# Graylog 4.1.5 - Notifications - One Mail per Event - No Backlog

**URL:** https://community.graylog.org/t/graylog-4-1-5-notifications-one-mail-per-event-no-backlog/21487
**Category:** Graylog Central (peer support)
**Created:** [October 18, 2021, 11:51am UTC](https://community.graylog.org/t/graylog-4-1-5-notifications-one-mail-per-event-no-backlog/21487 "2021-10-18T11:51:37Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![KPS](https://avatars.discourse-cdn.com/v4/letter/k/4491bb/32.png) [@KPS](https://community.graylog.org/u/KPS)
#### Post date: [October 18, 2021, 11:51am UTC](https://community.graylog.org/t/graylog-4-1-5-notifications-one-mail-per-event-no-backlog/21487/1 "2021-10-18T11:51:37Z")

</div>

Hi!

I am trying to setup a notification for aggregated events:  
“Filter has results”, Search every 2 min within 2 min, Mail Notification, backlog 50.

But:  
One mail is triggered for _each_ event - although they happen within one second. Backlog does always contain one single message and:

Timerange Start: ${event.timerange\_start}  
Timerange End: ${event.timerange\_end}  
 → Both Timeranges are empty.

Do you have any idea, why this happens and how to solve this?

Thank you and best wishes!  
KPS

---

<div class="post-metadata">

### Author: ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)
#### Post date: [October 18, 2021, 9:50pm UTC](https://community.graylog.org/t/graylog-4-1-5-notifications-one-mail-per-event-no-backlog/21487/2 "2021-10-18T21:50:32Z")

</div>

Hello && Welcome

To help you further I need to ask a couple question. Maybe we can narrow it down.

1. When these event come in are they all together or to they arrived every 2 minutes? If so have you tried to expand you search time?
2. What version of Graylog are you using?
3. Can you show you full configuration of your alert Definition?
4. What have you done/tried to resolve this issue ?

---

<div class="post-metadata">

### Author: ![KPS](https://avatars.discourse-cdn.com/v4/letter/k/4491bb/32.png) [@KPS](https://community.graylog.org/u/KPS)
#### Post date: [October 19, 2021, 6:00am UTC](https://community.graylog.org/t/graylog-4-1-5-notifications-one-mail-per-event-no-backlog/21487/3 "2021-10-19T06:00:16Z")

</div>

Hi!

> When these event come in are they all together or to they arrived every 2 minutes?  
> As written in my post: The events arrive in a small timeframe - mostly within one second

> What version of Graylog are you using?  
> 4.1.5 community

> Can you show you full configuration of your alert Definition?  
> Which part of the config is missing? Filter is working on Stream “All messages”. Search query is: (cat:GPOMgmtReports OR cat:ADVGPOReports) AND NOT cs4:“Computer Version (Sysvol)”

> What have you done/tried to resolve this issue ?  
> I tried to increase the timeframe, but as is seems to be ignored, nothing changed

---

<div class="post-metadata">

### Author: ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)
#### Post date: [October 19, 2021, 6:15am UTC](https://community.graylog.org/t/graylog-4-1-5-notifications-one-mail-per-event-no-backlog/21487/4 "2021-10-19T06:15:24Z")

</div>

Hello,  
Maybe try to adjust you Grace Period?

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/f/f508f04c8e24eca9baee406443a7f0ca0f69708c.png)

My apologies, I just realize you put your GL version in the title of this post.

---

<div class="post-metadata">

### Author: ![KPS](https://avatars.discourse-cdn.com/v4/letter/k/4491bb/32.png) [@KPS](https://community.graylog.org/u/KPS)
#### Post date: [October 19, 2021, 6:37am UTC](https://community.graylog.org/t/graylog-4-1-5-notifications-one-mail-per-event-no-backlog/21487/5 "2021-10-19T06:37:48Z")

</div>

Hi!

I tried graceperiod, but there is still not a mail with “multiple” backlog-messages. But: now, some messages are just lost.

If a message arrives \<60s after the first one, it does just not trigger any notification.

Do you have any other idea?  
Thank you for your help

---

<div class="post-metadata">

### Author: ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)
#### Post date: [October 19, 2021, 9:42pm UTC](https://community.graylog.org/t/graylog-4-1-5-notifications-one-mail-per-event-no-backlog/21487/6 "2021-10-19T21:42:49Z")

</div>

Hello,

> [@KPS](#):
>
> there is still not a mail with “multiple” backlog-messages

Let me sum this up so I can get a better idea what’s going on.

1. You are receiving logs from your remote devices in a small time frame, correct?
2. Filter configuration is set to Search within the last 2 minutes & Execute search every 2 Minutes and the search query configuration/s is working fine? Does it look like this?

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/4/4701cd3ecf27fee37ed512b71e73b8c379ec295b.png)

1. The Grace Period is set to 0 with a back log of 50?, If so, that a lot of backlogs.
2. You receive one email notification with one back log?
3. You want one email with 50 backlogs?

If this is all correct I would try the following to see if that helps. First I would match my notification grace period with my search query.  
Something like this.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/8/8e75dd7d5072bfb863135895c061d9def08f110a.png)

Then I would check my Notification template.  
configuration. should look something like this.

```auto
--- [Event Definition] ---------------------------
Title: ${event_definition_title}
Description: ${event_definition_description}
Type: ${event_definition_type}
--- [Event] --------------------------------------
Timestamp: ${event.timestamp}
Message: ${event.message}
Source: ${event.source}
Key: ${event.key}
Priority: ${event.priority}
Alert: ${event.alert}
Streams: ${event.streams}
Source Stream: ${event.source_streams}
Timerange Start: ${event.timerange_start}
Timerange End: ${event.timerange_end}
Fields:
${foreach event.fields field} ${field.key}: ${field.value}
${end}
${if backlog}
--- [Backlog] ------------------------------------
Last messages accounting for this alert:
${foreach backlog message}
${message}
${end}
${end}

```

If all of those are set then I would check your Aggregation configurations, I’m assume at this point that your configurations may look like this.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/8/844188702d424e3ba251c88b3b76c567defab272.png)

Hope that helps

---

<div class="post-metadata">

### Author: ![KPS](https://avatars.discourse-cdn.com/v4/letter/k/4491bb/32.png) [@KPS](https://community.graylog.org/u/KPS)
#### Post date: [October 20, 2021, 6:23am UTC](https://community.graylog.org/t/graylog-4-1-5-notifications-one-mail-per-event-no-backlog/21487/7 "2021-10-20T06:23:38Z")

</div>

Hi!

Thank you for helping me!  
I just found my mistake. I was not aware, that I need to set aggregation on the count to get the backlog. Now, everything is working fine!

Thank you!

---

<div class="post-metadata">

### Author: ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)
#### Post date: [October 20, 2021, 6:26am UTC](https://community.graylog.org/t/graylog-4-1-5-notifications-one-mail-per-event-no-backlog/21487/8 "2021-10-20T06:26:16Z")

</div>

That’s great. Glad I could help . 🙂

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)
#### Post date: [November 3, 2021, 6:26am UTC](https://community.graylog.org/t/graylog-4-1-5-notifications-one-mail-per-event-no-backlog/21487/9 "2021-11-03T06:26:26Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
