You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Logstash输出到Teams Webhook报HTTP 400错误求助

Logstash调用Teams Webhook返回400错误,curl/Postman调用正常

报错信息

[2023-06-28T10:04:05,828][ERROR][logstash.outputs.http][main][a426c749e290f2ae6144df4f0d2c91d791cf4273431bcb4fffb17f1f69460f74] [HTTP Output Failure] Encountered non-2xx HTTP code 400 {:response_code=>400, :url=> "https://elsgre.webhook.office.com/webhookb2/xx", :event=>#<LogStash::Event:0x6cfcf570>}

可正常工作的curl命令

curl -X POST \
      -H "Content-Type: application/json" \
      -d '{"text": "postman test2"}' \
      "https://elsgre.webhook.office.com/webhookb2/xx"

当前Logstash配置

input {
   file {
     path => "/opt/testLog/test.log"
     sincedb_path => "/dev/null"
     start_position => "beginning"
     mode => "read"
     file_completed_action => "log"
     file_completed_log_path => "/tmp/logstash-completed.log"
     codec => plain { charset => "UTF-8" }
     tags => ["logstash-file-input"]
   }
}

filter {
}

output {
   http {
     url => "https://elsgre.webhook.office.com/webhookb2/xx"
     http_method => "post"
     format => "json"
     content_type => "application/json"
     message => '{"text": "postman test2"}'
   }
}

Debug输出片段

config LogStash::Outputs::Http/@format = "json"
config LogStash::Outputs::Http/@http_method = "post"
config LogStash::Outputs::Http/@id = "xxxxx"
config LogStash::Outputs::Http/@content_type = "application/json"
config LogStash::Outputs::Http/@message = "{\"text\": \"postman test2\"}"
config LogStash::Outputs::Http/@url = "https://elsgre.webhook.office.com/webhookb2/xx"
config LogStash::Outputs::Http/@enable_metric = true
config LogStash::Outputs::Http/@codec = <LogStash::Codecs::Plain id=>"plain_4be9fafa-86ac-4d87-8ba2-b5b24252c424", enable_metric=>true, charset=>"UTF-8">
config LogStash::Outputs::Http/@workers = 1
config LogStash::Outputs::Http/@request_timeout = 60
config LogStash::Outputs::Http/@socket_timeout = 10
config LogStash::Outputs::Http/@connect_timeout = 10
config LogStash::Outputs::Http/@follow_redirects = true
config LogStash::Outputs::Http/@pool_max = 50
config LogStash::Outputs::Http/@pool_max_per_route = 25
config LogStash::Outputs::Http/@keepalive = true
config LogStash::Outputs::Http/@automatic_retries = 1
config LogStash::Outputs::Http/@retry_non_idempotent = false
config LogStash::Outputs::Http/@validate_after_inactivity = 200
config LogStash::Outputs::Http/@keystore_type = "JKS"
config LogStash::Outputs::Http/@truststore_type = "JKS"
config LogStash::Outputs::Http/@cookies = true
config LogStash::Outputs::Http/@headers = {}
config LogStash::Outputs::Http/@retry_failed = true
config LogStash::Outputs::Http/@retryable_codes = [429, 500, 502, 503, 504]
config LogStash::Outputs::Http/@http_compression = false

解决方法

问题根源在于format => "json"的配置:当启用该参数时,Logstash会把整个事件对象(包含message字段及其他元数据)序列化为JSON发送给Teams Webhook,而非直接发送message字段的内容。而Teams Webhook仅接受{"text": "xxx"}这类简洁结构的请求体,因此返回400错误。

可通过以下两种方式修复:

方式1:修改format为message

将输出配置的format改为message,让Logstash直接发送message字段的内容作为请求体:

output {
   http {
     url => "https://elsgre.webhook.office.com/webhookb2/xx"
     http_method => "post"
     content_type => "application/json"
     format => "message"
     message => '{"text": "postman test2"}'
     # 如果需要发送日志文件中的内容,可改为:message => '{"text": "%{message}"}'
   }
}

方式2:使用body参数(Logstash 7.x及以上版本)

新版本的Logstash Http输出支持body参数,可直接指定请求体内容,无需依赖format配置:

output {
   http {
     url => "https://elsgre.webhook.office.com/webhookb2/xx"
     http_method => "post"
     content_type => "application/json"
     body => '{"text": "postman test2"}'
     # 若需动态插入日志内容:body => '{"text": "%{message}"}'
   }
}

修改配置后重启Logstash,即可正常向Teams Webhook发送消息。


内容的提问来源于stack exchange,提问作者J C

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 00:23:16