# Send all new messages in stream to alert stream

**URL:** <https://community.graylog.org/t/send-all-new-messages-in-stream-to-alert-stream/8155>\
**Category:** Graylog Central (peer support)\
**Created:** [December 21, 2018, 3:05pm UTC](https://community.graylog.org/t/send-all-new-messages-in-stream-to-alert-stream/8155 "2018-12-21T15:05:43Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![np97190](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/np97190/32/3466_2.png) [@np97190](https://community.graylog.org/u/np97190)\
**Post date:** [December 21, 2018, 3:05pm UTC](https://community.graylog.org/t/send-all-new-messages-in-stream-to-alert-stream/8155/1 "2018-12-21T15:05:43Z")

</div>

Hi,

I have setup HTTP Alarm Callback and using Message Count Alert Condition. My condition looks like:

`Configuration: Alert is triggered when there are more than 0 messages in the last minute. Grace period: 0 minutes. Including last message in alert notification. Configured to repeat notifications.`

With this rule only one message gets sent as notification rest all new messages are missed. How can I make it send notification for all new messages in stream?

---

<div class="post-metadata">

**Author:** ![christophetd](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/christophetd/32/3493_2.png) [@christophetd](https://community.graylog.org/u/christophetd)\
**Post date:** [December 23, 2018, 9:15am UTC](https://community.graylog.org/t/send-all-new-messages-in-stream-to-alert-stream/8155/2 "2018-12-23T09:15:11Z")

</div>

AFAIK you cannot do this with the current state of Graylog alerting system. Graylog only considers alert conditions to be matched or not on a certain period of time (by default 60s). If you have multiple messages matching an alert condition in the same minute, only a single alert notification will be sent.

I see two options:

1. Set the message backlog to a high number - this was, Graylog’s notification should include all the messages, and your notification endpoint (e.g. HTTP server listening for webhooks) can take action for each individual message

2. Give feedback to the Graylog team so they implement the possibility to have alert conditions trigger on individual messages 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [January 6, 2019, 9:15am UTC](https://community.graylog.org/t/send-all-new-messages-in-stream-to-alert-stream/8155/3 "2019-01-06T09:15:19Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
