# Sending Logs to Slack

**URL:** <https://discuss.elastic.co/t/sending-logs-to-slack/41000>\
**Category:** Logstash\
**Created:** [February 4, 2016, 7:59pm UTC](https://discuss.elastic.co/t/sending-logs-to-slack/41000 "2016-02-04T19:59:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![cotcadaver](https://avatars.discourse-cdn.com/v4/letter/c/a88e4f/32.png) [@cotcadaver](https://discuss.elastic.co/u/cotcadaver)\
**Post date:** [February 4, 2016, 7:59pm UTC](https://discuss.elastic.co/t/sending-logs-to-slack/41000/1 "2016-02-04T19:59:39Z")

</div>

Hey guys,  
I am having trouble understanding why my instance of logstash isn't sending the files to slack. I was hoping a pair of fresh eyes may be able to find my mistakes. I am simply using an Ubuntu server and am wanting to send some of the server's own logs as a test.

```
input{
  file{
     path => "/var/log/apt/history.log"
  }
}

filter{
  grok{
     match => {"message" =>"%{GREEDYDATA:message}"}
  }
}

output {
  slack {
     url => "MY_SLACK_WEBHOOK"
     channel => "#logs-syslog"
  }
}
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 4, 2016, 8:01pm UTC](https://discuss.elastic.co/t/sending-logs-to-slack/41000/2 "2016-02-04T20:01:54Z")

</div>

Are new lines being appended to the end of history.log, which Logstash is tailing?

---

<div class="post-metadata">

**Author:** ![cotcadaver](https://avatars.discourse-cdn.com/v4/letter/c/a88e4f/32.png) [@cotcadaver](https://discuss.elastic.co/u/cotcadaver)\
**Post date:** [February 4, 2016, 8:18pm UTC](https://discuss.elastic.co/t/sending-logs-to-slack/41000/3 "2016-02-04T20:18:50Z")

</div>

That is my understanding of how the logs are set up.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 4, 2016, 8:38pm UTC](https://discuss.elastic.co/t/sending-logs-to-slack/41000/4 "2016-02-04T20:38:27Z")

</div>

If you replace the slack output with `stdout { codec => rubydebug }`, you get output?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:13am UTC](https://discuss.elastic.co/t/sending-logs-to-slack/41000/5 "2017-07-06T05:13:00Z")

</div>


