Introduction:
In the dynamic landscape of software development, ensuring the robustness and reliability of your applications is paramount. Enter Seq, a structured log server designed to empower developers with comprehensive and insightful logging capabilities. Logging, when done right, is more than just a record of events — it’s a powerful tool for debugging, monitoring, and gaining deep insights into your application’s behavior.
Seq is a powerful log management and event monitoring tool that allows you to set up alerts to be notified of important events and issues in your applications and systems.
Prerequisites
Before you begin, ensure that you have the following:
- A running instance of Seq.
- Access to the Seq web interface.
1. Identify Events to alert on.
- Identify the critical services and components in your system. Things that you absolutely need to be alerted about if they fail or experience problems?
- Identify the critical services and components in your system. Key indicators of health for each service or component? What values should these indicators fall within?
- Identify the types of events that you want to be alerted about. This could include errors, warnings, performance problems, and security events.
- Use the Seq search bar to find events that match your criteria. Use variety of filters to refine your search results, such as the event type, message, source, and severity.
Example:
Filtering Event with Exception name:

Once you have found the events that you want to be alerted about, you can create an alert for different events.
2. Set Alert Actions
- To the right of the search box, you’ll spot the Add Alert button. It looks like a bell with a small “plus” icon overlay. Or you can setup alert form scratch by clicking ‘Alerts’ in Navigation Bar.

- Setting up an Alert
- Give your alert a descriptive name and optional description to help you identify its purpose.
- Define the criteria that will trigger the alert. This typically includes specifying the log events, conditions, and time frames that should trigger the alert.
- Choose the Source of Events in ’Signal’
- In ’select’, specify one or more columns to compute; the columns should be based on aggregate functions like count, min, max, mean, and percentile. (Eg. select count(*) as count selects the number of rows in the result set and assigns it to the variable count.)
- Specify your Trigger Condition in ’where’.
where @Exception like 'MongoDB.Driver.MongoCommandException%'
- The ’group by’ clause in an alert configuration allows you to group the results by one or more columns.
group sby time(1m), SourceContext, Application, Environment, State
- ‘Time grouping’ in alert configuration allows you to group alerts that occur within a certain time period. This can be useful for reducing the noise of alerts and for identifying trends and patterns.
- ‘having’ clause allows you to filter the results of a GROUP BY clause. This can be useful for creating alerts that only trigger when certain conditions are met.
having count > 1
- Suppression time is the amount of time that an alert will be suppressed after it is triggered. This can be useful for reducing the noise of alerts and for preventing alerts from being triggered repeatedly for the same problem.
- This whole process creates a query like this-

3. Test Alert
- Before saving the alert, you can test it by clicking the “Test Alert” button to ensure that it triggers correctly based on your criteria.
- If the test is successful, click the “Save” or “Create” button to save the alert.
4. Installing Output Apps
- Go to the Settings page.
- Click the Apps tab.
- Click the Install from NuGet button.
- In the Package ID field, enter the package ID of the app you want to install from Nuget App Gallery.
- Click the Install button.
5. Creating Instance of an App
- Go to the Settings page.
- Click the Apps tab.
- Find the app you want to create an instance of and click the Start a new instance link next to its name.
- The configuration page for the app will appear. You can configure the app’s settings on this page.
- Once you have configured the app, click the Start button.
The app will start running and will start processing events from Seq.
Here are some additional information for setting up app instances on Seq:
- You can create multiple instances of the same app. This can be useful if you need to configure the app differently for different purposes.
- You can give each app instance a different name. This can help you to keep track of your app instances.
- You can specify which signals the app instance should process.
- This can help you to improve the performance of your Seq server.
- You can enable or disable app instances at any time.
Configuring Instance of EmailPlus
- Give Suitable Title for the Instance (Eg. Send Email) Stream incoming events means that the app instance will start processing events from Seq as soon as it is started.
- Add Sender’s Email in ‘From Address’.
- Add Recipent’s Email in ‘To address’.
- We can add multiple emails here.
- We can also override this section, so that we can provide different email while sending specific Log Event.
-
Provide subject for your emails.
-
Configure your SMTP Server for sender’s email. (Eg. smtp.office365.com for outlook mails)
-
Provide port number. (Eg. 587 for outlook)
-
Provide Subject for your Emails.
-
Provide Username and Password (Sender’s Email Credentials)
-
Click save.

Configure Alert Notifications
- Choose Notification level.
- Choose your app isntance.
- Click on Customize this notification
- Check ‘Include contributing Events’ and enter the maximmun numbers of contributing events to include in notification.
Configuring Instance of Microsoft Teams
For this, First create a teams channel and configure Teams Webhook and store that webhook url for later use.
- Give Suitable Title for the Instance (Eg. Send to Teams) Stream incoming events means that the app instance will start processing events from Seq as soon as it is started.
- Provide teams webhook URL.
- Check Trace All Messages.
- Add following properties in ‘Properties to serialize as JSON’ & check ‘Properties to serialize as JSON — Use Indented JSON?’ part
Source.Results
Source.ContributingEvents
-
Enter event level (Eg. Error)
-
Save it.
Monitor Alerts
- Back on the “Alerts” tab, you can see a list of your defined alerts. Enable or disable them as needed.
- As log events meet the criteria you defined, Seq will trigger alerts and send notifications according to your configurations.
- You can see Triggered Alerts on left plane.

Email Notifications should be like this.

Teams Notifications should be like this.


For more Informed teams notifications, try using Seq.App.Teams.AdaptiveCard. This app will provide more informations as mentioned on alerts.
Thanks for reading.