Monitor failed logins in Telegram
Catch the login failures that look like an attack — repeated misses from one address — with geo and network context attached before they reach you.
01source
02pipeline · 3 steps
- 01CTLfilter.matchattempt ≥ 5 only
- 02ENRenrich.entityip → geo · asn · known-bad
- 03MUTredact.piimask email before posting
03destinations · 1
- totelegramTelegramchat@oncall
the event
You emit login.failed with this shape. The TypeScript SDK keeps the call type-safe, and the event is stored whole — so every field below is available to the pipeline by name.
- emailstring
- ipstring
- reasonstringbad-password | locked | mfa
- attemptnumberconsecutive misses
emit it
From your code with the TypeScript SDK — or any language over the REST endpoint and signed webhook ingress.
import { ingest } from "@ingestlayer/sdk";
await ingest("login.failed", {
email: creds.email,
ip: req.ip,
reason: result.reason,
attempt: result.consecutive,
});route it to Telegram
Message a person, group, or channel through a connected bot.
- 01
connect a bot
Create a bot with @BotFather and paste its token. We register the webhook and verify it in-region.
- 02
start a chat
Send /start to the bot from the target chat — or add it to the group/channel — then pick the chat from the list.
- 03
format the text
Messages use MarkdownV2; the default template bolds the event name and lists fields. Reserved characters in field values are escaped for you.
oncall *support.ticket.created* ticket T-4821 subject API returning 500s tier enterprise urgency critical
notes
- Telegram caps a bot at roughly 30 messages per second overall, and one per second to a single chat.
- The bot must be added to a group — and promoted to admin for a channel — before it can post.
- MarkdownV2 requires escaping characters like _ * [ ] ( ); ingestlayer escapes field values, but custom templates are your responsibility.
questions
- How do I avoid alerting on typos?
- Filter on the attempt count so a single fat-fingered password stays quiet and only sustained failures escalate.
- Where does the geo come from?
- enrich.entity resolves the IP to geo, ASN, and a known-bad flag in flight, so the alert carries the context to act on.
- Is it safe to post emails to a channel?
- redact.pii masks the email for the chat destination while the full record still lands in your audit table.
failed logins, routed elsewhere
- Monitor failed logins in SlackSlack
- Monitor failed logins in DiscordDiscord
- Monitor failed logins in EmailEmail
- Monitor failed logins in WebhookWebhook
- Monitor failed logins in PostgresPostgres
- Monitor failed logins in NotionNotion
more, into Telegram
- Track user signups in Telegramtrack
- Monitor failed payments in Telegrammonitor
- Route support escalations in Telegramalert
- Track waitlist signups in Telegramtrack
- Track new subscriptions in Telegramtrack
- Track canceled subscriptions in Telegramtrack
- Track successful payments in Telegramtrack
- Track trial conversions in Telegramtrack
- Track form submissions in Telegramtrack
- Track feature usage in Telegramtrack
- Track file uploads in Telegramtrack
- Monitor usage-limit hits in Telegrammonitor
- Monitor error spikes in Telegrammonitor
- Monitor cron-job health in Telegrammonitor
- Monitor CI/CD build status in Telegrammonitor
- Flag high-value leads in Telegramalert
- Catch churn-risk signals in Telegramalert
- everything you can pipe to Telegramhub