Notification catalog

This page lists every notification Sifflet can send, what it tells the recipient, and which channels receive it. For how notifications are routed, see the Notifications overview.

✅ Sent · — Not sent

Incident-centric notifications

NotificationWhat it tells the recipientSlackMicrosoft TeamsEmailGoogle ChatWebhook
Incident createdA new incident has been opened, with the monitor that opened it.✅✅✅✅—
Incident updatedA monitor was added to an incident that already existed.✅✅✅✅—
Incident closedThe incident is now closed. Sent to every channel the incident has notified so far, not only the one that opened it.✅✅✅✅✅ INCIDENT_CLOSED
Incident message updatedThe original Slack incident message is edited in place to show the incident as closed.✅————
Monitor recoveredA monitor is passing again, after failing or needing attention.✅✅—✅✅ MONITOR_STATUS_CHANGE
Assignee addedYou were assigned to an incident. Sent once per newly assigned user, including users reached through a team assignment.——✅——

Monitor-centric notifications

NotificationWhat it tells the recipientSlackMicrosoft TeamsEmailGoogle ChatWebhook
Monitor failureA monitor run failed its threshold. Includes the failing rows or dimensions, and drives incident creation or grouping.✅✅✅✅✅ MONITOR_FAILURE
Monitor needs attentionA monitor run could not reach a verdict: a technical error, or a run that requires a human look.✅✅✅✅✅ MONITOR_NEEDS_ATTENTION
Monitor recoveredA monitor is passing again, after failing or needing attention.✅✅—✅✅ MONITOR_STATUS_CHANGE
Monitor successA monitor run succeeded. Sent for every successful run, not only recoveries.————✅ MONITOR_SUCCESS
ℹ️

Monitor-centric notifications are sent for each failure of the monitor. For incidents, a notification is only sent for the first failed run of the monitor. Until the incident is closed, no new notifications are sent for that monitor.

Good to know

  • Recovery is never sent by email. If email is your only destination, you will see failures but not recoveries.
  • Successful runs are sent to webhooks only. Chat and email channels are not flooded with one message per successful run.
  • Webhooks are sent for every failed run of a monitor, whether the notification is incident-centric or monitor-centric, and also when the monitor is muted.
  • Webhooks are not templated. They receive a JSON payload; see Webhooks.
  • Pipeline alerts are separate. Alerts about failing pipeline assets are described in Pipeline Alerting.

Channel references


Did this page help you?