We have defined a stream and set up an alert on the stream with the alert condition "less than 1 message in the last 30 minutes".
Running: graylog2-server 0.20.1. We are seeing this alert fire when a search on the stream shows many messages in the 30 minute time window. The graylog2-server log shows that the alert fired after a number of org.graylog2.indexer.ranges.RebuildIndexRangesJob messages. Incoming messages are perhaps queued up during the index rebuild, while the alerting triggers are not aware of this? Any suggestions? Robert -- You received this message because you are subscribed to the Google Groups "graylog2" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
