Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question. Don’t forget to select tags to help index your topic!
1. Describe your incident:
I try to use the parameter “event” & “backlog” with http_notifications.
And “event” is return what I want.
But when I used “backlog”, I cant receive the notifications.
I want to know if I miss any configuration.
can someone help me? Thx!
environment: graylog5.2.3
Here is the template of my notification.
in my cases where i need to extract the fields from backlog, the fields returned only values when i enclose it in breakets ( .backlog.[“fields”][“timestamp”] )
additional make sure, the triggered alert sends at least 1 backlog-message: