# Graylog Alert Fields are not getting filled when using a Threshold

**URL:** <https://community.graylog.org/t/graylog-alert-fields-are-not-getting-filled-when-using-a-threshold/32885>\
**Category:** Graylog Central (peer support)\
**Created:** [July 1, 2024, 9:51am UTC](https://community.graylog.org/t/graylog-alert-fields-are-not-getting-filled-when-using-a-threshold/32885 "2024-07-01T09:51:27Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![roaringkitty](https://avatars.discourse-cdn.com/v4/letter/r/cab0a1/32.png) [@roaringkitty](https://community.graylog.org/u/roaringkitty)\
**Post date:** [July 1, 2024, 9:51am UTC](https://community.graylog.org/t/graylog-alert-fields-are-not-getting-filled-when-using-a-threshold/32885/1 "2024-07-01T09:51:27Z")

</div>

Hello, Graylog Developers and Community

I really need help with this problem as soon as possible. When I’m in the event definition and choose “Create Events for Definition if filter has results,” for example, Event Limit at 1 or any number, the fields in my Microsoft Teams and my emails are filled with the information from the log.

However, when I choose “Create Events for Definition if Aggregation of results reaches a threshold,” for example, a count of 2 for example if only device vendor is trend micro and the event\_class\_id 393 appearing twice, because I only want to get notified when one of the events appears twice in the last 10 minutes, my fields in Teams or email notifications are not getting filled. How can I fix this problem?

I hope my Screenshots provide you guys with enough information, if you need more let me know. But i dont know, what could I do to fix this problem. (Please ignore the ,Search within the last 5xx Hours, so i just did not have to trigger an Event all time again to test the Notification)

I would appreciate it, if someone could help me please

**2. Describe your environment:**

- OS Information:  
Windows
- Package Version:  
6.0.2

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/7/b/7bfe762e1af4af51c7b5a69e414cb1ccf5d69781.png)  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/8/6/862b80061b6ee555e847faef6909f5fd94621d5c.png)  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/1/d/1d1d9cb2a0a6a6b95aff55d8c07f916f32d60681.png)

Now with Threshold:

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/4/a/4a53536350aa7223577092d31cf25b51e6ff62af.png)  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/d/2/d2aca3e9935e5871700899a5ca35a3ec4d5f0075.png)  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/e/2/e2d02a3578c03eb1c7987a42605d54c583efc756.png)

---

<div class="post-metadata">

**Author:** ![Arie](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/arie/32/8094_2.png) [@Arie](https://community.graylog.org/u/Arie)\
**Post date:** [July 1, 2024, 11:17am UTC](https://community.graylog.org/t/graylog-alert-fields-are-not-getting-filled-when-using-a-threshold/32885/2 "2024-07-01T11:17:24Z")

</div>

There are several solutions for this if I heve this correct.

This happens possibly because you execute this query every minute or faster.

What you could do is execute your search every ten minutes and search back for the past ten minutes.

Another solution is a grace period of nine or ten minutes to solve this in the Notifications tab.

---

<div class="post-metadata">

**Author:** ![roaringkitty](https://avatars.discourse-cdn.com/v4/letter/r/cab0a1/32.png) [@roaringkitty](https://community.graylog.org/u/roaringkitty)\
**Post date:** [July 1, 2024, 12:08pm UTC](https://community.graylog.org/t/graylog-alert-fields-are-not-getting-filled-when-using-a-threshold/32885/3 "2024-07-01T12:08:43Z")

</div>

Hey Arie,

Thank you, first of all, for your proposed solutions.

I just tried both options, but my fields are still empty. Do you have another solution for me that I could try, please?

---

<div class="post-metadata">

**Author:** ![Joel\_Duffield](https://avatars.discourse-cdn.com/v4/letter/j/71c47a/32.png) [@Joel\_Duffield](https://community.graylog.org/u/Joel_Duffield)\
**Post date:** [July 1, 2024, 2:38pm UTC](https://community.graylog.org/t/graylog-alert-fields-are-not-getting-filled-when-using-a-threshold/32885/4 "2024-07-01T14:38:25Z")

</div>

Im away from my computer today, but Im fairly certain that you can only get field values that are used in the group by of the aggregation, or the output of the aggregation themselves (count=5). Because its an aggregation each message could have a different value in that field, so what value is it supposed to use in the message is the issue.

---

<div class="post-metadata">

**Author:** ![roaringkitty](https://avatars.discourse-cdn.com/v4/letter/r/cab0a1/32.png) [@roaringkitty](https://community.graylog.org/u/roaringkitty)\
**Post date:** [July 1, 2024, 4:58pm UTC](https://community.graylog.org/t/graylog-alert-fields-are-not-getting-filled-when-using-a-threshold/32885/5 "2024-07-01T16:58:32Z")

</div>

So if I understand it correctly, it depends on what I choose for the “Group By” of the aggregation? Should it be the same as the “Fields”? And okay, the output you mean will just give me the number for which I adjust the threshold, like = 3, so it will give me 3 back, right?

---

<div class="post-metadata">

**Author:** ![Arie](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/arie/32/8094_2.png) [@Arie](https://community.graylog.org/u/Arie)\
**Post date:** [July 3, 2024, 9:15am UTC](https://community.graylog.org/t/graylog-alert-fields-are-not-getting-filled-when-using-a-threshold/32885/6 "2024-07-03T09:15:48Z")

</div>

Hi Thai,

Have you taken al look at the aggregation function to do this. At firts you need to have an Search Query that works, and after that you can create a aggregation that counts up to the messages within a period. Your period should be 10 minutes, and repeated every minute if 2 massages within 10 minutes is what is needed.

 ![afbeelding](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/f/2/f27ae2ec5a874a3135d28c043a8bc361dcb72c44.png)

---

<div class="post-metadata">

**Author:** ![roaringkitty](https://avatars.discourse-cdn.com/v4/letter/r/cab0a1/32.png) [@roaringkitty](https://community.graylog.org/u/roaringkitty)\
**Post date:** [July 9, 2024, 6:12am UTC](https://community.graylog.org/t/graylog-alert-fields-are-not-getting-filled-when-using-a-threshold/32885/7 "2024-07-09T06:12:09Z")

</div>

Hi Arie,

Yes i already look at the aggregation function and I have an Query that works, and yes I know how to count up to the messages. But I think you dont understand what i want in my Thread. Because it seems like my problem can not be fixed, I spoke with people and they told me already, that it is not possible to get the information what i needed like in the attaced screenshot with the Aggregation and its only possible to get like the counter of like how many messages, matches the query in like the last 10 minutes and so on. But thank you very much for your time

---

<div class="post-metadata">

**Author:** ![Arie](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/arie/32/8094_2.png) [@Arie](https://community.graylog.org/u/Arie)\
**Post date:** [July 9, 2024, 8:21am UTC](https://community.graylog.org/t/graylog-alert-fields-are-not-getting-filled-when-using-a-threshold/32885/8 "2024-07-09T08:21:24Z")

</div>

Hi Thai,

Maybe not with the default alerting system, but you could check the plugins for their capabilities like this one. There are several.

> [@Alert Wizard plugin for Graylog to manage the alert rules](https://community.graylog.org/t/alert-wizard-plugin-for-graylog-to-manage-the-alert-rules/22687):
>
> [Alert Wizard](https://marketplace.graylog.org/addons/d9425ea6-68bf-41cb-8c39-9ea98e11eefc)Plugin 4.1.0 Alert Wizard plugin for Graylog to manage the alert rules @dlancelin [Download from Github](https://github.com/airbus-cyber/graylog-plugin-alert-wizard/releases/tag/4.1.0)[View on Github](https://github.com/airbus-cyber/graylog-plugin-alert-wizard)[Issues](https://github.com/airbus-cyber/graylog-plugin-alert-wizard/issues)[Stargazers](https://github.com/airbus-cyber/graylog-plugin-alert-wizard/stargazers)Alert Wizard Plugin for Graylog [[Continuous Integration]](https://github.com/airbus-cyber/graylog-plugin-alert-wizard/actions/workflows/ci.yml) [[License]](https://www.mongodb.com/licensing/server-side-public-license) [[GitHub Release]](https://github.com/airbus-cyber/graylog-plugin-alert-wizard/releases)Alert Wizard plugin for Graylog to manage the alert rules An alert wizard for configuring alert rules on Graylog. Perfect for example to configure together and at the same time a stream, an alert condition and a logging alert notification. Required Graylog ve…

---

<div class="post-metadata">

**Author:** ![drmax24](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/drmax24/32/16924_2.png) [@drmax24](https://community.graylog.org/u/drmax24)\
**Post date:** [July 10, 2024, 10:00am UTC](https://community.graylog.org/t/graylog-alert-fields-are-not-getting-filled-when-using-a-threshold/32885/9 "2024-07-10T10:00:42Z")

</div>

I have a similar problem  
This does not print anything. Not a single field

Event Fields:  
${foreach event.fields field}  
${field.key}: ${field.value}  
${end}  
${if backlog}

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/2/b/2b58f7f14ddc676aef7b82e6e5a2c789181076c4.png)

The graylog alert is sent and message is printed. But no fields.

_Graylog 5.2.1_

---

<div class="post-metadata">

**Author:** ![drmax24](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/drmax24/32/16924_2.png) [@drmax24](https://community.graylog.org/u/drmax24)\
**Post date:** [July 18, 2024, 1:15pm UTC](https://community.graylog.org/t/graylog-alert-fields-are-not-getting-filled-when-using-a-threshold/32885/10 "2024-07-18T13:15:20Z")

</div>

> > Im away from my computer today, but Im fairly certain that you can only get field values that are used in the group by of the aggregation, or the output of the aggregation themselves (count=5). Because its an aggregation each message could have a different value in that field, so what value is it supposed to use in the message is the issue.

I try to print any field in my above code. I just can not print anything apart from message. Can not print any data fields

---

<div class="post-metadata">

**Author:** ![Arie](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/arie/32/8094_2.png) [@Arie](https://community.graylog.org/u/Arie)\
**Post date:** [July 18, 2024, 3:01pm UTC](https://community.graylog.org/t/graylog-alert-fields-are-not-getting-filled-when-using-a-threshold/32885/11 "2024-07-18T15:01:12Z")

</div>

That could be because the is the filter an Aggregation page, to get info of a field in the output we have configured that on the fields page. hth

 ![afbeelding](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/0/3/037e7945576397b7ebbebff7fdeda0e2e01be5dc.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [August 1, 2024, 3:01pm UTC](https://community.graylog.org/t/graylog-alert-fields-are-not-getting-filled-when-using-a-threshold/32885/12 "2024-08-01T15:01:40Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![Joel\_Duffield](https://avatars.discourse-cdn.com/v4/letter/j/71c47a/32.png) [@Joel\_Duffield](https://community.graylog.org/u/Joel_Duffield)\
**Post date:** [September 6, 2025, 3:48pm UTC](https://community.graylog.org/t/graylog-alert-fields-are-not-getting-filled-when-using-a-threshold/32885/13 "2025-09-06T15:48:51Z")

</div>

In order for backlog messages to work you have to make sure you turn on the message backlog when you add the notification to the event, it is not enabled by default you have to turn it on and specify how many messages you want included in the backlog.

For @roaringkitty the backlog may actually help you with your problem as well, i haven’t tested it but I believe the backlog works even when doing an aggregation event. Now because its an aggregation of messages you have to use it carefully because field values may be different, but if you know all the values would be the same (like event\_source\_product etc) you could have the backlog just grab 1 message and then pull those values from that message.
