Managing alerts
runZero can trigger automatic alerts for specific events through a combination of Channels and Rules.
runZero supports Internal, Email, Email runZero Users, and Webhook channel types.
Internal channels store events in the runZero Console’s Alerts list. Internal alerts support explicit acknowledgement, and you can acknowledge and clear them in bulk from the Console.
Email channels deliver mail to one or more recipients. Each message contains a summary of the alert and a link to the specifics in the runZero Console. runZero sends these messages from its own infrastructure through the Sendgrid service.
Webhook channels tie runZero alerts into third-party platforms by posting to internet-reachable web services. The post request contains a standard text message for platforms like Slack and Mattermost, plus additional fields with the full alert details.
To trigger an alert on a channel, create a Rule. Rules define which events lead to an alert on which channels. The rule’s name appears in the alert content, so name it for the type of event it monitors.
Some example event types you can build rules on:
- Scan completed
- New assets found
- Assets back online
- Assets now offline
- Assets changed
Scan completion and assets changed rules can be noisy, but they may be useful for keeping a running log of network changes. For typical monitoring, create a rule that triggers on Assets now offline, Assets back online, and New assets found, then alerts an email alias or a Slack channel. Combined with recurring scans, alert rules can be a simple way to track network changes over time.
You create these rules in the rules engine, the automation framework for monitoring, alerts, and workflow management.