I am trying to setup alerting in graylog. Setup:
client (timestamp) --------> server (eventReceived) ---------> Graylog.
Timestamp and eventreceived times can differ up to 1h or even longer if a client has connectivity issues. Graylog alerting by default compares timestamp and the time range in the alert setting. Currently I set it to 30 minutes to captures most events however I have another issue, if another event fires from any client or even the same client, a new alert will not be fired up. That new event will fall under the same alert with no new notification.
Is there a way to alert on every unique message in the stream disregarding timestamps?