Limit backlog to alerts matching grouping condition

Hello,

The addition of the grouping to alert conditions in 3.1 is a huge help! The only thing I am wondering if I am missing or overlooking, is there a way to have the notification that gets sent for an alert event include the backlog of messages that only match the grouped key or filter?

Currently it seems to include all of the messages that match the given search filter, not just those that also matched the aggregation condition to trigger the alert.

Thanks!
Josh

1 Like

Hi @josha_ml,

No you are right. As it seems we do not separate the messages based on the grouping
key for the message backlog.

Could you please open a feature request on github with a detailed example?

Thank you!

Cheers,
Konrad

Done! #6381

https://github.com/Graylog2/graylog2-server/issues/6381

Thanks!

image001.jpg

1 Like

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.