Notification catalog
This page lists every notification Sifflet can send, what it tells the recipient, and which channels receive it. For how notifications are routed, see the Notifications overview.
✅ Sent · — Not sent
Incident-centric notifications
| Notification | What it tells the recipient | Slack | Microsoft Teams | Google Chat | Webhook | |
|---|---|---|---|---|---|---|
| Incident created | A new incident has been opened, with the monitor that opened it. | ✅ | ✅ | ✅ | ✅ | — |
| Incident updated | A monitor was added to an incident that already existed. | ✅ | ✅ | ✅ | ✅ | — |
| Incident closed | The incident is now closed. Sent to every channel the incident has notified so far, not only the one that opened it. | ✅ | ✅ | ✅ | ✅ | ✅ INCIDENT_CLOSED |
| Incident message updated | The original Slack incident message is edited in place to show the incident as closed. | ✅ | — | — | — | — |
| Monitor recovered | A monitor is passing again, after failing or needing attention. | ✅ | ✅ | — | ✅ | ✅ MONITOR_STATUS_CHANGE |
| Assignee added | You were assigned to an incident. Sent once per newly assigned user, including users reached through a team assignment. | — | — | ✅ | — | — |
Monitor-centric notifications
| Notification | What it tells the recipient | Slack | Microsoft Teams | Google Chat | Webhook | |
|---|---|---|---|---|---|---|
| Monitor failure | A monitor run failed its threshold. Includes the failing rows or dimensions, and drives incident creation or grouping. | ✅ | ✅ | ✅ | ✅ | ✅ MONITOR_FAILURE |
| Monitor needs attention | A monitor run could not reach a verdict: a technical error, or a run that requires a human look. | ✅ | ✅ | ✅ | ✅ | ✅ MONITOR_NEEDS_ATTENTION |
| Monitor recovered | A monitor is passing again, after failing or needing attention. | ✅ | ✅ | — | ✅ | ✅ MONITOR_STATUS_CHANGE |
| Monitor success | A monitor run succeeded. Sent for every successful run, not only recoveries. | — | — | — | — | ✅ MONITOR_SUCCESS |
Monitor-centric notifications are sent for each failure of the monitor. For incidents, a notification is only sent for the first failed run of the monitor. Until the incident is closed, no new notifications are sent for that monitor.
Good to know
- Recovery is never sent by email. If email is your only destination, you will see failures but not recoveries.
- Successful runs are sent to webhooks only. Chat and email channels are not flooded with one message per successful run.
- Webhooks are sent for every failed run of a monitor, whether the notification is incident-centric or monitor-centric, and also when the monitor is muted.
- Webhooks are not templated. They receive a JSON payload; see Webhooks.
- Pipeline alerts are separate. Alerts about failing pipeline assets are described in Pipeline Alerting.
Channel references
Updated about 2 hours ago
Did this page help you?

