Hi Jochen --
The messages are not truncated in the web interface for the stream. The
entirety of the matched line is displayed in the Message.
I also checked the raw email source and it shows the same (...) at the part
where the message gets cut off.
Here is what I'm seeing in the email... I've sanitized this a bit and
highlighted the message and where it gets cut off:
##########
sender:
[email protected]
body:
#################
Customer: xxx
Userid: xxx
xxx: xxx
xxxx: xxxxx
#################
##########
Date: 2015-05-14T14:53:03.935Z
Stream ID: 5553695de4b0fcd5deffeb86
Stream title: xxxx
Triggered condition:
ac4bb3d5-b00e-4376-8dfe-3b6339b11948:MESSAGE_COUNT={time: 1,
threshold_type: more, threshold: 0, grace: 1},
stream:={5553695de4b0fcd5deffeb86: " xxxx "}
##########
Last messages accounting for this alert:
source: xxxx | message: xxxx xxxx: 03AFFA67 2015-05-14 10:52:19 25292
2009655040
"TxSummary[active=xx;[email protected];ver=xxx;service=xxx;port=xxx;contLen=xxx;rcvdReq=xxx;basicAuthTime=xxx;startHttpPost=x;procReque
(...) { timestamp: 2015-05-14T14:52:19.000Z | level: 6 | _id:
d1fb3c9d-fa48-11e4-8780-002590496156 | facility: user-level |
gl2_source_node: fe67ebe0-1566-470a-af83-a707a47ded79 | gl2_source_input:
54ff45b8e4b0ca3409e2bdf1 | streams: [54caa046e4b0b014cbaef196,
5553695de4b0fcd5deffeb86, 54e74209e4b0eb31de809e45] | gl2_remote_port: xxx|
gl2_remote_ip: xxx.xxx.xxx.xxx }
subject:
Graylog alert for stream: xxx
Here is an example of the full message I see matched in the stream that
sends these alert emails:
xxxx xxxx: 03FA48C3 2015-05-14 23:44:49 31390 -2022226176
"TxSummary[active=xx;[email protected];ver=xxx;service=xxx;port=xxx;contLen=xxx;rcvdReq=xxx;basicAuthTime=xxx;startHttpPost=xxx;procRequestStart=xxx;soap=xxx;txid=xxx;xxx=x;xxx=x;startCallOut=x;sentSoapFault=xxx;comp=xxx;]"
Any further suggestions would be greatly appreciated.
Thank you!
On Friday, May 15, 2015 at 4:43:14 AM UTC-4, Jochen Schalanda wrote:
>
> Hi Russel,
>
> are the messages also truncated in the web interface if you check the
> stream? There's no deliberate truncation of the messages in the "backlog"
> (which is the list of messages that matched the alert condition when the
> alert check ran), so I just want to make sure that the original messages
> aren't truncated.
>
> Additionally please check, if it's maybe just a display issue with the
> mail client(s) being used and if the messages are complete if you take a
> look at the "email source" (i. e. the raw email text).
>
>
> Cheers,
> Jochen
>
> On Thursday, 14 May 2015 19:16:01 UTC+2, Russell Wagner wrote:
>>
>> In the Email Alert Callback, we are seeing ${message} get trunctated when
>> it is greater than ~230 characters. Is their a way to avoid this truncation
>> as the people getting these alerts are interested in seeing the whole
>> message.
>>
>> Thanks
>>
>
--
You received this message because you are subscribed to the Google Groups
"graylog2" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
For more options, visit https://groups.google.com/d/optout.