# \#alert

**URL:** https://community.graylog.org/tag/alert/74.md

[Latest](https://community.graylog.org/latest.md) · [Categories](https://community.graylog.org/categories.md) · [Tags](https://community.graylog.org/tags.md)

---

## [Feature request - allow suppression of specific system notifications](https://community.graylog.org/t/feature-request-allow-suppression-of-specific-system-notifications/37490)

<div class="topic-metadata">

**Author:** [@GiverSeries](https://community.graylog.org/u/GiverSeries)\
**Replies:** 1\
**Last updated:** [August 10, 2026, 3:58pm UTC](https://community.graylog.org/t/feature-request-allow-suppression-of-specific-system-notifications/37490 "2026-08-10T15:58:41Z")

</div>

It should be possible to suppress/silence unwanted system notifications. For example my datanode heap size is 4 GB and I am pestered by the “Data Node Heap Size Warning” every time. No matter how many times it happens I…

---

## [Greylog message error](https://community.graylog.org/t/greylog-message-error/37315)

<div class="topic-metadata">

**Author:** [@dgchultaeiz](https://community.graylog.org/u/dgchultaeiz)\
**Replies:** 0\
**Last updated:** [May 22, 2026, 2:04pm UTC](https://community.graylog.org/t/greylog-message-error/37315 "2026-05-22T14:04:02Z")

</div>

Describe your incident: I have a random UI message in Graylog: “Node cannot be found among active nodes” The node is real and active: Single-node installation The node ID exists in: /etc/graylog/server/node-…

---

## [Error Massage - limit fields problem](https://community.graylog.org/t/error-massage-limit-fields-problem/36835)

<div class="topic-metadata">

**Author:** [@BillyWaiWai](https://community.graylog.org/u/BillyWaiWai)\
**Replies:** 5\
**Last updated:** [January 13, 2026, 9:13am UTC](https://community.graylog.org/t/error-massage-limit-fields-problem/36835 "2026-01-13T09:13:37Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question. Don’t forget to select tags to help index your topic! 1. Describ…

---

## [Has a question about nofication delay, what should i do](https://community.graylog.org/t/has-a-question-about-nofication-delay-what-should-i-do/36800)

<div class="topic-metadata">

**Author:** [@gnarly9203](https://community.graylog.org/u/gnarly9203)\
**Replies:** 3\
**Last updated:** [December 29, 2025, 12:16pm UTC](https://community.graylog.org/t/has-a-question-about-nofication-delay-what-should-i-do/36800 "2025-12-29T12:16:42Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question. Don’t forget to select tags to help index your topic! 1. Describ…

---

## [Correlating events from multiple streams](https://community.graylog.org/t/correlating-events-from-multiple-streams/36437)

<div class="topic-metadata">

**Author:** [@Miki](https://community.graylog.org/u/Miki)\
**Replies:** 1\
**Last updated:** [October 13, 2025, 2:23pm UTC](https://community.graylog.org/t/correlating-events-from-multiple-streams/36437 "2025-10-13T14:23:03Z")

</div>

Hi everyone, I’m using the free version of Graylog 6.3.3. Is there a way to create an alert that triggers only if both of these log events occur (from different streams) within 5 minutes? Stream AD → winlogbeat\_even…

---

## [Event definition dont match](https://community.graylog.org/t/event-definition-dont-match/36443)

<div class="topic-metadata">

**Author:** [@Hugoo](https://community.graylog.org/u/Hugoo)\
**Replies:** 2\
**Last updated:** [October 9, 2025, 12:58pm UTC](https://community.graylog.org/t/event-definition-dont-match/36443 "2025-10-09T12:58:32Z")

</div>

Hi, I’m new to graylog, I’ve seen a lot of topics on the subject without any real solution for my case. 1. Describe your incident: I’m trying to create an Event Definition that should trigger ‘\*’. However, despite havi…

---

## [Unable to delete unassigned shards in Graylog cluster](https://community.graylog.org/t/unable-to-delete-unassigned-shards-in-graylog-cluster/36362)

<div class="topic-metadata">

**Author:** [@HawkManHawk](https://community.graylog.org/u/HawkManHawk)\
**Replies:** 0\
**Last updated:** [September 23, 2025, 3:03pm UTC](https://community.graylog.org/t/unable-to-delete-unassigned-shards-in-graylog-cluster/36362 "2025-09-23T15:03:00Z")

</div>

1. Describe your incident: Unassigned shards after datanode disconnect. Built the cluster from the “Ubuntu Installation Multiple Graylog Nodes” guide on graylog.org I’ve resolved that issue but now i’ve got a constantl…

---

## [Markup in event description defenition](https://community.graylog.org/t/markup-in-event-description-defenition/36215)

<div class="topic-metadata">

**Author:** [@Arie](https://community.graylog.org/u/Arie)\
**Replies:** 6\
**Last updated:** [August 18, 2025, 10:13am UTC](https://community.graylog.org/t/markup-in-event-description-defenition/36215 "2025-08-18T10:13:01Z")

</div>

1. Markup in event definition description: Is it somehow possible to use markup in some way so when we put out an email alert a well made up procedure can be given if an email alert is triggered. Now everything becomes …

---

## [Graylog + Opensearch cluster error](https://community.graylog.org/t/graylog-opensearch-cluster-error/36095)

<div class="topic-metadata">

**Author:** [@Jon\_Doe](https://community.graylog.org/u/Jon_Doe)\
**Replies:** 15\
**Last updated:** [August 5, 2025, 8:21am UTC](https://community.graylog.org/t/graylog-opensearch-cluster-error/36095 "2025-08-05T08:21:55Z")

</div>

Hello, so I have a problem with OpenSearch cluster. It says " OpenSearch cluster datanode-cluster is red. Shards: 87 active, 0 initializing, 0 relocating, 11 unassigned". On “Streams \> All events” tab it’s also returnin…

---

## [Struggle About Using Email HTML Template](https://community.graylog.org/t/struggle-about-using-email-html-template/36120)

<div class="topic-metadata">

**Author:** [@alpryhnn](https://community.graylog.org/u/alpryhnn)\
**Replies:** 0\
**Last updated:** [July 31, 2025, 9:44am UTC](https://community.graylog.org/t/struggle-about-using-email-html-template/36120 "2025-07-31T09:44:28Z")

</div>

(topic deleted by author)

---

## [Graylog Indexing & Processing Failures](https://community.graylog.org/t/graylog-indexing-processing-failures/36063)

<div class="topic-metadata">

**Author:** [@long.nguyen15](https://community.graylog.org/u/long.nguyen15)\
**Replies:** 0\
**Last updated:** [July 22, 2025, 3:06am UTC](https://community.graylog.org/t/graylog-indexing-processing-failures/36063 "2025-07-22T03:06:40Z")

</div>

Hi everyone, I have an issue about Indexing & Processing Failures Graylog has indexing errors like pic below I has turn on I want to reprocess log has failures, any plan for this. Im trying reprocess with pytho…

---

## [What are the best practices for maximizing the value of log data?](https://community.graylog.org/t/what-are-the-best-practices-for-maximizing-the-value-of-log-data/36014)

<div class="topic-metadata">

**Author:** [@Kalinovka](https://community.graylog.org/u/Kalinovka)\
**Replies:** 3\
**Last updated:** [July 21, 2025, 2:21pm UTC](https://community.graylog.org/t/what-are-the-best-practices-for-maximizing-the-value-of-log-data/36014 "2025-07-21T14:21:43Z")

</div>

Hi, I’m currently working with Graylog, which contains log data from both Linux and Windows machines. I’ve been able to create streams, alerts, and dashboards etc but I’m struggling to find other ways to better leverage…

---

## [Replace "logcheck" by Graylog?](https://community.graylog.org/t/replace-logcheck-by-graylog/35887)

<div class="topic-metadata">

**Author:** [@ralfbergs](https://community.graylog.org/u/ralfbergs)\
**Replies:** 0\
**Last updated:** [June 23, 2025, 7:20am UTC](https://community.graylog.org/t/replace-logcheck-by-graylog/35887 "2025-06-23T07:20:03Z")

</div>

1. Purpose: I’m looking into replacing “logcheck” by Graylog. Currently I’m using “logcheck” on my Debian bare-metal server to become aware of events of interest. I’ve created an extensive regexp pattern list to suppres…

---

## [Cannot create Event Definition - f\[0\] is not a function](https://community.graylog.org/t/cannot-create-event-definition-f-0-is-not-a-function/35845)

<div class="topic-metadata">

**Author:** [@Synergie](https://community.graylog.org/u/Synergie)\
**Replies:** 0\
**Last updated:** [June 14, 2025, 11:18am UTC](https://community.graylog.org/t/cannot-create-event-definition-f-0-is-not-a-function/35845 "2025-06-14T11:18:20Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question. Don’t forget to select tags to help index your topic! 1. Describ…

---

## [Graylog alerting - question](https://community.graylog.org/t/graylog-alerting-question/35826)

<div class="topic-metadata">

**Author:** [@royalstar](https://community.graylog.org/u/royalstar)\
**Replies:** 1\
**Last updated:** [June 9, 2025, 11:40am UTC](https://community.graylog.org/t/graylog-alerting-question/35826 "2025-06-09T11:40:48Z")

</div>

Hi, Is it possible to use same event definitions, but with different streams and different notifications? For example, I have already created 50 event definitions and I’m using them with stream named “Company One” and…

---

## [Loading component failed: Unable to read undefined property (reading “result”)](https://community.graylog.org/t/loading-component-failed-unable-to-read-undefined-property-reading-result/35783)

<div class="topic-metadata">

**Author:** [@bobwang](https://community.graylog.org/u/bobwang)\
**Replies:** 0\
**Last updated:** [June 4, 2025, 1:31am UTC](https://community.graylog.org/t/loading-component-failed-unable-to-read-undefined-property-reading-result/35783 "2025-06-04T01:31:02Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question. Don’t forget to select tags to help index your topic! 1. Describ…

---

## [No alert is created in graylog 5.0.5](https://community.graylog.org/t/no-alert-is-created-in-graylog-5-0-5/35689)

<div class="topic-metadata">

**Author:** [@yunhyeonglee](https://community.graylog.org/u/yunhyeonglee)\
**Replies:** 0\
**Last updated:** [May 22, 2025, 6:49pm UTC](https://community.graylog.org/t/no-alert-is-created-in-graylog-5-0-5/35689 "2025-05-22T18:49:42Z")

</div>

I am currently using Graylog 5.0.5. I have created an Event Definition, and the filtered logs are visible in the filter preview. However, no actual alerts are being triggered. The defined event is as follows: { \_id:…

---

## [Pagerduty Notification Event Custom fields](https://community.graylog.org/t/pagerduty-notification-event-custom-fields/35609)

<div class="topic-metadata">

**Author:** [@codyz](https://community.graylog.org/u/codyz)\
**Replies:** 0\
**Last updated:** [May 14, 2025, 1:02pm UTC](https://community.graylog.org/t/pagerduty-notification-event-custom-fields/35609 "2025-05-14T13:02:32Z")

</div>

I have an event definition setup in graylog that is filtering failed logins for admin user. I have the source being populated as a key in the alert. I’m trying to get the source to be shown in the Pagerduty alert right…

---

## [Search in Alerts & Events behaving unexpectedly](https://community.graylog.org/t/search-in-alerts-events-behaving-unexpectedly/35588)

<div class="topic-metadata">

**Author:** [@rivad](https://community.graylog.org/u/rivad)\
**Replies:** 2\
**Last updated:** [May 13, 2025, 8:56am UTC](https://community.graylog.org/t/search-in-alerts-events-behaving-unexpectedly/35588 "2025-05-13T08:56:52Z")

</div>

I’m setting up GitHub - sowoi/graylog-alerts-to-icinga: Monitor graylog alerts with icinga2 to get Graylog events/alterts into Icinga and got into a fight with the search at “Alerts & Event” page and the query at /api/ap…

---

## [Server log getting flooded with notification warnings since 6.2 changes](https://community.graylog.org/t/server-log-getting-flooded-with-notification-warnings-since-6-2-changes/35564)

<div class="topic-metadata">

**Author:** [@elster](https://community.graylog.org/u/elster)\
**Replies:** 4\
**Last updated:** [May 12, 2025, 6:14am UTC](https://community.graylog.org/t/server-log-getting-flooded-with-notification-warnings-since-6-2-changes/35564 "2025-05-12T06:14:05Z")

</div>

Hi everyone! 1. Describe your incident: Since the update to 6.2 the graylog-server logs are getting flooded with warning messages regarding notifications, see 2). Since it’s every few seconds there are tens of thousand…

---

## [Event Definition does not appear Cron Scheduling](https://community.graylog.org/t/event-definition-does-not-appear-cron-scheduling/35277)

<div class="topic-metadata">

**Author:** [@stec](https://community.graylog.org/u/stec)\
**Replies:** 3\
**Last updated:** [March 24, 2025, 3:58pm UTC](https://community.graylog.org/t/event-definition-does-not-appear-cron-scheduling/35277 "2025-03-24T15:58:44Z")

</div>

I’m working with Graylog 6.0.13. I’m trying to create an event definition with cron scheduling in Alerts, but I don’t see this option anywhere. It’s hidden, not as it appears in the Graylog manual. How is this possible?…

---

## [alerts on graylog ](https://community.graylog.org/t/alerts-on-graylog/35270)

<div class="topic-metadata">

**Author:** [@mouayedoss](https://community.graylog.org/u/mouayedoss)\
**Replies:** 1\
**Last updated:** [March 21, 2025, 11:58am UTC](https://community.graylog.org/t/alerts-on-graylog/35270 "2025-03-21T11:58:00Z")

</div>

I am using Graylog 6.1.8, and I have created a stream and a notification. I tried to simulate a DDoS attack on my PC, but I am receiving too many emails for every event. I want to group them and receive an email only if …

---

## [Simplest possible number search](https://community.graylog.org/t/simplest-possible-number-search/35044)

<div class="topic-metadata">

**Author:** [@lpcez](https://community.graylog.org/u/lpcez)\
**Replies:** 0\
**Last updated:** [February 26, 2025, 3:56pm UTC](https://community.graylog.org/t/simplest-possible-number-search/35044 "2025-02-26T15:56:57Z")

</div>

It is my first post, so hi everyone. 1. Describe your incident: I have a very simple stream, created on data sent by ncat - no rsyslog, journald, or any other log parsers: \* \* \* \* \* find /var/spool/postfix/deferred -t…

---

## [Not able to get Email notification and opsgenie alerts from graylog](https://community.graylog.org/t/not-able-to-get-email-notification-and-opsgenie-alerts-from-graylog/34973)

<div class="topic-metadata">

**Author:** [@genevio](https://community.graylog.org/u/genevio)\
**Replies:** 2\
**Last updated:** [February 19, 2025, 1:07pm UTC](https://community.graylog.org/t/not-able-to-get-email-notification-and-opsgenie-alerts-from-graylog/34973 "2025-02-19T13:07:32Z")

</div>

Describe your incident: We had a issue in alert page and we have done few changes from backend in mongo like event\_definitions scheduler\_triggers event\_processor\_state event\_notification\_status scheduler\_job\_defin…

---

## [Wrong timestamp when filtering in Event Condition](https://community.graylog.org/t/wrong-timestamp-when-filtering-in-event-condition/34929)

<div class="topic-metadata">

**Author:** [@shinichihatake97](https://community.graylog.org/u/shinichihatake97)\
**Replies:** 9\
**Last updated:** [February 19, 2025, 5:59am UTC](https://community.graylog.org/t/wrong-timestamp-when-filtering-in-event-condition/34929 "2025-02-19T05:59:48Z")

</div>

Greetings everyone, I’m facing an issue with Event Condition filter query. In the Graylog dashboard, my query runs fine, showing correct timestamp and updating data in real-time However, when filtering query in Event …

---

## [Issue: Graylog DMS Legacy Alerting & Notification System Not Working after updating to ver 6](https://community.graylog.org/t/issue-graylog-dms-legacy-alerting-notification-system-not-working-after-updating-to-ver-6/34922)

<div class="topic-metadata">

**Author:** [@Udisha006](https://community.graylog.org/u/Udisha006)\
**Replies:** 0\
**Last updated:** [February 13, 2025, 3:45pm UTC](https://community.graylog.org/t/issue-graylog-dms-legacy-alerting-notification-system-not-working-after-updating-to-ver-6/34922 "2025-02-13T15:45:01Z")

</div>

Issue: Graylog DMS Legacy Alerting & Notification System Not Working Description: The DMS Legacy alerting and notification system in Graylog has stopped working, both after the upgrade from version 5 to version 6. Aler…

---

## [Error " could not retrive event definitions " error in alert page](https://community.graylog.org/t/error-could-not-retrive-event-definitions-error-in-alert-page/34880)

<div class="topic-metadata">

**Author:** [@genevio](https://community.graylog.org/u/genevio)\
**Replies:** 1\
**Last updated:** [February 7, 2025, 12:45pm UTC](https://community.graylog.org/t/error-could-not-retrive-event-definitions-error-in-alert-page/34880 "2025-02-07T12:45:36Z")

</div>

Describe your incident: Error " could not retrive event definitions " error in alert page . We have created an alert and after that the Email started flowing more which stopped out entire Alert page to be crashed , I w…

---

## [Notification: Missing Linebreaks in HTML formatted Email](https://community.graylog.org/t/notification-missing-linebreaks-in-html-formatted-email/34780)

<div class="topic-metadata">

**Author:** [@Bjoern1234](https://community.graylog.org/u/Bjoern1234)\
**Replies:** 1\
**Last updated:** [February 6, 2025, 2:06pm UTC](https://community.graylog.org/t/notification-missing-linebreaks-in-html-formatted-email/34780 "2025-02-06T14:06:35Z")

</div>

Hello I want to send email notification including the full\_message field which contains line breaks. When sending email notification as plan text, the line breaks exists in the email. But when sending in HTML format t…

---

## [Graylog Possibilities](https://community.graylog.org/t/graylog-possibilities/34828)

<div class="topic-metadata">

**Author:** [@Louis1](https://community.graylog.org/u/Louis1)\
**Replies:** 2\
**Last updated:** [February 3, 2025, 1:30pm UTC](https://community.graylog.org/t/graylog-possibilities/34828 "2025-02-03T13:30:06Z")

</div>

I am training to be an IT specialist for system integration and am currently preparing for my final project. I chose Graylog because we already use it in our company and I like working with monitoring. In order to not ju…

---

## [Events triggering count() == 0 even though "replay search" shows logs](https://community.graylog.org/t/events-triggering-count-0-even-though-replay-search-shows-logs/34592)

<div class="topic-metadata">

**Author:** [@woodsb02](https://community.graylog.org/u/woodsb02)\
**Replies:** 5\
**Last updated:** [January 11, 2025, 2:27am UTC](https://community.graylog.org/t/events-triggering-count-0-even-though-replay-search-shows-logs/34592 "2025-01-11T02:27:06Z")

</div>

1. Describe your incident: I have Event Definitions setup with Aggregation using count() == 0, and these events are matching / being triggered even through there are log entries that match. The filter preview on the ri…

[Next page](https://community.graylog.org/tag/alert/74.md?match_all_tags=true&page=1&tags%5B%5D=alert)
