Hello,
Perhaps this might answer your question. Specially Under Notification settings
https://docs.graylog.org/en/4.0/pages/alerting/alerting-by-example.html#alerting-by-example
EDIT: I have found success in using the Fields section in Event Definition.
As the instruction from Graylog Document suggested, I unchecked the Message Backlog.
The notifications are sent per UserID (i.e., Grouped per UserID)
I haven’t configured Alerts like this before so I found it interesting on what more I can do. Sorry I don’t have a direct answer your solution but If you give a look at the link/s, I provided you may be able to fix you backlog issue.
So, to recap:
- I have a stream to filter down what I need with Rules.
- In my Event Condition Search Query, I used “EventType: Error/Warning”
- Aggregation I Group by Fields using UserID & EventType
- In Create Events for Definition I used count () with >= 0
- Created Fields section which is shown above.
- Notification Template I used the same one from previous post above.
- I uncheck Message Backlog as stated in the Graylog Documents.
I would highly suggest looking at the links I gave you and do some testing. There is more then one or two configuration needed to make your idea work for you, like Notification templates, notification settings, Fields, etc… I think you get the idea.
Results: I received a notification from each UserID. Its not in one email notification, they came grouped up in separate emails.
This is the best I can do for you, if this doesnt work maybe someone else here can help you further
Hope this helps.