We are currently using Graylog v2.0.3 and I have defined the following alert condition:
Alert is triggered when there are more than 20 messages in the last 5 minutes. Grace period: 1 minute. Including last message in alert notification.
I am getting alerts when there are more than 20 messages counted in the last 5 minutes.
I am currently looking for some ‘back to normal’ alert so that in case there are less than 20 messages counted after 5 minutes I would expect to get an alert saying ‘number of messages counted in the last 5 minutes is for example 15 although the threshold is 20’ so I know it is all good again.
I will appreciate your assistance.