Group by message data

Hi all,

I have created a stream which store all error and exceptions comes fromsyslog. I want to group by errors according to error message

for example ı got this error 5 times in last 1 minutes. I want to group same type errors and create alert

how can ı do that ?

message
/home/logs/app.log,07:14:09,534 INFO - DeviceCmd::writeException::handled::appKey::xxx::iid::gT07Jklck::deviceId::8f2ecac6

He @getaffe
as you did not share your Graylog version I assume you have the latest running. What you want to make is an aggregation on the message, that is part of the enterprise plugins for alerting.

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.