Logstash输出到Teams Webhook报HTTP 400错误求助
Logstash调用Teams Webhook返回400错误,curl/Postman调用正常
报错信息
[2023-06-28T10:04:05,828][ERROR][logstash.outputs.http][main][a426c749e290f2ae6144df4f0d2c91d791cf4273431bcb4fffb17f1f69460f74] [HTTP Output Failure] Encountered non-2xx HTTP code 400 {:response_code=>400, :url=> "https://elsgre.webhook.office.com/webhookb2/xx", :event=>#<LogStash::Event:0x6cfcf570>}
可正常工作的curl命令
curl -X POST \ -H "Content-Type: application/json" \ -d '{"text": "postman test2"}' \ "https://elsgre.webhook.office.com/webhookb2/xx"
当前Logstash配置
input { file { path => "/opt/testLog/test.log" sincedb_path => "/dev/null" start_position => "beginning" mode => "read" file_completed_action => "log" file_completed_log_path => "/tmp/logstash-completed.log" codec => plain { charset => "UTF-8" } tags => ["logstash-file-input"] } } filter { } output { http { url => "https://elsgre.webhook.office.com/webhookb2/xx" http_method => "post" format => "json" content_type => "application/json" message => '{"text": "postman test2"}' } }
Debug输出片段
config LogStash::Outputs::Http/@format = "json" config LogStash::Outputs::Http/@http_method = "post" config LogStash::Outputs::Http/@id = "xxxxx" config LogStash::Outputs::Http/@content_type = "application/json" config LogStash::Outputs::Http/@message = "{\"text\": \"postman test2\"}" config LogStash::Outputs::Http/@url = "https://elsgre.webhook.office.com/webhookb2/xx" config LogStash::Outputs::Http/@enable_metric = true config LogStash::Outputs::Http/@codec = <LogStash::Codecs::Plain id=>"plain_4be9fafa-86ac-4d87-8ba2-b5b24252c424", enable_metric=>true, charset=>"UTF-8"> config LogStash::Outputs::Http/@workers = 1 config LogStash::Outputs::Http/@request_timeout = 60 config LogStash::Outputs::Http/@socket_timeout = 10 config LogStash::Outputs::Http/@connect_timeout = 10 config LogStash::Outputs::Http/@follow_redirects = true config LogStash::Outputs::Http/@pool_max = 50 config LogStash::Outputs::Http/@pool_max_per_route = 25 config LogStash::Outputs::Http/@keepalive = true config LogStash::Outputs::Http/@automatic_retries = 1 config LogStash::Outputs::Http/@retry_non_idempotent = false config LogStash::Outputs::Http/@validate_after_inactivity = 200 config LogStash::Outputs::Http/@keystore_type = "JKS" config LogStash::Outputs::Http/@truststore_type = "JKS" config LogStash::Outputs::Http/@cookies = true config LogStash::Outputs::Http/@headers = {} config LogStash::Outputs::Http/@retry_failed = true config LogStash::Outputs::Http/@retryable_codes = [429, 500, 502, 503, 504] config LogStash::Outputs::Http/@http_compression = false
解决方法
问题根源在于format => "json"的配置:当启用该参数时,Logstash会把整个事件对象(包含message字段及其他元数据)序列化为JSON发送给Teams Webhook,而非直接发送message字段的内容。而Teams Webhook仅接受{"text": "xxx"}这类简洁结构的请求体,因此返回400错误。
可通过以下两种方式修复:
方式1:修改format为message
将输出配置的format改为message,让Logstash直接发送message字段的内容作为请求体:
output { http { url => "https://elsgre.webhook.office.com/webhookb2/xx" http_method => "post" content_type => "application/json" format => "message" message => '{"text": "postman test2"}' # 如果需要发送日志文件中的内容,可改为:message => '{"text": "%{message}"}' } }
方式2:使用body参数(Logstash 7.x及以上版本)
新版本的Logstash Http输出支持body参数,可直接指定请求体内容,无需依赖format配置:
output { http { url => "https://elsgre.webhook.office.com/webhookb2/xx" http_method => "post" content_type => "application/json" body => '{"text": "postman test2"}' # 若需动态插入日志内容:body => '{"text": "%{message}"}' } }
修改配置后重启Logstash,即可正常向Teams Webhook发送消息。
内容的提问来源于stack exchange,提问作者J C
相关产品推荐
相关产品推荐

