# Watcher status Failure

**URL:** <https://discuss.elastic.co/t/watcher-status-failure/191588>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [July 22, 2019, 6:52am UTC](https://discuss.elastic.co/t/watcher-status-failure/191588 "2019-07-22T06:52:11Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![anaxagoras.kosta](https://avatars.discourse-cdn.com/v4/letter/a/848f3c/32.png) [@anaxagoras.kosta](https://discuss.elastic.co/u/anaxagoras.kosta)\
**Post date:** [July 22, 2019, 6:52am UTC](https://discuss.elastic.co/t/watcher-status-failure/191588/1 "2019-07-22T06:52:11Z")

</div>

I happened to install ELK 7.2 for testing purposes.  
We came across the alert system (Watchers) but unfortunately we cant make it work.  
Log file is in txt file (json format):  
// [{"date":"19-07-2019 04:33:46pm","error":"Error","error\_description":"Description"},{"date":"19-07-2019 04:49:43pm","error":"Error","error\_description":"Description"},{"date":"21-07-2019 06:19:55pm","error":"Error","error\_description":"Description"}]

We use slack to print out the messages with  
//"body": "{{ctx.payload.hits.hits.0.\_source.message}}",

This gives us this response  
//"id" : "send\_trigger",  
"type" : "webhook",  
"status" : "failure",  
"reason" : "received [400] status code",  
"body" : """date":"21-07-2019 07:33:16pm","error":"Error","error\_description":"Description"},{"date":"21-07-2019 08:31:49pm","error":"Error","error\_description":"Description"}]{"date":"22-07-2019 09:15:30am","error":"Error","error\_description":"Description"}]ion"}]"""  
},

This is the whole code and response we are getting.  
Any help, would be much appreciated.

[https://pastebin.com/rWvjgmKf](https://pastebin.com/rWvjgmKf)

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 1, 2019, 12:17pm UTC](https://discuss.elastic.co/t/watcher-status-failure/191588/2 "2019-08-01T12:17:08Z")

</div>

It looks to me as if you do not properly format the message that you want to sent to slack. The `message` field of the first search result is

```auto
date":"21-07-2019 07:33:16pm","error":"Error","error_description":"Description"},{"date":"21-07-2019 08:31:49pm","error":"Error","error_description":"Description"}]{"date":"22-07-2019 09:15:30am","error":"Error","error_description":"Description"}]ion"}]

```

and this is send **exactly** as is to slack. This is not valid JSON and thus you are getting an error.

You can either construct the JSON yourself, or you are going to use the [slack action](https://www.elastic.co/guide/en/elastic-stack-overview/7.2/actions-slack.html) instead.

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 29, 2019, 12:17pm UTC](https://discuss.elastic.co/t/watcher-status-failure/191588/3 "2019-08-29T12:17:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
