Skip to main content
User guide

Notifications

Deliver AI investigation findings, alert escalations and reports to Feishu, DingTalk, WeCom, email and webhooks; the delivery log and resending; audit forwarding.

Notifications is in the Audit & notify group at the bottom of the sidebar and opens as a page tab. The page is titled Outbound channels.

Notifications deliver only AI output: investigation conclusions, alert clusters escalated in triage, and reports. This is not alert routing and does not forward Alertmanager alerts; Alertmanager still pages people, so nobody gets the same alert twice.

Notifications

Destinations

Channels: Feishu, DingTalk, WeCom, email and webhook. Click Add a destination, choose the channel and enter a name and address (group bot webhook, recipients or webhook URL), with an optional signing secret. Each destination's subscriptions are independent:

SubscriptionMeaning
ReportsPick daily, weekly or monthly; scheduled reports are delivered when generated
AI findingsDelivered when someone clicks Push the conclusion on an investigation. Set a minimum severity: warning and above, or critical only
Alert escalationsAlert clusters escalated in triage are pushed here, regardless of the findings subscription and minimum severity

Send a test checks a destination. Webhook addresses, signing secrets and SMTP passwords are stored encrypted and never shown again.

The schedule sets the send time and time zone for scheduled reports.

Delivery log

Delivery goes through an outbound queue in the database. Failures are retried with backoff; after the last retry the delivery is marked as given up. Once the configuration is fixed, click Resend in the delivery log.

Mail server

One setting shared by every email destination: server address, encryption, port, user name, password (an app password or authorization code), sender address and sender name. Without it, email destinations keep failing.

Audit forwarding

On this tab Enterprise can forward audit events such as sign-ins, queries and model calls to an external log platform in real time, over syslog (RFC 5424) or a webhook (POST JSON). See Audit log.

On this page