# Notification mesage filter

**URL:** <https://community.graylog.org/t/notification-mesage-filter/13077>\
**Category:** Graylog Central (peer support)\
**Created:** [December 5, 2019, 6:29pm UTC](https://community.graylog.org/t/notification-mesage-filter/13077 "2019-12-05T18:29:45Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![gertz](https://avatars.discourse-cdn.com/v4/letter/g/f07891/32.png) [@gertz](https://community.graylog.org/u/gertz)\
**Post date:** [December 5, 2019, 6:29pm UTC](https://community.graylog.org/t/notification-mesage-filter/13077/1 "2019-12-05T18:29:45Z")

</div>

Hi I have problem with graylog notification. I need filter part of message like :  
message: “127.0.0.1:1234 VERIFY error: depth=0, error:somethink: TB=23-sdsdw-2d, dont needed, this”

and I need send e-mail only with “TB=23-sdsdw-2d” information

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [December 6, 2019, 5:12pm UTC](https://community.graylog.org/t/notification-mesage-filter/13077/2 "2019-12-06T17:12:05Z")

</div>

you need to process that message before the alerting with the processing pipeline.

---

<div class="post-metadata">

**Author:** ![gertz](https://avatars.discourse-cdn.com/v4/letter/g/f07891/32.png) [@gertz](https://community.graylog.org/u/gertz)\
**Post date:** [December 9, 2019, 9:30am UTC](https://community.graylog.org/t/notification-mesage-filter/13077/3 "2019-12-09T09:30:41Z")

</div>

but in that case I override original message right?  
I need dont touch original message

---

<div class="post-metadata">

**Author:** ![shoothub](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shoothub/32/6412_2.png) [@shoothub](https://community.graylog.org/u/shoothub)\
**Post date:** [December 9, 2019, 10:06am UTC](https://community.graylog.org/t/notification-mesage-filter/13077/4 "2019-12-09T10:06:14Z")

</div>

Try to extract TB=xxx from message field to new field for example alert\_field. Use regular expression (or GROK) extractor rule, or pipeline for example, or specific (depends on a pattern of original message):  
(TB="\S+)

After that use this snippet in notification body to insert extracted field only:  
{foreach backlog message}{message.fields.alert\_field}${end}

[https://docs.graylog.org/en/3.1/pages/extractors.html](https://docs.graylog.org/en/3.1/pages/extractors.html)  
[https://docs.graylog.org/en/3.1/pages/streams/alerts.html](https://docs.graylog.org/en/3.1/pages/streams/alerts.html)

---

<div class="post-metadata">

**Author:** ![gertz](https://avatars.discourse-cdn.com/v4/letter/g/f07891/32.png) [@gertz](https://community.graylog.org/u/gertz)\
**Post date:** [December 9, 2019, 12:56pm UTC](https://community.graylog.org/t/notification-mesage-filter/13077/5 "2019-12-09T12:56:22Z")

</div>

Thank you very much, finaly it working 🙂

Would it be possible to get one mail with all messages found matching the filter criteria?

---

<div class="post-metadata">

**Author:** ![shoothub](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shoothub/32/6412_2.png) [@shoothub](https://community.graylog.org/u/shoothub)\
**Post date:** [December 9, 2019, 2:17pm UTC](https://community.graylog.org/t/notification-mesage-filter/13077/6 "2019-12-09T14:17:57Z")

</div>

Yes, change number of backlog messages in `Alerts - Event Definitions - Edit - Notification tab, field Message Backlog.`

---

<div class="post-metadata">

**Author:** ![gertz](https://avatars.discourse-cdn.com/v4/letter/g/f07891/32.png) [@gertz](https://community.graylog.org/u/gertz)\
**Post date:** [December 9, 2019, 2:20pm UTC](https://community.graylog.org/t/notification-mesage-filter/13077/7 "2019-12-09T14:20:25Z")

</div>

Thank I already have it, but I dont realyze, message with alert have same source and message that was the proble probably

---

<div class="post-metadata">

**Author:** ![gertz](https://avatars.discourse-cdn.com/v4/letter/g/f07891/32.png) [@gertz](https://community.graylog.org/u/gertz)\
**Post date:** [December 9, 2019, 2:30pm UTC](https://community.graylog.org/t/notification-mesage-filter/13077/8 "2019-12-09T14:30:01Z")

</div>

interesting now, graylog send me 17x mail with one message. no one mail with 17x message

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [December 23, 2019, 2:30pm UTC](https://community.graylog.org/t/notification-mesage-filter/13077/9 "2019-12-23T14:30:05Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
