# Alerts - Notifications

**URL:** <https://community.graylog.org/t/alerts-notifications/17612>\
**Category:** Graylog Central (peer support)\
**Created:** [October 23, 2020, 2:57pm UTC](https://community.graylog.org/t/alerts-notifications/17612 "2020-10-23T14:57:35Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![marick](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/marick/32/1418_2.png) [@marick](https://community.graylog.org/u/marick)\
**Post date:** [October 23, 2020, 2:57pm UTC](https://community.graylog.org/t/alerts-notifications/17612/1 "2020-10-23T14:57:35Z")

</div>

hello everyone,

Our alerts are never up to date with Graylog 3.3.8, centOS 8, elasticsearch 6.8.13, mongodb 4.4.1  
I see in _/var/lib/graylog-server/journal/graylog2-committed-read-offset_  
36  
In _/var/lib/graylog-server/journal/recovery-point-offset-checkpoint_  
0  
1  
messagejournal 0 37

We are monitoring some logs with very few errors. Alerts are always lagging behind with last errors scanned in past 10 seconds. We write ERROR 3 in log we get mail with previous ERROR 2 and so on.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/5/53e55f95b575bf939b4f53a4e92965076dc1cb5b.png)  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/0/033e46f8865142b46d02ded4163a046d20690f74.png)  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/c/ce87cc3604600ddd768ccb5a604a4578db61a5ce.png)

No errors at all in logs. Any thoughts guys? Where we are getting it wrong… please help! 🙂

---

<div class="post-metadata">

**Author:** ![marick](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/marick/32/1418_2.png) [@marick](https://community.graylog.org/u/marick)\
**Post date:** [October 29, 2020, 11:02am UTC](https://community.graylog.org/t/alerts-notifications/17612/2 "2020-10-29T11:02:17Z")

</div>

Always behind with one step  
Incoming message from **2020-10-29 12:49:49 +02:00** trigger event fom  
**2020-10-29 12:11:50.497** and so on and so on

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/0/03debc57f3008e4e9e5f66445a88509290265790.png)  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/0/039572491ac1453418db3a4360be866e68d4424c.png)

Anyone with the same problem?

---

<div class="post-metadata">

**Author:** ![joe.gross](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/joe.gross/32/13372_2.png) [@joe.gross](https://community.graylog.org/u/joe.gross)\
**Post date:** [October 29, 2020, 8:07pm UTC](https://community.graylog.org/t/alerts-notifications/17612/3 "2020-10-29T20:07:49Z")

</div>

Your time window is too small. You are searching every ten seconds over the previous ten seconds. It takes time for an event to move from collection, through processing in Graylog, then into Elasticsearch, where the alert query can then search for it. It is not unusual for that process to take as long as 30 seconds or longer, depending on the Elasticsearch refresh interval setting.

The time stamp, however, will be applied during the period of time when it was passing through Graylog. If the timestamp is added to the message at second 1, then it takes 15 seconds to get from the Input on Graylog into Elasticsearch and another two seconds before Elasticsearch indexes and stores it, any search over the past ten seconds will fail.

Try expanding it to a search over the past one or two minutes. I think you’ll find all the alerts start to show up as expected.

---

<div class="post-metadata">

**Author:** ![marick](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/marick/32/1418_2.png) [@marick](https://community.graylog.org/u/marick)\
**Post date:** [October 29, 2020, 8:57pm UTC](https://community.graylog.org/t/alerts-notifications/17612/4 "2020-10-29T20:57:56Z")

</div>

Hey Chris! Thank you very much for your answer but it didn’t help. Changed to 1 min, then 2 min and it didn’t change the behavior. Restart of graylog-server and the hole machine also didn’t change nothing.  
I have no errors in logs (graylog, sidecar, elastic, mongod) and it used to work in graylog 2.4 even with 10 second search/execute.  
Any other suggestions - highly appreciated. Thanks again!

---

<div class="post-metadata">

**Author:** ![joe.gross](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/joe.gross/32/13372_2.png) [@joe.gross](https://community.graylog.org/u/joe.gross)\
**Post date:** [October 29, 2020, 9:17pm UTC](https://community.graylog.org/t/alerts-notifications/17612/5 "2020-10-29T21:17:06Z")

</div>

Looking at the time ranges involved, I notice that you are running the query at 17:46, but the next time range begins at 16:40:19. When a notification is sent, how far in the past is it reporting on?

I wonder if your processing is backed up? When you look at System/Nodes?Details, do you see either the processor buffer or journal filling up, or consistently above a single digit percentage?

---

<div class="post-metadata">

**Author:** ![marick](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/marick/32/1418_2.png) [@marick](https://community.graylog.org/u/marick)\
**Post date:** [October 30, 2020, 8:02am UTC](https://community.graylog.org/t/alerts-notifications/17612/6 "2020-10-30T08:02:51Z")

</div>

**When a notification is sent, how far in the past is it reporting on?**  
It reports just the last message that I wrote in the oracle database alertlog with: sql\> exec dbms\_system.ksdwrt(3,‘ORA-36’); For example: I write: exec dbms\_system.ksdwrt(3,‘ORA-37’); then it will send me a mail with previous ORA-36 that I wrote earlier.

**I wonder if your processing is backed up? When you look at System/Nodes?Details, do you see either the processor buffer or journal filling up, or consistently above a single digit percentage?**  
It is always at 0.00%. I installed it 3-4 weeks ago and I was testing with just one oracle database alert log where I or occasionally database is writing very few errors.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/9/900095a58e85ca3a6ed0f073466da657fcf24e6a.png)  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/b/b172b0805702e9dd8bec57946d703772596f9ae7.png)

Actually Graylog works very fast even with 10 second search/execute (with or without backlog messages) but somehow events/alerts are lagging behind with -1.

CONTENT OF **/var/lib/graylog-server/journal/messagejournal-0/00000000000000000119.log** 1572/1572 100%  
…w…t®.  
…=_6 …ë.Áªär.Ú…è…ë… 6_=…ڞräªÁ.!.Âsxu…\*-  
.beats.${“source”:{“no\_beats\_prefix”:false}}2B  
$e88d3431-4d88-4708-a01c-2c033908c523…5f92be1b03217d779a1cbeb6:

.À¨.X…´.BÉ.{"@timestamp":“2020-10-30T07:40:52.756Z”,"@metadata":{“beat”:“filebeat”,“type”:"\_doc",“version”:“7.8.1”},“log”:{“offset”:539662,“file”:{“path”:"/u01/  
app/oracle/diag/rdbms/dev/DEV/trace/alert\_DEV.log"}},“message”:“ORA-38”,“input”:{“type”:“log”},“gl2\_source\_collector”:“223aa2xxxxxxxxxxxx258ad718”,"  
collector\_node\_id":“oratest”,“ecs”:{“version”:“1.5.0”},“host”:{“name”:“oratest”},“agent”:{“version”:“7.8.1”,“hostname”:“oratest”,“ephemeral\_id”:“da1ec79  
b-e529-4a6c-882a-fb922d81b4a2”,“id”:“3adc7c78-b0fa-4f06-a8e8-128ad009bd89”,“name”:“oratest”,“type”:“filebeat”}}…x…æñ.\>…[0…ë.Áªär.Ú…è…ë.  
…0[…ڞräªÁ.!é.txu…\*-  
.beats.${“source”:{“no\_beats\_prefix”:false}}2B  
$e88d3431-4d88-4708-a01c-2c033908c523…5f92be1b03217d779a1cbeb6:

.À¨.X…´.BÉ.{"@timestamp":“2020-10-30T07:41:42.778Z”,"@metadata":{“beat”:“filebeat”,“type”:"\_doc",“version”:“7.8.1”},“message”:“ORA-39”,“input”:{“type”:“log”},“g  
l2\_source\_collector”:“223aa277xxxxxxxxx258ad718”,“collector\_node\_id”:“oratest”,“ecs”:{“version”:“1.5.0”},“host”:{“name”:“oratest”},“agent”:{“ver  
sion”:“7.8.1”,“hostname”:“oratest”,“ephemeral\_id”:“da1ec79b-e529-4a6c-882a-fb922d81b4a2”,“id”:“3adc7c78-b0fa-4f06-a8e8-128ad009bd89”,“name”:“oratest”,“type  
“:“filebeat”},“log”:{“offset”:540224,“file”:{“path”:”/u01/app/oracle/diag/rdbms/dev/DEV/trace/alert\_DEV.log”}}}

Even if I see message ORA-39 in [http://192.168.x.xx:9000/search](http://192.168.x.xx:9000/search) an event/alert for this message is not triggered.

Thank you, Chris!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [November 13, 2020, 8:03am UTC](https://community.graylog.org/t/alerts-notifications/17612/7 "2020-11-13T08:03:05Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
