# Event definition not triggering Notification

**URL:** https://community.graylog.org/t/event-definition-not-triggering-notification/34434
**Category:** Graylog Central (peer support)
**Tags:** alert
**Created:** [December 12, 2024, 12:20pm UTC](https://community.graylog.org/t/event-definition-not-triggering-notification/34434 "2024-12-12T12:20:08Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Bjoern1234](https://avatars.discourse-cdn.com/v4/letter/b/4bbf92/32.png) [@Bjoern1234](https://community.graylog.org/u/Bjoern1234)
#### Post date: [December 12, 2024, 12:20pm UTC](https://community.graylog.org/t/event-definition-not-triggering-notification/34434/1 "2024-12-12T12:20:08Z")

</div>

I want to be notified when there are any FATAL messages. But Graylog is not sending the notification.

What I made:

- defined email notification with my Reply-To email address. It’s working.
- defined event with right stream and search query. Filter preview shows messages.
- other configuration:
  - Search within the last: 1 hour (for test, to be sure it will find any messages)
  - Execute search every: 1 minutes
  - Create Events for Definition if: Rule: count() \> 0

- Notification: wired with the previous defined notification
  - Grace Period: Unchecked
  - Message Backlog: Checked, 1

In the Event Definitions list it shows in

- ‘Last Matched’: 2 days ago. Why is that not working?
- Status: enabled
- Scheduling: Runs every 1 minutes, searching within the last 1 hour
- Scheduling Info: Status runnable,
  - Next execution: current time + 1 min,
  - Queued notifications: 0 \<== what’s the meaning of that?

- More \> Replay search: opens query with count() = 23 =\> so it should trigger the alert?

I use Graylog 6.1.2 Open

- List item

Did I missed something?

---

<div class="post-metadata">

### Author: ![patrickmann](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/patrickmann/32/9091_2.png) [@patrickmann](https://community.graylog.org/u/patrickmann)
#### Post date: [December 12, 2024, 3:19pm UTC](https://community.graylog.org/t/event-definition-not-triggering-notification/34434/2 "2024-12-12T15:19:10Z")

</div>

Event processor looks at indexed messages, so if indexing is backlogged there can be a delay. But since replay shows messages, it should be firing.  
Have you tried testing with a different notification type, e.g. HTTP? That would show up immediately when it fires.

---

<div class="post-metadata">

### Author: ![Bjoern1234](https://avatars.discourse-cdn.com/v4/letter/b/4bbf92/32.png) [@Bjoern1234](https://community.graylog.org/u/Bjoern1234)
#### Post date: [December 18, 2024, 5:12pm UTC](https://community.graylog.org/t/event-definition-not-triggering-notification/34434/3 "2024-12-18T17:12:53Z")

</div>

I solved the problem.  
I created new Event Definition exactly the same as the previous one with the same notification.  
I don’t see any differences in the definition, but it works.  
Thanks for the support.

---

<div class="post-metadata">

### Author: ![patrickmann](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/patrickmann/32/9091_2.png) [@patrickmann](https://community.graylog.org/u/patrickmann)
#### Post date: [December 19, 2024, 7:42am UTC](https://community.graylog.org/t/event-definition-not-triggering-notification/34434/4 "2024-12-19T07:42:35Z")

</div>

That’s strange. Glad you solved your issue. If it happens again, it would be interesting to drill down more to try and understand the root cause.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)
#### Post date: [January 2, 2025, 7:43am UTC](https://community.graylog.org/t/event-definition-not-triggering-notification/34434/5 "2025-01-02T07:43:07Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
