On This Page

Home / Stream/ Monitor Health and Metrics/ Internal Logs/notifications.log

notifications.log ​

The Leader writes notifications.log to $CRIBL_HOME/log/. These events correspond to messages in the Notification list.

To search this file in a built-in Dataset, see Map Log Files to Built-in Datasets.

Example Event ​

The following example shows a typical event in notifications.log. Event fields may vary depending on the process or action that generated the event.

{
  "time": "2026-03-03T19:35:00.000Z",
  "channel": "unhealthy-destination",
  "message": "Destination is unhealthy",
  "_time": 1772566500
}

Event Fields ​

The following table describes fields that may be included in events in this log. Event fields may vary depending on the process or action that generated the event.

FieldDescription
timeFor a metric-based Notification, the start of the aggregation window that triggered the event. Otherwise, the time the event occurred. In UTC.
channelThe ID of the Notification rule that fired.
messageBrief reason for the Notification. Omitted when the event has no message text.
_timeFor a metric-based Notification, the start of the aggregation window that triggered the event. Otherwise, the time the event occurred. In Unix time in seconds.
__worker_groupWorker Group that the Notification rule monitors. Omitted when the rule is not limited to one Worker Group.
__dist_modeDistribution mode of the Worker Group that the Notification rule monitors. worker is a Worker Group. managed-edge is a Fleet. Omitted when the rule is not limited to one Worker Group.
starttimeStart of the metric aggregation window that triggered the Notification. Present on metric-based Notifications. Omitted otherwise.