "1m"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"\*"  
],  
"types": [],  
"body": {  
"size": 0,  
"query": {  
"match\_all": {}  
}  
}  
}  
}  
},  
"condition": {  
"compare": {  
"ctx.payload.hits.total": {  
"gte": 10  
}  
}  
},  
"actions": {  
"send\_email": {  
"email": {  
"profile": "standard",  
"to": [  
"aaa@bbb.com"  
],  
"subject": "Watcher Notification Test",  
"body": {  
"text": "This is a test"  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![Cre8ivE\_OnE](https://avatars.discourse-cdn.com/v4/letter/c/4bbf92/32.png) [@Cre8ivE\_OnE](https://discuss.elastic.co/u/Cre8ivE_OnE)\
**Post date:** [November 21, 2017, 6:04pm UTC](https://discuss.elastic.co/t/watcher-reporting-basic-auth-not-working-password-not-saved/108597/7 "2017-11-21T18:04:04Z")

</div>

Experiencing similar issue (we opened a similar ticket _on v5.6.3_ about 19m after this one was opened - crazy!) - watching both threads for a solution...

Simulating the watcher, before saving it, seems to trigger fine

Once I SAVE the JSON definition, the "password" element in the JSON is parsed out by the Kibana server as it is performing the save action.

Re-opening the watch and attempting to simulate then produces the error:  
Watcher: [parse\_exception] password is a required option

This seems to be a **"feature"** as reported here :

> [@Password field gets deleted after adding a watch](https://discuss.elastic.co/t/password-field-gets-deleted-after-adding-a-watch/88178):
>
> Hello, I've been trying to add a new watcher that will email a report to multiple users, however after I've added the watch (either via web UI or curl) and try to run it, I get the following error "password is a required option". Looking at the watch after I've inserted it I noticed the password filed is gone (under email attachment). I've also tried to edit the watch via web UI after adding it, and after I hit 'save' the password is gone again. Here is my watch: { "trigger" : { "schedule"…

So... irritating messaging? Is there anyway to get a different, more explicit, message 🙂

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 22, 2017, 10:00am UTC](https://discuss.elastic.co/t/watcher-reporting-basic-auth-not-working-password-not-saved/108597/8 "2017-11-22T10:00:20Z")

</div>

Hey,

indeed, this a feature from watchers GET Watch API, that removes passwords, when data is returned to kibana. In this special case, the credentials should not get removed, as otherwise storing the watch fails - what you are experiencing.

I will work with the UI team on a fix. Sorry for the inconvenience.

--Alex

---

<div class="post-metadata">

**Author:** ![Tommaso](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tommaso/32/24519_2.png) [@Tommaso](https://discuss.elastic.co/u/Tommaso)\
**Post date:** [November 22, 2017, 2:38pm UTC](https://discuss.elastic.co/t/watcher-reporting-basic-auth-not-working-password-not-saved/108597/9 "2017-11-22T14:38:44Z")

</div>

Thank you Alex! Do you know if this is fixed in v6.0? I am running an evaluation, non-production environment, so I can upgrade anytime.

Thanks,  
Tommaso

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 22, 2017, 3:01pm UTC](https://discuss.elastic.co/t/watcher-reporting-basic-auth-not-working-password-not-saved/108597/10 "2017-11-22T15:01:53Z")

</div>

Hey Tommaso,

no, it's not, the behaviour is the same.

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 20, 2017, 3:02pm UTC](https://discuss.elastic.co/t/watcher-reporting-basic-auth-not-working-password-not-saved/108597/11 "2017-12-20T15:02:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
