# Graylog Notification - Message Condition

**URL:** <https://community.graylog.org/t/graylog-notification-message-condition/13317>\
**Category:** Graylog Central (peer support)\
**Tags:** pipeline-rules\
**Created:** [December 27, 2019, 7:22pm UTC](https://community.graylog.org/t/graylog-notification-message-condition/13317 "2019-12-27T19:22:38Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![gfcarvalho](https://avatars.discourse-cdn.com/v4/letter/g/c89c15/32.png) [@gfcarvalho](https://community.graylog.org/u/gfcarvalho)\
**Post date:** [December 27, 2019, 7:22pm UTC](https://community.graylog.org/t/graylog-notification-message-condition/13317/1 "2019-12-27T19:22:38Z")

</div>

Hey Guys

I’m on new on Graylog and i’m having some issues with notifications, i have created a telegram notification and it’s working without problem, today two devices (firewall and AD DC) are sending information to graylog, one has the field ‘message’ and the other ‘full\_message’, i don’t no why i can’t create two notifications with same configuration so what i would like to now is if it’s possible to use a condition like to use ‘message’ or ‘full\_message’, i did a test wiht:

### 

##########  
Alert: {check\_result.resultDescription} ########## Raw Message ########## {if backlog}Last messages:  
${foreach backlog message}

{if message.message}Message:{if message.message}{end} {if message.fields.full\_message}Message:{message.fields.full\_message}{end}

{end}{else}  
${end}

### 

But the response was ‘Error while parsing ‘else’ at location (12:9): Can’t use else outside of if block!’

Can you guys help?

Thanks

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [December 29, 2019, 10:43am UTC](https://community.graylog.org/t/graylog-notification-message-condition/13317/2 "2019-12-29T10:43:05Z")

</div>

he @gfcarvalho

first it would be nice to know which Graylog version are you using?

Second - I would start normalizing your data. Means cut/split/extract the information you really want into seperate fields that you know and control. Those fields can then be used in the notification for more detailed/better messages.

---

<div class="post-metadata">

**Author:** ![gfcarvalho](https://avatars.discourse-cdn.com/v4/letter/g/c89c15/32.png) [@gfcarvalho](https://community.graylog.org/u/gfcarvalho)\
**Post date:** [December 30, 2019, 7:38pm UTC](https://community.graylog.org/t/graylog-notification-message-condition/13317/3 "2019-12-30T19:38:14Z")

</div>

Hey @jan

Sorry, My graylog version is “Graylog 3.1.3+cda805f on server (Private Build 1.8.0\_232 on Linux 5.0.0-37-generic)”

Answering your second question, i was able to use a pipeline rule to remove the field message and rename the field full\_message to message, this ‘solved’ the problem…

Out of curiosity, whats is the best prectice here, i would need to create one notification for each ‘subject’ (in other words, one notification for each ‘event definition’) ?

Thanks @jan

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [January 6, 2020, 9:42am UTC](https://community.graylog.org/t/graylog-notification-message-condition/13317/4 "2020-01-06T09:42:22Z")

</div>

he @gfcarvalho

you have multiple options and what the best for your environment is, I can only guess.

But I would use processing pipelines to identify the events I want to be alerted on, create a new field for that and use the alerting and watch for this new created field.

This way you can use the complete power of the processing pipeline to identify the events you want to be alerted on. Even extract data on on specific events to have that separate for search and notifications.

---

<div class="post-metadata">

**Author:** ![gfcarvalho](https://avatars.discourse-cdn.com/v4/letter/g/c89c15/32.png) [@gfcarvalho](https://community.graylog.org/u/gfcarvalho)\
**Post date:** [January 6, 2020, 6:56pm UTC](https://community.graylog.org/t/graylog-notification-message-condition/13317/5 "2020-01-06T18:56:16Z")

</div>

I understand, i’ll take a look at this

Thanks for your help

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [January 20, 2020, 6:56pm UTC](https://community.graylog.org/t/graylog-notification-message-condition/13317/6 "2020-01-20T18:56:21Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
