Log alerts

Get notified when a service logs too many errors — or when it stops logging altogether. A log alert counts the lines matching a filter over the last few minutes and tells you once when the count crosses your threshold, and once when it is back to normal.

What a log alert is

A log alert is a saved search plus a condition:

  • a query — a LogsQL filter that selects the lines to count (empty counts every line),
  • a comparison — more than or fewer than,
  • a threshold — the number of matching lines,
  • a window — the last 5, 10, 15, 30 or 60 minutes,
  • a notification channel — any of your channels whose integrations your plan includes: email, Slack, Discord, Telegram, Microsoft Teams, PagerDuty or a webhook.

Every alert is checked once a minute against your organization's logs only.

Creating an alert

Open Logs → Alerts → New alert, or — usually quicker — run a search in the Logs Explorer and click Create alert. The new alert starts with exactly the query of that search, including the field filters you clicked, so it counts the lines you were just looking at.

While you set the condition, the form shows the current value for the chosen window, whether the alert would fire right now, and a histogram of the last 48 windows with your threshold drawn in, so you can see how often it would have fired. A new alert is checked immediately after saving; if the condition already holds, it fires right away.

Conditions and windows

ConditionFires whenTypical use
more than Xthe window has more than X matching lineserror bursts, 5xx spikes, failed logins
fewer than Xthe window has fewer than X matching linesa service, cron job or log shipper went silent

A window with no matching lines counts as 0, so fewer than 1 reliably detects a service that stopped logging. The window is fixed to 5, 10, 15, 30 or 60 minutes: shorter windows react faster, longer ones smooth out noise.

The one-minute delay

Each check counts the window that ended one minute ago — at 12:10, a 5-minute alert counts 12:04–12:09. Log agents such as Vector, Fluent Bit or the OpenTelemetry Collector ship in batches, so the newest lines can arrive a few seconds late. Without the delay those lines would be missing from the count and a “fewer than” alert could fire for no reason.

Filter-only queries

An alert counts lines, so its query must be a filter: words, phrases, field:value filters, AND/OR/- and parentheses. Pipes such as | stats, | sort or | limit are not allowed — the form and the API reject a query with a top-level pipe and tell you so. A | inside quotes, parentheses or a comment is fine.

In the Explorer, Create alert is disabled for searches with pipes. Remove the pipe part to turn the search into an alert.

Note: A query that the log store cannot parse is rejected when you save, with the reason from the parser. If the query cannot be checked at that moment (no logs sent yet, storage briefly unavailable), the alert is saved and a broken query shows up as the Error state instead.

Examples

  • service:=booking-svc level:errorMore than 20 in 5 min: the booking service is throwing errors.
  • service:=booking-svcFewer than 1 in 10 min: the booking service stopped logging — crashed, scaled to zero or its shipper broke.
  • kubernetes.namespace_name:=payments OOMKilledMore than 0 in 5 min: a pod in the payments namespace ran out of memory.
  • status:>=500More than 50 in 5 min: your ingress returns server errors.
  • "login failed"More than 100 in 15 min: possible credential stuffing.

States

StateMeaning
OKThe condition does not hold.
FiringThe condition holds.
ErrorThe last three checks in a row failed (for example the log store did not answer in time). Retried every minute.
SuspendedYour organization has used its monthly log quota; the alert is not checked until the quota resets or you upgrade.
PausedYou paused the alert, or it was paused because your plan's limit shrank.

The Alerts page lists every alert with its state, the last measured value against the threshold, when it was last checked and since when it is in its state. The edit page shows the recent state changes.

Notifications

Notifications are only sent when the state changes, and only once:

  • OK → Firing: a firing notification with the count, the condition, the query and a link to the matching lines in the Logs Explorer.
  • Firing → OK: one resolved notification.
  • Entering Error after three failed checks in a row: one notification with the reason. Shorter hiccups stay silent.
  • Entering Suspended: one notification with your quota, the reset date and an upgrade link.
  • Leaving Error, Suspended or Paused back to OK is silent; if the alert goes straight to Firing, you get a normal firing notification.

There are no repeat notifications while a state lasts. Notifications never include log lines.

Editing and pausing

Changing the query, comparison, threshold or window resets the alert to OK without a notification and checks it again right away. Renaming it or switching the channel keeps its state. The switch in the list pauses an alert; resuming it returns it to OK silently and checks it again right away.

Quota suspension

When your organization has used its monthly log volume, new logs are rejected. Counting them anyway would make “fewer than” alerts fire falsely and “more than” alerts go blind, so all active alerts of the organization are suspended instead — with one notification each. They resume automatically at the start of the next month (UTC) or as soon as you upgrade. Paused alerts stay paused.

Plan limits

PlanActive log alerts
Free2
Pro25
Agentur100

Paused alerts don't count against the limit. On a downgrade or when a trial ends, alerts beyond the new limit are paused, never deleted.

FAQ

Do notifications contain my log lines?
No. A notification carries the alert name, the measured count, the condition, the query and a link into the Logs Explorer for the evaluated window — never the contents of a log line, so personal data from your logs does not end up in Slack, email or other channels.
Why didn't my alert fire for logs that arrived a few seconds ago?
Alerts look at the window that ended one minute ago, so lines from the last minute are counted in the next evaluations. That delay prevents false “fewer than” alarms when an agent ships logs in batches.
Can an alert group by service or count a field's average?
Not yet. An alert counts matching lines; it does not group, aggregate or compute ratios. Create one alert per service if you need per-service thresholds.
Will I get reminded while an alert keeps firing?
No. You get exactly one notification when it fires and one when it resolves. The Alerts page shows everything that is currently firing.
What happens to my alerts when I downgrade?
Alerts beyond the new plan's limit are paused, never deleted. You choose which ones stay active by pausing and resuming them on the Alerts page.