Comments (4)
Hi,
It should work, but I see in your configuration that the query parameter is empty.
Could you try with the parameter query set to * ?
from graylog-plugin-aggregation-count.
I tried with query=* and it didn't work either.
Adding a backlog parameter seems to work. I understand that the backlog messages parameter is only used to determine how many messages to include in the notification alert? It seems to affect the actual number of messages examined.
So, if I set it to, for example, 20 minutes, and with a backlog of 10 messages it does work.
Curious.
I wonder. Is the message backlog only the number of messages to include with the alert, or is it actually a cap on the number of messages to evaluate?
In the latter case it would make sense (avoiding a sort of collapse in an error condition in which the number of events per second increase a lot) but it should be pointed out in the description ;)
from graylog-plugin-aggregation-count.
Anyway, sorry for the belated update. It works on 3.0.0 although the documentation is a bit confusing.
from graylog-plugin-aggregation-count.
I agree with you here, the backlog description is very confusing. I was having the same issue here, alerts were not firing until I raised backlog.
from graylog-plugin-aggregation-count.
Related Issues (13)
- How to alert if the field value is larger then 50? HOT 1
- Throw the right exception to get more context HOT 1
- can't use distinction/grouping fields HOT 9
- Build is getting failed while compiling the source HOT 2
- Timestamp of events is at the start of the defined time period HOT 1
- Aggregation table in notification HOT 1
- issue with "less than" threshold type HOT 5
- How query works?. I'm unable to filter using query on Graylog 3 HOT 2
- Wrong query when email alert HOT 3
- Alert does not trigger if backlog is 0 HOT 1
- Include messages in email alert notification HOT 5
- Not functional HOT 5
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from graylog-plugin-aggregation-count.