# Graylog

EvoHub receives Graylog alerts through an **HTTP Notification** attached to your event definitions. Each event opens an EvoHub alert. Graylog does not send a notification when the condition clears, so these alerts are resolved in EvoHub.

## Set it up

:::steps
### Create the integration
In EvoHub, go to **On-Call → Integrations → + Add Integration**, choose **Graylog**, pick an **Escalation Policy** and click **Create Integration**. Copy the **Webhook URL**.
### Create the notification
In Graylog, go to **Alerts → Notifications → Create Notification**, choose **HTTP Notification** and set **URL** to your webhook URL.
### Test it
Click **Execute Test Notification**. EvoHub answers with success and opens no alert; the integration's **Last Event** updates.
### Attach it to event definitions
Go to **Alerts → Event Definitions**, edit each definition that should page, and add the notification on the **Notifications** step.
:::

Graylog's fixed JSON body is read as it is; there is nothing to template.

## What EvoHub reads

| EvoHub alert | Taken from |
| --- | --- |
| Title | `event_definition_title`. |
| Description | `event.message`, followed by the first three backlog messages. |
| Labels | Every field in `event.fields`, plus `event_key` and `event_definition_id`. |
| Fingerprint | The event definition ID and `event.key` (the group-by value). |

### Severity

| Graylog priority | EvoHub severity |
| --- | --- |
| 4 (critical) | critical |
| 3 (high) | high |
| 2 (normal) | medium |
| 1 (low) | low |

## Resolve and deduplication

- Graylog sends no recovery notification. Resolve the alert in EvoHub when the problem is fixed.
- Each firing of the same event definition with the same group-by key, while the alert is open, is recorded as **Retriggered**. Use **Group by** fields in the event definition to get one alert per host or service.

## Related

- [Integrations overview](https://docs-dev.evohub.io/integrations-overview.md)
- [Splunk](https://docs-dev.evohub.io/splunk.md)
