Link

ALERT WEBHOOK

Alert Payload

Name Type Description
event_type string Always: “zebrium_alert”
customer_name string Customer name of Zebrium instance
deployment_name string Name of the deployment where incident was raised
incident_group string Name of the incident group where alert was raised
view_name string Name of view associated with alert
alert_name string Name of alert definition
alert_hit_ct integer Count of events in alert
alert_rule_def_hit_ct integer Count of events in alert rule definition
alert_hit_within_time_span integer Time span covered by alert in seconds
alert_rule_def_hit_within_time_span integer Time span specified in the alert rule definition in seconds
alert_reason string Textual description of alert
alert_rule string Textual description of alert rule definition
alert_start_epoch_ts timestamp (yyyy-mm-ddThh:mm:ss.nnnnnnZ) UTC timestamp of alert start
alert_end_epoch_ts timestamp (yyyy-mm-ddThh:mm:ss.nnnnnnZ) UTC timestamp of alert end
alert_start_epoch integer UTC epoch of alert start
alert_end_epoch integer UTC epoch of alert end
view_id uuid Unique identifier for the view
view_url url encoded string URL to the view in the Zebrium UI
unique_etype_ct integer Count of unique etypes
event_examples_by_etype etype object list One example of each unique etype
alert_events event object list All events that comprise the alert

Etype Object

Name Type Description
etype string Name of the event type
event_ct integer Count of events of this etype in alert
log_name string Name of log basename (e.g. syslog, error)
event_text string Example of one log event of this etype
etype_url url encoded string Link to a track of this etype in the Zebrium UI
severity string Severity text as seen in the log event (e.g. INFO)
epoch_ts timestamp (yyyy-mm-ddThh:mm:ss.nnnnnnZ) UTC timestamp of event

Event Object

Name Type Description
event_uuid uuid Unique identifier for the event
etype string Event type
ze_xid uuid Unique external identifier for the event if provided by the log collector (otherwise empty)
event_text string Log event text
host string Host on which event originated
log_name string Name of log basename (e.g. syslog, error)
severity string Severity text as see in the log (e.g. INFO)
severity_num integer Severity number as defined by syslog
app string Application name from meta data
container_name string Container name from meta data
namespace_name string Namespace name from meta data
incident_group string Name of the incident group where alert was raised
epoch integer UTC epoch of event
epoch_ts timestamp (yyyy-mm-ddThh:mm:ss.nnnnnnZ) UTC timestamp of event
local_timestamp timestamp (yyyy-mm-ddThh:mm:ss.nnnnnn) Local timestamp of event
local_offset string Local time offset from UTC as depicted in the log event
event_meta_data set of name value pairs Name value pairs derived from event meta data

Example Payload

{
  "event_type": "zebrium_alert",
  "customer_name": "customer01",
  "deployment_name": "deployment01",
  "incident_group": "prod",
  "view_name": "All Errors",
  "alert_name": "ERROR ALERT",
  "alert_hit_ct": 110,
  "alert_rule_def_hit_ct": 1,
  "alert_hit_within_time_span": 300,
  "alert_rule_def_hit_within_time_span": 300,
  "alert_reason": "Hit 110 times within 300 seconds beginning at 2020-06-18 21:25:00 and ending at 2020-06-18 21:30:00",
  "alert_rule": "Hit at least 1 times within 300 seconds",
  "alert_start_epoch_ts": "2020-06-18T21:25:00.000000Z",
  "alert_end_epoch_ts": "2020-06-18T21:30:00.000000Z",
  "view_url": "https://portal11.zebrium.com:443/0/filterviewlookup/3af02a24-20ea-4bba-6985-b877901d6079/1592515500/1592515800/portal03/#webhook",
  "unique_etype_ct": 3,
  "event_examples_by_etype": [
    {
      "etype": "system_stats_service_cgroup",
      "etype_url": "https://portal11.zebrium.com:443/0/etypelookup/system_stats_service_cgroup/1592429100/1592602200/portal03/#webhook",
      "log_name": "kubelet",
      "severity": "E",
      "event_ct": 54,
      "event_text": "E0618 14:27:20.339899     994 summary_sys_containers.go:47] Failed to get system container stats for \\\"/system.slice/docker.service\\\": failed to get cgroup stats for \\\"/system.slice/docker.service\\\": failed to get container info for \\\"/system.slice/docker.service\\\": unknown container \\\"/system.slice/docker.service\\\"",
      "epoch_ts:: "2020-06-18T14:27:20.339899Z"
    },
    {
      "etype": "prepared_name_command_select_numargs_write",
      "etype_url": "https://portal11.zebrium.com:443/0/etypelookup/prepared_name_command_select_numargs_write/1592429100/1592602200/portal03/#webhook",
      "log_name": "zwsd",
      "severity": "ERROR",
      "event_ct": 37,
      "event_text": "Jun 18 14:26:48.122576 ERROR connection: -> FAILED SENDING Parse: PreparedName = \\\"S115925156082030536565\\\", Command = \\\"select 1 as test\\\", NumArgs = 0: write tcp 10.100.1.177:36124->172.31.54.255:5433: write: broken pipe",
      "epoch_ts:: "2020-06-18T14:26:14.122576Z"
    },
    {
      "etype": "database_driver_failed_broken",
      "etype_url": "https://portal11.zebrium.com:443/0/etypelookup/database_driver_failed_broken/1592429100/1592602200/portal03/#webhook",
      "log_name": "zwsd",
      "severity": "ERROR",
      "event_ct": 19,
      "event_text": "2020-06-18T14:26:48.122535497-07:00 1 error db.go 176: database driver odbc failed ping, err = write tcp 10.100.1.177:36124->172.31.54.255:5433: write: broken pipe",
      "epoch_ts:: "2020-06-18T14:26:48.122535Z"
    }
  ],
  "alert_events": [
    {
      "event_uuid": "0005edb2-2a5d-65b0-0200-007000013af2",
      "etype": "process_initiated_computer_on_behalf_user09",
      "ze_xid": "1b3dYb84hYbgd82"",
      "event_text": "2020-06-06 04:59:17,878 INFO  [spring-startup]  c.a.u.c.l.PluginSettingsAuditLogService Thu Jun 25 04:59:17 PDT 2019 Bitbucket: Successfully started the Universal Plugin Manager",
      "host": "host005",
      "log_name": "bitbkt",
      "severity": "Informational",
      "severity_num": 6,
      "app": null,
      "container_name": null,
      "namespace_name": "default",
      "incident_group": "prod",
      "epoch": 1591419557878,
      "epoch_ts": "2020-06-06T04:59:17.878000Z",
      "local_timestamp": "2020-06-06T04:59:17.878000Z",
      "local_utcoffset": "+0000",
      "event_meta_data": {
          "host": "host005",
          "pod_name": "bitbucket_master_76de32ac-86d3"
      }
    },
    {
      "event_uuid": "0005edb2-2a5d-65b0-0200-007000013af6",
      "etype": "process_initiated_computer_on_behalf_user09",
      "ze_xid": "1b9hdteh756dhag"",
      "event_text": "2020-06-06 04:59:17,878 INFO  [spring-startup]  c.a.p.c.p.l.ConnectPluginEnabledHandler Got the last lifecycle event... Time to get started!",
      "host": "host005",
      "log_name": "bitbkt",
      "severity": "Informational",
      "severity_num": 6,
      "app": null,
      "container_name": null,
      "namespace_name": "default",
      "incident_group": "prod",
      "epoch": 1591419557878,
      "epoch_ts": "2020-06-06T04:59:17.878000Z",
      "local_timestamp": "2020-06-06T04:59:17.878000Z",
      "local_utcoffset": "+0000",
      "event_meta_data": {
          "host": "host005",
          "pod_name": "bitbucket_master_76de32ac-86d3"
      }
    },
    {
      "event_uuid": "0005edb2-2a5d-7550-0200-007000013af9",
      "etype": "process_initiated_computer_on_behalf_user09",
      "ze_xid": "189jhasdiasn088"",
      "event_text": "2020-06-06 04:59:17,882 DEBUG [spring-startup]  c.a.b.i.m.u.DefaultMirrorService Validating that all configured mirror servers are still installed",
      "host": "host005",
      "log_name": "bitbkt",
      "severity": "Debug",
      "severity_num": 7,
      "app": null,
      "container_name": null,
      "namespace_name": "default",
      "incident_group": "prod",
      "epoch": 1591419557882,
      "epoch_ts": "2020-06-06T04:59:17.882000Z",
      "local_timestamp": "2020-06-06T04:59:17.882000Z",
      "local_utcoffset": "+0000",
      "event_meta_data": {
          "host": "host005",
          "pod_name": "bitbucket_master_76de32ac-86d3"
      }
    }
  ]
}