Graylog aggregation that shows message time delta from last message

Hello && Welcome

I might be able to help.

I found a couple post if your not aware of, that might help.

As for…

Graylog 4.x has a dashboard called Source. You should be able to see your message count from each source (device). You could use that for your alerts or graphs on the amount of data received. This would all depend on how you configured/installed your environment.

EDIT: Below I did a quick widget mockup. I added Group By source. Then added Metrics Count w/ field gl2_accounted_message_size. Basically the Default widget on Graylog’s Dashboard called Sources. As you can see it shows my sources (devices) and how many messages are within one hour. This helps keep an eye on the average amount of messages per hour. You can always modify it further.