The addition of the grouping to alert conditions in 3.1 is a huge help! The only thing I am wondering if I am missing or overlooking, is there a way to have the notification that gets sent for an alert event include the backlog of messages that only match the grouped key or filter?
Currently it seems to include all of the messages that match the given search filter, not just those that also matched the aggregation condition to trigger the alert.