# Backlog and alerting via mail

**URL:** https://community.graylog.org/t/backlog-and-alerting-via-mail/11781
**Category:** Graylog Central (peer support)
**Created:** [September 2, 2019, 6:06am UTC](https://community.graylog.org/t/backlog-and-alerting-via-mail/11781 "2019-09-02T06:06:32Z")
**Posts on this page:** 12
**Page:** 1

<div class="post-metadata">

### Author: ![110719](https://avatars.discourse-cdn.com/v4/letter/1/a88e4f/32.png) [@110719](https://community.graylog.org/u/110719)
#### Post date: [September 2, 2019, 6:06am UTC](https://community.graylog.org/t/backlog-and-alerting-via-mail/11781/1 "2019-09-02T06:06:32Z")

</div>

Hi graylog team,

since i’m using “backlog” i have some issue with alerting via mail. I receive everytime 3 (same)mails.

my Condition :

 ![grafik](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/9/9c5e88ee01ecf932dca455c6136bc2716647f56b.png)

Alert :  
\*\*\*\*\*\*\*\*\*\* graylog \*\*\*\*\*\*\*\*\*\*  
Alert Description: {check\_result.resultDescription} Date: {check\_result.triggeredAt}  
Alert Condition Title: {alertCondition.title} {if stream\_url}Stream URL: {stream\_url}{end}  
{if backlog} Last messages accounting for this alert: {foreach backlog message}  
Source: {message.source} {end}{else}\<No backlog\> {end}

* * *

Mail :  
first mail :  
\*\*\*\*\*\*\*\*\*\* graylog \*\*\*\*\*\*\*\*\*\* Alert Description: Stream received messages matching message:“Error” (Current grace time: 0 minutes)  
Date: 2019-09-01T18:46:28.942Z  
Alert Condition Title: Error  
Stream URL: [https://graylog.example.com/streams/000000000000000000000001/messages?rangetype=absolute&from=2019-09-01T18:41:28.942Z&to=2019-09-01T18:46:28.942Z&q=\*](https://graylog.example.com/streams/000000000000000000000001/messages?rangetype=absolute&from=2019-09-01T18:41:28.942Z&to=2019-09-01T18:46:28.942Z&q=*)

* * *

Last messages accounting for this alert:  
Message:Error: limit exceededSource:www.mydomain.com

second mail :

\*\*\*\*\*\*\*\*\*\* graylog \*\*\*\*\*\*\*\*\*\* Alert Description: Stream received messages matching message:“Error” (Current grace time: 0 minutes)  
Date: 2019-09-01T18:46:28.942Z  
Alert Condition Title: Error  
Stream URL: [https://graylog.example.com/streams/000000000000000000000001/messages?rangetype=absolute&from=2019-09-01T18:41:28.942Z&to=2019-09-01T18:46:28.942Z&q=\*](https://graylog.example.com/streams/000000000000000000000001/messages?rangetype=absolute&from=2019-09-01T18:41:28.942Z&to=2019-09-01T18:46:28.942Z&q=*)

* * *

Last messages accounting for this alert:  
Message:Error: limit exceededSource:www.mydomain.com

third mail :

\*\*\*\*\*\*\* graylog \*\*\*\*\*\*\*\*\*\* Alert Description: Stream received messages matching message:“Error” (Current grace time: 0 minutes)  
Date: 2019-09-01T18:46:28.942Z  
Alert Condition Title: Error  
Stream URL: [https://graylog.example.com/streams/000000000000000000000001/messages?rangetype=absolute&from=2019-09-01T18:41:28.942Z&to=2019-09-01T18:46:28.942Z&q=\*](https://graylog.example.com/streams/000000000000000000000001/messages?rangetype=absolute&from=2019-09-01T18:41:28.942Z&to=2019-09-01T18:46:28.942Z&q=*)

* * *

Last messages accounting for this alert:  
Source:www.mydomain.com

I would be really grateful if you could answer my question.

---

<div class="post-metadata">

### Author: ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)
#### Post date: [September 2, 2019, 6:27am UTC](https://community.graylog.org/t/backlog-and-alerting-via-mail/11781/2 "2019-09-02T06:27:09Z")

</div>

have you checked if the recipient is a Mailinglist or an alias that duplicates the message?

---

<div class="post-metadata">

### Author: ![110719](https://avatars.discourse-cdn.com/v4/letter/1/a88e4f/32.png) [@110719](https://community.graylog.org/u/110719)
#### Post date: [September 2, 2019, 6:42am UTC](https://community.graylog.org/t/backlog-and-alerting-via-mail/11781/3 "2019-09-02T06:42:03Z")

</div>

Hi @jan ,

thanks for your quick answer, there is only one mail as recipient for this alarm. Is there any way to debug sending mail for each alert or any logfiles which shows, how many mails and when the mails were sent ? Where are the path of alert and condition on server ?

---

<div class="post-metadata">

### Author: ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)
#### Post date: [September 2, 2019, 7:08am UTC](https://community.graylog.org/t/backlog-and-alerting-via-mail/11781/4 "2019-09-02T07:08:35Z")

</div>

all logs are in one location, that is on most installations `/var/log/graylog/server.log` (but we wrote down most default locations in the docs: [http://docs.graylog.org/en/3.1/pages/configuration/file\_location.html](http://docs.graylog.org/en/3.1/pages/configuration/file_location.html) ).

If you can’t find a notice about the mail you could raise the logging in Graylog to info or similar. The other option would be - check the logfile of your mailserver.

---

<div class="post-metadata">

### Author: ![110719](https://avatars.discourse-cdn.com/v4/letter/1/a88e4f/32.png) [@110719](https://community.graylog.org/u/110719)
#### Post date: [September 2, 2019, 8:00am UTC](https://community.graylog.org/t/backlog-and-alerting-via-mail/11781/5 "2019-09-02T08:00:39Z")

</div>

@jan

i couldn’t find any related logs in debug mode and on `/var/log/graylog/server.log`. The Logs of Mailserver shows that each time was 3x mails sent.  
Could you please review my backlog config again and check if it’s 100% ok and give some idee to find the issue ? As i mentioned the issue is since i’m using `backlog`.

Thanks.

---

<div class="post-metadata">

### Author: ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)
#### Post date: [September 2, 2019, 8:44am UTC](https://community.graylog.org/t/backlog-and-alerting-via-mail/11781/6 "2019-09-02T08:44:39Z")

</div>

E-Mail is the notification - so the reason might be in the condition.

I’m not able to debug that and give a reason for you. It is very likely that the reason is in your configuration.

Check if you might have copied the condition multiple times, or the have multiple notifications.

---

<div class="post-metadata">

### Author: ![110719](https://avatars.discourse-cdn.com/v4/letter/1/a88e4f/32.png) [@110719](https://community.graylog.org/u/110719)
#### Post date: [September 2, 2019, 9:16am UTC](https://community.graylog.org/t/backlog-and-alerting-via-mail/11781/7 "2019-09-02T09:16:07Z")

</div>

@jan

i’m using 3 differents Conditions :

```
    exception (Field Content Alert Condition)
    Alerting on stream All messages
Message Backlog : 1

    outofmemory (Field Content Alert Condition)
        Alerting on stream All messages
Message Backlog : 1

    Error (Field Content Alert Condition)
        Alerting on stream All messages
Message Backlog : 1

```

and 3 Notifications with same names “`exception, outofmemory, Error`” .

i assume that there is copies of (multiple) condition which is not shown on graylog GUI but it exist on server. Where can i find this conditions / Notifications on server ?

What’s the next step to find the issue ?

We’re going to use graylog on more 200x servers and it’s very important for us to solve the issue.

---

<div class="post-metadata">

### Author: ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)
#### Post date: [September 2, 2019, 10:20am UTC](https://community.graylog.org/t/backlog-and-alerting-via-mail/11781/8 "2019-09-02T10:20:23Z")

</div>

Did you have 3 conditions and 3 notifications on the same stream?

the connection between condition and notification is the stream. That means ONE condition is true, all Notifications for that stream are fired…

If you do not want that - update Graylog to 3.1 to the new alert and notification system.

---

<div class="post-metadata">

### Author: ![110719](https://avatars.discourse-cdn.com/v4/letter/1/a88e4f/32.png) [@110719](https://community.graylog.org/u/110719)
#### Post date: [September 2, 2019, 11:59am UTC](https://community.graylog.org/t/backlog-and-alerting-via-mail/11781/9 "2019-09-02T11:59:58Z")

</div>

Hi @jan

> [@jan](#):
>
> Did you have 3 conditions and 3 notifications on the same stream?

yes, it’s correct. should i have only ONE notification for ALL 3 conditions?

> [@jan](#):
>
> If you do not want that - update Graylog to 3.1 to the new alert and notification system.

should i remove all 3 notifications after update to 3.1 and create only ONE for all 3 (old) conditions ?

---

<div class="post-metadata">

### Author: ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)
#### Post date: [September 2, 2019, 12:14pm UTC](https://community.graylog.org/t/backlog-and-alerting-via-mail/11781/10 "2019-09-02T12:14:54Z")

</div>

As I have written:

> the connection between condition and notification is the stream. That means ONE condition is true, all Notifications for that stream are fired…

* * *

The alerting in 3.1 is different. When you update, you will notice that.

---

<div class="post-metadata">

### Author: ![110719](https://avatars.discourse-cdn.com/v4/letter/1/a88e4f/32.png) [@110719](https://community.graylog.org/u/110719)
#### Post date: [September 3, 2019, 2:07pm UTC](https://community.graylog.org/t/backlog-and-alerting-via-mail/11781/11 "2019-09-03T14:07:10Z")

</div>

@jan

thanks for your tip.  
Best regards.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)
#### Post date: [September 17, 2019, 2:07pm UTC](https://community.graylog.org/t/backlog-and-alerting-via-mail/11781/12 "2019-09-17T14:07:12Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
