Notifications
Push reports and high-severity alerts to Feishu, DingTalk, WeCom, Teams, Slack or email: destinations, periods and alert threshold, mail server; failed deliveries retry and can be resent.
Notifications is the product's only outbound message channel: scheduled reports, live alerts above a threshold, "push the conclusion" from an investigation, "escalate" from batch triage. In the top tabs of Platform health; every edition.

Schedule
At the top: periods (daily / weekly / monthly), send hour, timezone, and the alert threshold (new alerts at or above this severity are pushed automatically). Once saved, destinations bound to a period receive that report.
Destinations

| Channel | What to enter |
|---|---|
| Feishu | The group bot's webhook URL; the signing secret if the bot has signature verification on |
| DingTalk | Same |
| WeCom / Teams / Slack | The group bot / incoming webhook URL |
| Recipients (comma, semicolon or newline separated); the sending server is configured once under Mail server |
Each destination is bound to periods and enabled / disabled on its own. "Test send" after creating one confirms delivery.
Webhook URLs and secrets are stored encrypted in ES; after a gateway reinstall the old ciphertext cannot be opened and the destination is marked "secret stale". Re-enter it.
Mail server

Host, encryption (the port follows), username / password (an app password or authorisation code), sender address and name. Saving validates the format only; "Test send" on an email destination proves delivery. Without a mail server every email destination keeps failing.
Delivery log

One row per delivery: kind (report / alert), channel, destination, status, attempts, last error, updated. States: queued → sending → delivered / retrying → given up. Failures retry with backoff; once retries run out the row reads "given up". Fix the configuration and click "Resend".
Audit forwarding
The "Audit forwarding" tab configures where audit events go (syslog / webhook); it is unrelated to the destinations above.
Audit
A record of every login, query, model call and settings change: who, when, which index, what, outcome, tokens. Filter, export, forward.
Account
Avatar, role, password; interface language and theme; the default index, page size and remembered columns for Smart query. Saved instantly, follows the account.