notifications.log
The Leader writes notifications.log to $CRIBL_HOME/log/. These events correspond to messages in the Notification list.
To search this file in a built-in Dataset, see Map Log Files to Built-in Datasets.
Example Event
The following example shows a typical event in notifications.log. Event fields may vary depending on the process or action that generated the event.
{
"time": "2026-03-03T19:35:00.000Z",
"channel": "unhealthy-destination",
"message": "Destination is unhealthy",
"_time": 1772566500
}Event Fields
The following table describes fields that may be included in events in this log. Event fields may vary depending on the process or action that generated the event.
| Field | Description |
|---|---|
time | For a metric-based Notification, the start of the aggregation window that triggered the event. Otherwise, the time the event occurred. In UTC. |
channel | The ID of the Notification rule that fired. |
message | Brief reason for the Notification. Omitted when the event has no message text. |
_time | For a metric-based Notification, the start of the aggregation window that triggered the event. Otherwise, the time the event occurred. In Unix time in seconds. |
__worker_group | Worker Group that the Notification rule monitors. Omitted when the rule is not limited to one Worker Group. |
__dist_mode | Distribution mode of the Worker Group that the Notification rule monitors. worker is a Worker Group. managed-edge is a Fleet. Omitted when the rule is not limited to one Worker Group. |
starttime | Start of the metric aggregation window that triggered the Notification. Present on metric-based Notifications. Omitted otherwise. |