Group by message data

Hi all,

I have created a stream which store all error and exceptions comes fromsyslog. I want to group by errors according to error message

for example ı got this error 5 times in last 1 minutes. I want to group same type errors and create alert

how can ı do that ?

/home/logs/app.log,07:14:09,534 INFO - DeviceCmd::writeException::handled::appKey::xxx::iid::gT07Jklck::deviceId::8f2ecac6

He @getaffe
as you did not share your Graylog version I assume you have the latest running. What you want to make is an aggregation on the message, that is part of the enterprise plugins for alerting.

