Log monitors alert when a specified type of log exceeds a user-defined threshold over a given period of time. Common use cases for this monitor include:
Define the search query: The search query has the same behavior as the log explorer search
(Optional) Define the alert grouping: With or without alert grouping defined, you get one alert when the aggregated value meets the conditions set below. Even if you split the query by host, a single notification is sent if several hosts meet the conditions set below. This is done to reduce notification noise.
Set alert conditions:
Configure your notification options:
Refer to the Notifications dedicated documentation page for a detailed options.
It is possible to add up to 10 samples of logs that triggered the monitor in the notification message. This is available for Slack and email notifications.
Samples are not available for multi-alerts.
Enable log samples in notification message
Example for Slack notifications
Additional helpful documentation, links, and articles: