# Logstash-hipchat messages are not displaying in hipchat

**URL:** <https://discuss.elastic.co/t/logstash-hipchat-messages-are-not-displaying-in-hipchat/52611>\
**Category:** Logstash\
**Created:** [June 13, 2016, 12:56pm UTC](https://discuss.elastic.co/t/logstash-hipchat-messages-are-not-displaying-in-hipchat/52611 "2016-06-13T12:56:49Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![babeesh](https://avatars.discourse-cdn.com/v4/letter/b/e47c2d/32.png) [@babeesh](https://discuss.elastic.co/u/babeesh)\
**Post date:** [June 13, 2016, 12:56pm UTC](https://discuss.elastic.co/t/logstash-hipchat-messages-are-not-displaying-in-hipchat/52611/1 "2016-06-13T12:56:49Z")

</div>

Hi,

I have redirected logs recieving in logstash to hipchat.

```
output {
 if [type]== 'eventlog' {

    hipchat {
      room_id => ' ****'
      token => ' ****'
          }

    elasticsearch {
      hosts => ['172.30.0.206:9200']
              }
         }
      }

```

But in hipchat it is showing like

**logstash · logstash·5:58 PM**  
**%{message}**

**logstash · logstash·6:08 PM**  
**%{message}**  
No content in message field. What may be the issue?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 14, 2016, 3:47am UTC](https://discuss.elastic.co/t/logstash-hipchat-messages-are-not-displaying-in-hipchat/52611/2 "2016-06-14T03:47:11Z")

</div>

What does the rest of your config look like? What does the data look like?  
What version are you on?

---

<div class="post-metadata">

**Author:** ![babeesh](https://avatars.discourse-cdn.com/v4/letter/b/e47c2d/32.png) [@babeesh](https://discuss.elastic.co/u/babeesh)\
**Post date:** [June 14, 2016, 5:54am UTC](https://discuss.elastic.co/t/logstash-hipchat-messages-are-not-displaying-in-hipchat/52611/3 "2016-06-14T05:54:45Z")

</div>

Logstash configuration:

```
input {
 tcp {
   port => 5045
   type => 'eventlog'
   codec =>"json"
     }
   }

filter {
 if [type]== 'eventlog' {

    hipchat {
      room_id => ' *****'
      token => ' ****'
          }
    elasticsearch {
      hosts => ['172.30.0.206:9200']
              }
         }
      }

```

In kibana, it looks like

```
{
  "_index": "logstash-2016.06.14",
  "_type": "eventlog",
  "_id": "AVVNbiXCoy4-TtrOUrmi",
  "_score": null,
  "_source": {
    "EventTime": "2016-06-14 11:11:47",
    "Hostname": "xx.xx.x",
    "Keywords": 2305843009213694000,
    "EventType": "ERROR",
    "SeverityValue": 4,
    "Severity": "ERROR",
    "EventID": 216,
    "SourceName": "Microsoft-Windows-ServerManager-MultiMachine",
    "ProviderGuid": "{D8D37081-10BD-4A89-A971-1CDA6899BDB3}",
    "Version": 0,
    "Task": 17,
    "OpcodeValue": 0,
    "RecordNumber": 3369760,
    "ProcessID": 4988,
    "ThreadID": 6944,
    "Channel": "Microsoft-Windows-ServerManager-MultiMachine/Operational",
    "Domain": "ONTASHINDIA",
    "AccountName": "Administrator",
    "UserID": "Administrator",
    "AccountType": "User",
    "Message": "Invoke method error. Server: localhost, Namespace: root\\microsoft\\windows\\servermanager, Class: MSFT_ServerManagerTasks, Method: GetCounterSamplesInTimeRange, Error: A general error occurred that is not covered by a more specific error code.",
    "Category": "Node access.",
    "Opcode": "Info",
    "serverName": "localhost",
    "namespaceName": "root\\microsoft\\windows\\servermanager",
    "wmiClassName": "MSFT_ServerManagerTasks",
    "methodName": "GetCounterSamplesInTimeRange",
    "protocol": "DCOM",
    "error": "A general error occurred that is not covered by a more specific error code.",
    "EventReceivedTime": "2016-06-14 11:11:49",
    "SourceModuleName": "eventlog",
    "SourceModuleType": "im_msvistalog",
    "@version": "1",
    "@timestamp": "2016-06-14T05:41:50.634Z",
    "host": "x.x.x.x",
    "port": 60831,
    "type": "eventlog",
    "tags": [
      "_grokparsefailure"
    ]
  },
  "fields": {
    "@timestamp": [
      1465882910634
    ]
  },
  "sort": [
    1465882910634
  ]
}

```

I am using nxlog in windows server to ship logs to logstash.

Version

Elasticsearch 2.2.x, Logstash 2.2.x, and Kibana 4.4.x.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 14, 2016, 6:09am UTC](https://discuss.elastic.co/t/logstash-hipchat-messages-are-not-displaying-in-hipchat/52611/4 "2016-06-14T06:09:26Z")

</div>

That is not a valid config, you cannot have an output like that in a filter.

---

<div class="post-metadata">

**Author:** ![babeesh](https://avatars.discourse-cdn.com/v4/letter/b/e47c2d/32.png) [@babeesh](https://discuss.elastic.co/u/babeesh)\
**Post date:** [June 14, 2016, 9:09am UTC](https://discuss.elastic.co/t/logstash-hipchat-messages-are-not-displaying-in-hipchat/52611/5 "2016-06-14T09:09:13Z")

</div>

Oh.. Sorry. That is a copy paste mistake. correct config is :

```
input {
 tcp {
   port => 5045
   type => 'eventlog'
   codec =>"json"
     }
   }

filter {
    if [type] == "eventlog" and [Severity] == "WARNING" {
    drop { }
  }

  if [type] == "eventlog" and [Severity] == "INFO" {
    drop { }
  }
}

output {
 if [type]== 'eventlog' {

    hipchat {
      room_id => ' ****'
      token => ' ****'
          }

    elasticsearch {
      hosts => ['172.30.0.206:9200']
              }
         }
      }
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 15, 2016, 5:49am UTC](https://discuss.elastic.co/t/logstash-hipchat-messages-are-not-displaying-in-hipchat/52611/6 "2016-06-15T05:49:52Z")

</div>

As you don't have a `message` in your events you'll want to adjust the hipchat output's `format` option.

---

<div class="post-metadata">

**Author:** ![babeesh](https://avatars.discourse-cdn.com/v4/letter/b/e47c2d/32.png) [@babeesh](https://discuss.elastic.co/u/babeesh)\
**Post date:** [June 15, 2016, 5:55am UTC](https://discuss.elastic.co/t/logstash-hipchat-messages-are-not-displaying-in-hipchat/52611/7 "2016-06-15T05:55:48Z")

</div>

What format should I use in hipchat output in logstash for displaying messages?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 15, 2016, 5:56am UTC](https://discuss.elastic.co/t/logstash-hipchat-messages-are-not-displaying-in-hipchat/52611/8 "2016-06-15T05:56:20Z")

</div>

Use `stdout { codec => rubydebug}` to see what is generated and go from there.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 15, 2016, 5:57am UTC](https://discuss.elastic.co/t/logstash-hipchat-messages-are-not-displaying-in-hipchat/52611/9 "2016-06-15T05:57:46Z")

</div>

What do you want the messages sent to HipChat to contain?

---

<div class="post-metadata">

**Author:** ![babeesh](https://avatars.discourse-cdn.com/v4/letter/b/e47c2d/32.png) [@babeesh](https://discuss.elastic.co/u/babeesh)\
**Post date:** [June 15, 2016, 6:00am UTC](https://discuss.elastic.co/t/logstash-hipchat-messages-are-not-displaying-in-hipchat/52611/10 "2016-06-15T06:00:15Z")

</div>

I need **Source, date time, severity level, message title, message description**  
in hipchat

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 15, 2016, 6:03am UTC](https://discuss.elastic.co/t/logstash-hipchat-messages-are-not-displaying-in-hipchat/52611/11 "2016-06-15T06:03:09Z")

</div>

Then adjust the hipchat output's `format` option accordingly.

```nohighlight
hipchat {
  ...
  format => "%{SourceName} %{Severity} ..."
}

```

[https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#logstash-config-field-references](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#logstash-config-field-references)

---

<div class="post-metadata">

**Author:** ![babeesh](https://avatars.discourse-cdn.com/v4/letter/b/e47c2d/32.png) [@babeesh](https://discuss.elastic.co/u/babeesh)\
**Post date:** [June 17, 2016, 10:55am UTC](https://discuss.elastic.co/t/logstash-hipchat-messages-are-not-displaying-in-hipchat/52611/12 "2016-06-17T10:55:44Z")

</div>

> [@](#):
>
> hipchat {  
> ...  
> format =\> "%{SourceName} %{Severity} ..."  
> }

This worked for me.

In hipchat logs are showing in the format :

`Microsoft-Windows-ServerManager-MultiMachine 2016-06-17 11:28:45 ERROR Invoke method error. Server: localhost, Namespace: root\microsoft\windows\servermanager, Class: MSFT_ServerManagerTasks, Method: GetCounterSamplesInTimeRange, Error: A general error occurred that is not covered by a more specific error code`

Is it possible to make each fields in seperate lines? Like

**SourceName**  
**Date Time**  
**Severity**  
**Message**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:52am UTC](https://discuss.elastic.co/t/logstash-hipchat-messages-are-not-displaying-in-hipchat/52611/13 "2017-07-06T04:52:14Z")

</div>


