Does any one know the syntax to add the Alert Description shown on the Alerts & Events Page to the notifications. Essentially I’m doing Aggregation Alerts and the alert description shows the exact information I need.
Thanks for the response gsmith,
Sorry for the late response I was out of the office for a minute.
The description is from the main alerts page. (ie. “https://mygraylogserver.com/Alerts”)
I have an alert that will fire when a user tries to login to something X number of times. If I send the message backlog it doesn’t show me the info I need in the alert (its just sends the most recent logs which aren’t what fired the alarm). Basically User X has attempted to login 500 times, similar to the mass file deletions listed in the first screen shot.
Here is example on a received email. I believe in the red box is what you wanted. That would be this section of the Notification template Message: ${event.message}