# alerts on graylog 

**URL:** <https://community.graylog.org/t/alerts-on-graylog/35270>\
**Category:** New to Graylog Community? READ-ME FIRST Guides\
**Tags:** alert\
**Created:** [March 21, 2025, 11:49am UTC](https://community.graylog.org/t/alerts-on-graylog/35270 "2025-03-21T11:49:25Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mouayedoss](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/mouayedoss/32/17737_2.png) [@mouayedoss](https://community.graylog.org/u/mouayedoss)\
**Post date:** [March 21, 2025, 11:49am UTC](https://community.graylog.org/t/alerts-on-graylog/35270/1 "2025-03-21T11:49:26Z")

</div>

I am using Graylog 6.1.8, and I have created a stream and a notification. I tried to simulate a DDoS attack on my PC, but I am receiving too many emails for every event. I want to group them and receive an email only if the DDoS logs exceed 70 or 80."

Let me know if it works!

---

<div class="post-metadata">

**Author:** ![Wine\_Merchant](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/wine_merchant/32/14596_2.png) [@Wine\_Merchant](https://community.graylog.org/u/Wine_Merchant)\
**Post date:** [March 21, 2025, 11:58am UTC](https://community.graylog.org/t/alerts-on-graylog/35270/2 "2025-03-21T11:58:00Z")

</div>

Hey @mouayedoss,

This is possible, you will need to group the logs by something like the source\_ip of the firewall and maybe also perhaps whichever field is being used to contain the IP of the attacker. In the below example the destination\_ip is simply being used as an example.

 ![Screenshot 2025-03-21 at 11.54.56](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/b/3/b3a355781e4fd3d50dc8f3ac9dee0c740304bdcd.png)
