Cloud platforms
Send AWS CloudTrail alerts to on-call with CallHeim.
CloudTrail API activity via EventBridge → webhook. CallHeim maps the payload, collapses repeats within five minutes, and pages whoever is on call for the service it belongs to.
You build the connection
AWS CloudTrail has no native outbound webhook for this. It requires a forwarder, script or template that you set up; CallHeim provides the ingest URL and understands the payload shape once it arrives.
Setting it up
Create an Integration in CallHeim and choose AWS CloudTrail from the Catalog. You get an ingest URL for that integration — paste it into AWS CloudTrail’s webhook configuration. The snippet beside this is the shape it expects, with {{WEBHOOK_URL}} replaced by your real URL.
If you enable request signing on this integration, CallHeim requires a valid HMAC-SHA256 signature in the X-ItOnCall-Signature or X-Hub-Signature-256 header on every request to it. Without a signing secret, the ingest URL itself is the credential.
CallHeim includes a payload mapping for AWS CloudTrail’s webhook format, built and tested against sample payloads.
# CloudTrail API calls reach CallHeim through an EventBridge rule you create in your own AWS account — nothing forwards them for you.
# EventBridge → API destinations → Connections → Create connection. Authorization type: API Key, with API key name X-Placeholder and any value. EventBridge requires one; CallHeim does not read it. Do not use Authorization or an X-CallHeim- / X-ItOnCall- header name, which CallHeim does read.
# EventBridge → API destinations → Create API destination: endpoint {{WEBHOOK_URL}}, HTTP method POST, using the connection you created above.
# EventBridge → Rules → Create rule on the default event bus, with this event pattern:
{"detail-type":["AWS API Call via CloudTrail"],"detail":{"eventName":["StopLogging","DeleteTrail","DeleteBucket"]}}
# Target: EventBridge API destination → the API destination you created above. Keep the target input as "Matched events" — no input transformer — so CallHeim receives the event exactly as EventBridge emits it. Let the console create the rule's execution role (it needs events:InvokeApiDestination on the destination).
# Replace the eventName list with the API calls that should page. Without it, every write call in the account opens an incident.
# EventBridge receives these events only from a CloudTrail trail with logging on in that region.
# A call that failed (it carries an error code) opens a P2, any other a P3. Each call is its own incident and has no recovery event, so these incidents do not auto-resolve.
# EventBridge rules, connections and API destinations are regional: repeat the connection, API destination and rule in every region you want covered.After it arrives
What CallHeim does with AWS CloudTrail alerts.
Platform and account-level events each get their own fingerprint — CallHeim does not preserve the provider’s own grouping — and land on the service the integration is bound to. An Orchestration Rule can route or re-prioritise by fields in the event.
CallHeim maps AWS CloudTrail’s own severity to a P1–P5 level and shows a separate, explainable severity suggestion — a published keyword ruleset plus your own resolved-incident history — that a person can apply. How severity is suggested →
Each alert source is bound to a service, and the service’s escalation policy (or its team’s) sets who is paged. Alerting and escalation →
CallHeim closes an incident on a recovery event only for sources whose recovery payload it recognises (or that you map). For the others, a person resolves the incident.
The thresholds it passes through
- Dedup window
- 300s
- Flap threshold
- 4 transitions / 600s
- Title correlation
- similarity ≥ 0.6, same source and service
- Group window default
- 600s
All defaults are published. You can turn title correlation off or change its threshold, and set the window on your own noise rules; the dedup window and the flap settings are fixed. How alerts are processed →
Point AWS CloudTrail at CallHeim and see what it does with your alerts.
Explore the platform, connect one source, and send yourself a test page by e-mail (early access).
Early access · every workspace starts with a 14-day trial for up to 5 seats, no card required