Skip to content
Castreon
Monitoring & server

Notifications — e-mail, Telegram, webhook

Updated 08 Oct 2026

Castreon can tell you by itself when something goes wrong with a channel: it went down, switched to a backup source, shows a black or frozen picture, lost its sound. Messages go out by e-mail, on Telegram or to a webhook, and you also get a message when the problem is over.

Available from Castreon 1.2.0, on all plans.

Setup

Open Settings → Notifications, switch on Send notifications, then switch on the destinations you want. Each destination has its own Send a test button, which sends a message right away with the data in the form (before saving) and shows the result or the exact error.

E-mail (SMTP)

  • SMTP server and Port, Security: STARTTLS (587), TLS (465) or No encryption (25).
  • User and Password — leave User empty if the server needs no authentication. The password is only sent over an encrypted connection.
  • From — the sender address; To — one or more addresses separated by commas (at most 10).

Telegram

  1. In Telegram, create a bot with @BotFather — you get the Bot token.
  2. Add the bot to the group or channel where you want the messages (to a channel as an administrator), or write to it once yourself.
  3. Chat ID: your own ID for a private chat, the group's ID (it starts with -100…) or the channel's name (@name).

Webhook (JSON)

Castreon sends a POST with a JSON body to the Webhook address. The body also contains the ready-written message in the text and content fields, so it works directly with chat services that only show a text.

{
  "source": "castreon",
  "server": "node-1",
  "sent_at": "2026-10-08T10:01:20Z",
  "test": false,
  "title": "Channel down",
  "events": [
    {"type": "down", "family": "down", "channel_id": "…", "slug": "channel-1", "channel": "Channel 1",
     "message": "…", "since": "2026-10-08T10:00:00Z", "at": "2026-10-08T10:01:20Z", "duration_s": 80}
  ],
  "text": "…",
  "content": "…"
}

type is down, up, failover, primary, alert or resolved; for alerts, code says which one (for example black_picture).

Signature. With a Signing secret (16–200 characters, Generate makes one), every request carries the headers X-Castreon-Timestamp and X-Castreon-Signature: sha256=…. The signature is the HMAC-SHA256 of timestamp + "." + body with your secret. Check it on your side and reject requests that are too old.

The webhook address is kept on the server and not shown again: many services put the access key in the address.

What gets announced

Under What to announce you choose the families:

Family When
Channel down the channel is not running for longer than the threshold (error, restarts, the source down and the “no signal” image on air) — and when it is back
Switch to backup the channel runs on a backup source — and when it is back on the main one
Picture and sound black or frozen picture, silent audio, output without new segments — see Picture and sound quality
DVB source the operator's programme gaps, a service gone from the mux
Push outputs RIST / SRT / UDP / RTMP outputs that do not reach their destination
Resources and stability high memory, falling behind real time, restarts too often
Information the same programme on several channels, HDR transcoded to SDR — off by default

A channel you stop from the panel, switch off or delete announces nothing.

No flood of messages

  • Announce only what lasts longer than — 60 seconds by default. Short gaps and quick restarts send nothing.
  • Also announce the recovery — only for problems that were announced.
  • Same problem on the same channel at most once every — 30 minutes by default.
  • What happens within the same 20 seconds goes out as one grouped message (for example “17 channels: …”).
  • At most 20 messages per hour per destination. Messages held back are counted and mentioned in the next one.

Language and links

  • Message language: Same as the panel, or English, Romanian, German, Italian, Spanish.
  • Server name in messages — empty = the machine name. Useful when you have several servers.
  • Panel address (optional) — with it, each message has a link straight to the channel's page.

Latest messages shows the last 20 sendings: time, destination, what was sent and whether it went out. Each destination also shows its last error and how many messages it sent in the last hour.

Security

The SMTP password, the Telegram token, the webhook address and the signing secret are kept on the server and never shown again: after saving, the field shows that a value is saved. Leave it empty to keep it, or type a new value. They don't appear in API responses, in the audit log or in the diagnostic report.

Common problems

  • E-mail: the server refuses the login or closes the connection: check the port and Security pair — 587 with STARTTLS, 465 with TLS. Many providers require an app password.
  • Telegram: chat not found: the bot hasn't been added to the group or channel, or nobody has written to it yet in a private chat.
  • Webhook: HTTP 4xx / 5xx: the message shows the status code returned by your service; the test sends exactly what a real message sends.
  • The test works, but nothing comes during an outage: check that the family is ticked and that the problem lasted longer than the threshold.

Privacy

Cookies & local storage

Strictly necessary cookies are always active. Analytics and marketing use Google services and only start if you accept them — until then nothing is sent to Google. You can withdraw your consent here at any time.

Strictly necessary

Without them, sign-in, forms and your chosen language don’t work. They don’t require consent (§ 25(2) no. 2 TDDDG).

Always active
Name Purpose Duration Type
castreon-session Keeps your session: sign-in and chosen language 2 hours, renewed on every visit Cookie
XSRF-TOKEN Protects forms against forged requests 2 hours, renewed on every visit Cookie
remember_web_… Only if you tick “Remember me” at sign-in Until you sign out, max. 400 days Cookie
__cf_bm Cloudflare: tells visitors and bots apart, only when traffic is being checked 30 minutes Cookie · Cloudflare
castreon:consent Remembers your cookie choice 12 months Local storage
theme Customer account appearance: light, dark or system Until you change it Local storage

Analytics

Google Analytics 4 (Google Ireland Ltd.): which pages are visited, where visits come from and on which type of device — with pseudonymous identifiers, without storing your IP address. Helps us improve the website.

Name Purpose Duration Type
_ga Google Analytics: recognises the visitor (pseudonymous ID) 13 months Cookie · Google Analytics
_ga_VHWQRPHPEF Google Analytics: keeps the state of the visit 13 months Cookie · Google Analytics

Marketing

Google Ads (Google Ireland Ltd.): measures whether visits from Google ads lead to a trial or a plan, and allows Castreon ads to be shown on other websites (remarketing).

Name Purpose Duration Type
_gcl_au, _gcl_aw Google Ads: links the visit to the ad click (conversions) 90 days Cookie · Google Ads
IDE, test_cookie Google Ads: remarketing and ad measurement, on Google domains (doubleclick.net) Up to 13 months Cookie · Google (third party)