Skip to main content
User guide

Notifications

Push reports and high-severity alerts to Feishu, DingTalk, WeCom, Teams, Slack or email: destinations, periods and alert threshold, mail server; failed deliveries retry and can be resent.

Notifications is the product's only outbound message channel: scheduled reports, live alerts above a threshold, "push the conclusion" from an investigation, "escalate" from batch triage. In the top tabs of Platform health; every edition.

Notifications

Schedule

Push flow

At the top: periods (daily / weekly / monthly), send hour, timezone, and the alert threshold (new alerts at or above this severity are pushed automatically). Once saved, destinations bound to a period receive that report.

Destinations

Add a destination

ChannelWhat to enter
FeishuThe group bot's webhook URL; the signing secret if the bot has signature verification on
DingTalkSame
WeCom / Teams / SlackThe group bot / incoming webhook URL
EmailRecipients (comma, semicolon or newline separated); the sending server is configured once under Mail server

Each destination is bound to periods and enabled / disabled on its own. "Test send" after creating one confirms delivery.

Webhook URLs and secrets are stored encrypted in ES; after a gateway reinstall the old ciphertext cannot be opened and the destination is marked "secret stale". Re-enter it.

Mail server

Mail server

Host, encryption (the port follows), username / password (an app password or authorisation code), sender address and name. Saving validates the format only; "Test send" on an email destination proves delivery. Without a mail server every email destination keeps failing.

Delivery log

Delivery log

One row per delivery: kind (report / alert), channel, destination, status, attempts, last error, updated. States: queued → sending → delivered / retrying → given up. Failures retry with backoff; once retries run out the row reads "given up". Fix the configuration and click "Resend".

Audit forwarding

The "Audit forwarding" tab configures where audit events go (syslog / webhook); it is unrelated to the destinations above.

On this page