When we created the LoggingAlert plugin we implemented split fields to merge/split alerts based on fields value because Graylog had no equivalent.
But now Graylog allows to set Event Fields in en Event Definition and some of these fields can be choosen as primary keys to split alerts.
We should POC this feature first to be sure it answers our purpose.
When we created the LoggingAlert plugin we implemented split fields to merge/split alerts based on fields value because Graylog had no equivalent. But now Graylog allows to set Event Fields in en Event Definition and some of these fields can be choosen as primary keys to split alerts. We should POC this feature first to be sure it answers our purpose.