What a log alert is
A log alert is a saved search plus a condition:
- a query — a LogsQL filter that selects the lines to count (empty counts every line),
- a comparison — more than or fewer than,
- a threshold — the number of matching lines,
- a window — the last 5, 10, 15, 30 or 60 minutes,
- a notification channel — any of your channels whose integrations your plan includes: email, Slack, Discord, Telegram, Microsoft Teams, PagerDuty or a webhook.
Every alert is checked once a minute against your organization's logs only.
Creating an alert
Open Logs → Alerts → New alert, or — usually quicker — run a search in the Logs Explorer and click Create alert. The new alert starts with exactly the query of that search, including the field filters you clicked, so it counts the lines you were just looking at.
While you set the condition, the form shows the current value for the chosen window, whether the alert would fire right now, and a histogram of the last 48 windows with your threshold drawn in, so you can see how often it would have fired. A new alert is checked immediately after saving; if the condition already holds, it fires right away.
Conditions and windows
| Condition | Fires when | Typical use |
|---|---|---|
| more than X | the window has more than X matching lines | error bursts, 5xx spikes, failed logins |
| fewer than X | the window has fewer than X matching lines | a service, cron job or log shipper went silent |
A window with no matching lines counts as 0, so fewer than 1 reliably detects a service that stopped logging. The window is fixed to 5, 10, 15, 30 or 60 minutes: shorter windows react faster, longer ones smooth out noise.
The one-minute delay
Each check counts the window that ended one minute ago — at 12:10, a 5-minute alert counts 12:04–12:09. Log agents such as Vector, Fluent Bit or the OpenTelemetry Collector ship in batches, so the newest lines can arrive a few seconds late. Without the delay those lines would be missing from the count and a “fewer than” alert could fire for no reason.
Filter-only queries
An alert counts lines, so its query must be a filter: words, phrases, field:value filters, AND/OR/- and parentheses. Pipes such as | stats, | sort or | limit are not allowed — the form and the API reject a query with a top-level pipe and tell you so. A | inside quotes, parentheses or a comment is fine.
In the Explorer, Create alert is disabled for searches with pipes. Remove the pipe part to turn the search into an alert.
Examples
service:=booking-svc level:errorMore than 20 in 5 min: the booking service is throwing errors.service:=booking-svcFewer than 1 in 10 min: the booking service stopped logging — crashed, scaled to zero or its shipper broke.kubernetes.namespace_name:=payments OOMKilledMore than 0 in 5 min: a pod in the payments namespace ran out of memory.status:>=500More than 50 in 5 min: your ingress returns server errors."login failed"More than 100 in 15 min: possible credential stuffing.
States
| State | Meaning |
|---|---|
| OK | The condition does not hold. |
| Firing | The condition holds. |
| Error | The last three checks in a row failed (for example the log store did not answer in time). Retried every minute. |
| Suspended | Your organization has used its monthly log quota; the alert is not checked until the quota resets or you upgrade. |
| Paused | You paused the alert, or it was paused because your plan's limit shrank. |
The Alerts page lists every alert with its state, the last measured value against the threshold, when it was last checked and since when it is in its state. The edit page shows the recent state changes.
Notifications
Notifications are only sent when the state changes, and only once:
- OK → Firing: a firing notification with the count, the condition, the query and a link to the matching lines in the Logs Explorer.
- Firing → OK: one resolved notification.
- Entering Error after three failed checks in a row: one notification with the reason. Shorter hiccups stay silent.
- Entering Suspended: one notification with your quota, the reset date and an upgrade link.
- Leaving Error, Suspended or Paused back to OK is silent; if the alert goes straight to Firing, you get a normal firing notification.
There are no repeat notifications while a state lasts. Notifications never include log lines.
Editing and pausing
Changing the query, comparison, threshold or window resets the alert to OK without a notification and checks it again right away. Renaming it or switching the channel keeps its state. The switch in the list pauses an alert; resuming it returns it to OK silently and checks it again right away.
Quota suspension
When your organization has used its monthly log volume, new logs are rejected. Counting them anyway would make “fewer than” alerts fire falsely and “more than” alerts go blind, so all active alerts of the organization are suspended instead — with one notification each. They resume automatically at the start of the next month (UTC) or as soon as you upgrade. Paused alerts stay paused.
Plan limits
| Plan | Active log alerts |
|---|---|
| Free | 2 |
| Pro | 25 |
| Agentur | 100 |
Paused alerts don't count against the limit. On a downgrade or when a trial ends, alerts beyond the new limit are paused, never deleted.
FAQ
- Do notifications contain my log lines?
- No. A notification carries the alert name, the measured count, the condition, the query and a link into the Logs Explorer for the evaluated window — never the contents of a log line, so personal data from your logs does not end up in Slack, email or other channels.
- Why didn't my alert fire for logs that arrived a few seconds ago?
- Alerts look at the window that ended one minute ago, so lines from the last minute are counted in the next evaluations. That delay prevents false “fewer than” alarms when an agent ships logs in batches.
- Can an alert group by service or count a field's average?
- Not yet. An alert counts matching lines; it does not group, aggregate or compute ratios. Create one alert per service if you need per-service thresholds.
- Will I get reminded while an alert keeps firing?
- No. You get exactly one notification when it fires and one when it resolves. The Alerts page shows everything that is currently firing.
- What happens to my alerts when I downgrade?
- Alerts beyond the new plan's limit are paused, never deleted. You choose which ones stay active by pausing and resuming them on the Alerts page.