On This Page

Home / Edge/ Monitor Health and Metrics/ Internal Logs/notifications.log

notifications.log ​

The Leader writes notifications.log to $CRIBL_HOME/log/. These events correspond to messages in the Notification list.

To search this file in a built-in Dataset, see Map Log Files to Built-in Datasets.

Example Event ​

The following example shows a typical event in notifications.log. Event fields may vary depending on the process or action that generated the event.

{
  "time": "2026-03-03T19:35:00.000Z",
  "channel": "unhealthy-destination",
  "message": "Destination is unhealthy",
  "_time": 1772566500
}

Event Fields ​

The following table describes fields that may be included in events in this log. Event fields may vary depending on the process or action that generated the event.

FieldDescription
timeFor a metric-based Notification, the start of the aggregation window that triggered the event. Otherwise, the time the event occurred. In UTC.
channelThe ID of the Notification rule that fired.
messageBrief reason for the Notification. Omitted when the event has no message text.
_timeFor a metric-based Notification, the start of the aggregation window that triggered the event. Otherwise, the time the event occurred. In Unix time in seconds.
__worker_groupFleet that the Notification rule monitors. Omitted when the rule is not limited to one Fleet.
__dist_modeDistribution mode of the Fleet that the Notification rule monitors. worker is a Worker Group. managed-edge is a Fleet. Omitted when the rule is not limited to one Fleet.
starttimeStart of the metric aggregation window that triggered the Notification. Present on metric-based Notifications. Omitted otherwise.