Graylog: Send a notification containing a list of matching events of a given timespan instead of seperate notifications for each event

Hey @stev-e

This statment does not match you configurations shown in that screen shot.

Here is a demo perhaps it might help.

EXAMPLE:

  • Search for “Level:<4”
  • In stream “all Messages”
  • Execute a search Ever 24 hours, THEN search the past 24 hours
  • Create Event IF the count is greater then 0 in the stream called “All messages”, ALERT.
  • Notification , Grace Period is set to 1 day. So ever DAY send a notification but only Only 10 messages