# X-pack Watcher Slack JSON code

**URL:** https://discuss.elastic.co/t/x-pack-watcher-slack-json-code/96430
**Category:** Elasticsearch
**Tags:** elastic-stack-alerting
**Created:** [August 9, 2017, 11:40am UTC](https://discuss.elastic.co/t/x-pack-watcher-slack-json-code/96430 "2017-08-09T11:40:28Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![ninja](https://avatars.discourse-cdn.com/v4/letter/n/53a042/32.png) [@ninja](https://discuss.elastic.co/u/ninja)
#### Post date: [August 9, 2017, 11:40am UTC](https://discuss.elastic.co/t/x-pack-watcher-slack-json-code/96430/1 "2017-08-09T11:40:29Z")

</div>

Hello ,  
I've created a notify script in JSON for Watcher with Slack Integration . I created webhook that i added at minimal in elasticsearch.yml

Bellow is the script :

{  
"trigger": {  
"schedule": {  
"interval": "24h"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"winevents"  
],  
"types": [],  
"body": {  
"size": 0,  
"query": {  
"bool": {  
"must": {  
"match": {  
"event\_id": "4,647"  
}  
}  
}  
}  
}  
}  
}  
},  
"condition": {  
"compare": {  
"ctx.payload.hits.total": {  
"gte": 0  
}  
}  
},  
"actions": {  
"notify-slack": {  
"slack" : {  
"message" : {  
"text" : "Test"  
}  
}  
}  
}  
}

When i try to save it i receive the following error . Any ideas ?  
Watcher: [remote\_transport\_exception] [test-sec-n2][10.100.111.101:9300][cluster:admin/xpack/watcher/watch/put]

---

<div class="post-metadata">

### Author: ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)
#### Post date: [August 11, 2017, 7:04am UTC](https://discuss.elastic.co/t/x-pack-watcher-slack-json-code/96430/2 "2017-08-11T07:04:24Z")

</div>

Can you provide a full exception including stack trace and error message? Please copy and paste the full output of the curl call.

Also provide the Elasticsearch version you are using and all xpack specific configurations in the `elasticsearch.yml` file.

Thanks!

---

<div class="post-metadata">

### Author: ![ninja](https://avatars.discourse-cdn.com/v4/letter/n/53a042/32.png) [@ninja](https://discuss.elastic.co/u/ninja)
#### Post date: [August 11, 2017, 11:45am UTC](https://discuss.elastic.co/t/x-pack-watcher-slack-json-code/96430/3 "2017-08-11T11:45:43Z")

</div>

discovery.zen.ping.unicast.hosts: ["elk-test-sec-prod.test.local"]  
gateway.recover\_after\_nodes: 2  
xpack.security.enabled: true  
xpack.security.authc.realms:  
elastic:  
type: native  
order: 1  
test1:  
type: ldap  
order: 0  
url: "ldaps://ldap-1.test.us:636"  
bind\_dn: "uid=elkbind,ou=TT2,dc=test,dc=us"  
bind\_password: latreaba#  
user\_search.base\_dn: "ou=TT2,dc=test,dc=us"  
group\_search.base\_dn: "cn=TT1,ou=Groups,dc=test,dc=us"  
files:  
role\_mapping: "/etc/elasticsearch/x-pack/role\_mapping.yml"  
cache.ttl: 10m  
test2:  
type: active\_directory  
order: 2  
domain\_name: test.local  
url: ldaps://colo-dc1.test.local:636, ldaps://colo-dc2.test.local:636  
load\_balance:  
type: "failover"  
files:  
role\_mapping: "/etc/elasticsearch/x-pack/role\_mapping.yml"  
user\_search.base\_dn: "OU=test,OU=test,DC=test,DC=Local"  
group\_search.base\_dn: "ou=groups,ou=test,dc=test,dc=local"  
ssl:  
verification\_mode: none  
cache.ttl: 10m  
xpack.watcher.enabled : true

xpack.notification.slack:  
account:  
monitoring:  
url: [https://hooks.slack.com/services/REMOVED](https://hooks.slack.com/services/REMOVED)

---

<div class="post-metadata">

### Author: ![ninja](https://avatars.discourse-cdn.com/v4/letter/n/53a042/32.png) [@ninja](https://discuss.elastic.co/u/ninja)
#### Post date: [August 11, 2017, 11:48am UTC](https://discuss.elastic.co/t/x-pack-watcher-slack-json-code/96430/4 "2017-08-11T11:48:57Z")

</div>

how can i get the stack trace and error message ? The error message is :  
Watcher: [remote\_transport\_exception] [test-sec-n2][10.100.111.101:9300][cluster:admin/xpack/watcher/watch/put]

This in the browser...  
in elatic.log i don't have any error . Where shall i look for it ?  
Thx

---

<div class="post-metadata">

### Author: ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)
#### Post date: [August 11, 2017, 12:25pm UTC](https://discuss.elastic.co/t/x-pack-watcher-slack-json-code/96430/5 "2017-08-11T12:25:32Z")

</div>

Please take your time and add proper formatting to your posts, this makes it hard to read (and on top of that indentation is important!).

Also, please tell us which elasticsearch version this is.

The above remote transport exception is not returned to the browser or an HTTP client. You would get back a formatted JSON response, and that is what I am also interested in.

Thanks.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 8, 2017, 12:25pm UTC](https://discuss.elastic.co/t/x-pack-watcher-slack-json-code/96430/6 "2017-09-08T12:25:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
