# Logstash + TG

**URL:** <https://discuss.elastic.co/t/logstash-tg/362776>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [July 9, 2024, 8:31am UTC](https://discuss.elastic.co/t/logstash-tg/362776 "2024-07-09T08:31:22Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![TatianaKlimova91](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tatianaklimova91/32/135900_2.png) [@TatianaKlimova91](https://discuss.elastic.co/u/TatianaKlimova91)\
**Post date:** [July 9, 2024, 8:31am UTC](https://discuss.elastic.co/t/logstash-tg/362776/1 "2024-07-09T08:31:22Z")

</div>

Hi there!  
I try to set logstash.config to send alerts to telegram bot.  
I added in output section http part and recreated logstash container, but still can’t get alerts. Locally from api alerts are working.  
Logstash placed in k8s.  
Any suggestions and personal experience very appreciated 🙏🏼  
What setting and where i need to add? I didn’t find in internet any detailed instructions.  
Thanks

---

<div class="post-metadata">

**Author:** ![jessgarson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jessgarson/32/129841_2.png) [@jessgarson](https://discuss.elastic.co/u/jessgarson)\
**Post date:** [July 11, 2024, 6:17pm UTC](https://discuss.elastic.co/t/logstash-tg/362776/2 "2024-07-11T18:17:11Z")

</div>

Thanks so much for reaching out, @TatianaKlimova91. Can you say a bit more about how you are sending the requests to Telegram? Do you have a code sample you can provide?

I have seen a few older posts on this topic as well that could be helpful:

- [Logstash config file alerting in telegram](https://discuss.elastic.co/t/logstash-config-file-alerting-in-telegram/217730)
- [How to make alerts with telegram bot?](https://discuss.elastic.co/t/how-to-make-alerts-with-telegram-bot/282794)

---

<div class="post-metadata">

**Author:** ![TatianaKlimova91](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tatianaklimova91/32/135900_2.png) [@TatianaKlimova91](https://discuss.elastic.co/u/TatianaKlimova91)\
**Post date:** [July 13, 2024, 10:12am UTC](https://discuss.elastic.co/t/logstash-tg/362776/3 "2024-07-13T10:12:42Z")

</div>

Yes, i alreade have checked these posts, but unfortunately the suggestion there were not helpful:(  
The example code og logstash.conf in pipline folder is:

input {  
Some code }

filter {  
Some code }

output {  
elasticsearch plugin output {}  
If “string pattern” in [log] {  
http plugin { here some code for tg api which works ok from pod by curl request  
url =\> “url here”  
http\_method =\> “post”  
format =\> message  
content\_type =\> “application/json”  
message =\> ‘{“chat\_id”: “id here”, “text”: “text here”}’}  
}  
}

So, code pattern looks like this. I need to add that when i add http-input-plugin or exec-input-plugin with curl it works fine. The issue is only related with output http plugin.

Mb i missed something?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [July 13, 2024, 3:54pm UTC](https://discuss.elastic.co/t/logstash-tg/362776/4 "2024-07-13T15:54:12Z")

</div>

Telegram url should have the https connection which means you are missing `cacert` and `ssl_verification_mode` parameters.

---

<div class="post-metadata">

**Author:** ![TatianaKlimova91](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tatianaklimova91/32/135900_2.png) [@TatianaKlimova91](https://discuss.elastic.co/u/TatianaKlimova91)\
**Post date:** [July 14, 2024, 8:33am UTC](https://discuss.elastic.co/t/logstash-tg/362776/5 "2024-07-14T08:33:42Z")

</div>

Okay, i ll check, thank you for advice!

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 14, 2024, 1:28pm UTC](https://discuss.elastic.co/t/logstash-tg/362776/6 "2024-07-14T13:28:29Z")

</div>

Telegram uses public and know CAs, there is no need for it.

> [@TatianaKlimova91](#):
>
> input {  
> Some code }
> 
> filter {  
> Some code }
> 
> output {  
> elasticsearch plugin output {}  
> If “string pattern” in [log] {  
> http plugin { here some code for tg api which works ok from pod by curl request  
> url =\> “url here”  
> http\_method =\> “post”  
> format =\> message  
> content\_type =\> “application/json”  
> message =\> ‘{“chat\_id”: “id here”, “text”: “text here”}’}  
> }  
> }

Can you change your output to a file and see if you are getting any events? If you are getting events with the `file` output, but not with the `http` output, then your issue may be in the configuration of the http output and you would probably have some logs in logstash logs.

---

<div class="post-metadata">

**Author:** ![TatianaKlimova91](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tatianaklimova91/32/135900_2.png) [@TatianaKlimova91](https://discuss.elastic.co/u/TatianaKlimova91)\
**Post date:** [July 22, 2024, 9:08am UTC](https://discuss.elastic.co/t/logstash-tg/362776/7 "2024-07-22T09:08:38Z")

</div>

It didn't help, there are no any outputs at all. I can't understand why output plugin doesn't work. Have you got example workable config for check? mb video tutorial?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [July 22, 2024, 7:34pm UTC](https://discuss.elastic.co/t/logstash-tg/362776/8 "2024-07-22T19:34:05Z")

</div>

1. Make sure that data has been arrived - use input, nothing in the filter, and output to ruby debug or txt file.
2. Make sure that any data has been arrived another way - use [LS node statistic](http://localhost:9600/_node/stats/pipelines?pretty). LS should provide the JSON some thing like this:

```auto
"events" : {
        "duration_in_millis" : 3500,
        "in" : 10,
        "filtered" : 10,
        "out" : 10,...

```

For more info, check [the documentation](https://www.elastic.co/guide/en/logstash/current/node-stats-api.html#pipeline-stats)

1. Change `log.level= trace` and restart LS.
2. If data is coming, check every condition, especially  
` if “string pattern” in [log] {...`

---

<div class="post-metadata">

**Author:** ![TatianaKlimova91](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tatianaklimova91/32/135900_2.png) [@TatianaKlimova91](https://discuss.elastic.co/u/TatianaKlimova91)\
**Post date:** [July 22, 2024, 8:11pm UTC](https://discuss.elastic.co/t/logstash-tg/362776/9 "2024-07-22T20:11:27Z")

</div>

Thank you for reply, will check next time.  
I decided to use grafana+elastic+telegram and this configuration works well for my goals.  
Mb next time i will back to this question, now it could be closed
