Metrics & monitoring
Send InfluxDB / Kapacitor alerts to on-call with CallHeim.
Kapacitor HTTPPost / InfluxDB check alert webhook. CallHeim maps the payload, collapses repeats within five minutes, and pages whoever is on call for the service it belongs to.
You build the connection
InfluxDB / Kapacitor has no native outbound webhook for this. It requires a forwarder, script or template that you set up; CallHeim provides the ingest URL and understands the payload shape once it arrives.
Setting it up
Create an Integration in CallHeim and choose InfluxDB / Kapacitor from the Catalog. You get an ingest URL for that integration — paste it into InfluxDB / Kapacitor’s webhook configuration. The snippet beside this is the shape it expects, with {{WEBHOOK_URL}} replaced by your real URL.
If you enable request signing on this integration, CallHeim requires a valid HMAC-SHA256 signature in the X-ItOnCall-Signature or X-Hub-Signature-256 header on every request to it. Without a signing secret, the ingest URL itself is the credential.
CallHeim includes a payload mapping for InfluxDB / Kapacitor’s webhook format, built and tested against sample payloads.
# Kapacitor TICKscript alert node:
# .post('{{WEBHOOK_URL}}')
# Or InfluxDB Cloud → Alerts → Notification Endpoint → HTTP.After it arrives
What CallHeim does with InfluxDB / Kapacitor alerts.
Threshold alerts flap at the boundary. Where a source sends a recovery event CallHeim recognises, a series that changes state four times inside ten minutes is grouped instead of re-paging, and the underlying incident stays open and visible.
CallHeim maps InfluxDB / Kapacitor’s own severity to a P1–P5 level and shows a separate, explainable severity suggestion — a published keyword ruleset plus your own resolved-incident history — that a person can apply. How severity is suggested →
Each alert source is bound to a service, and the service’s escalation policy (or its team’s) sets who is paged. Alerting and escalation →
CallHeim closes an incident on a recovery event only for sources whose recovery payload it recognises (or that you map). For the others, a person resolves the incident.
The thresholds it passes through
- Dedup window
- 300s
- Flap threshold
- 4 transitions / 600s
- Title correlation
- similarity ≥ 0.6, same source and service
- Group window default
- 600s
All defaults are published. You can turn title correlation off or change its threshold, and set the window on your own noise rules; the dedup window and the flap settings are fixed. How alerts are processed →
Point InfluxDB / Kapacitor at CallHeim and see what it does with your alerts.
Explore the platform, connect one source, and send yourself a test page by e-mail (early access).
Early access · every workspace starts with a 14-day trial for up to 5 seats, no card required