Metrics & monitoring

Send SolarWinds Orion alerts to on-call with CallHeim.

Orion/Observability alert action POST (Critical/Serious/Warning). CallHeim maps the payload, collapses repeats within five minutes, and pages whoever is on call for the service it belongs to.

solarwindsSolarWindsalso accepts: solar-winds, orion, swo

You build the connection

SolarWinds Orion has no native outbound webhook for this. It requires a forwarder, script or template that you set up; CallHeim provides the ingest URL and understands the payload shape once it arrives.

Setting it up

Add a "Send a GET or POST request to a web server" alert action and template a JSON body.

Create an Integration in CallHeim and choose SolarWinds Orion from the Catalog. You get an ingest URL for that integration — paste it into SolarWinds Orion’s webhook configuration. The snippet beside this is the shape it expects, with {{WEBHOOK_URL}} replaced by your real URL.

If you enable request signing on this integration, CallHeim requires a valid HMAC-SHA256 signature in the X-ItOnCall-Signature or X-Hub-Signature-256 header on every request to it. Without a signing secret, the ingest URL itself is the credential.

CallHeim includes a payload mapping for SolarWinds Orion’s webhook format, built and tested against sample payloads.

SolarWinds Orion webhook documentation →

Setup snippetsolarwinds
# SolarWinds → Alerts → Manage Alerts → Trigger Actions → Add Action
# "Send a GET or POST request to a web server"   URL: {{WEBHOOK_URL}}
# Body: {"AlertName":"${N=Alerting;M=AlertName}","Severity":"...","AlertActive":true}
Example shape written by us; check SolarWinds Orion’s current documentation.

After it arrives

What CallHeim does with SolarWinds Orion alerts.

Threshold alerts flap at the boundary. Where a source sends a recovery event CallHeim recognises, a series that changes state four times inside ten minutes is grouped instead of re-paging, and the underlying incident stays open and visible.

CallHeim maps SolarWinds Orion’s own severity to a P1–P5 level and shows a separate, explainable severity suggestion — a published keyword ruleset plus your own resolved-incident history — that a person can apply. How severity is suggested →

Each alert source is bound to a service, and the service’s escalation policy (or its team’s) sets who is paged. Alerting and escalation →

CallHeim closes an incident on a recovery event only for sources whose recovery payload it recognises (or that you map). For the others, a person resolves the incident.

The thresholds it passes through

Dedup window
300s
Flap threshold
4 transitions / 600s
Title correlation
similarity ≥ 0.6, same source and service
Group window default
600s

All defaults are published. You can turn title correlation off or change its threshold, and set the window on your own noise rules; the dedup window and the flap settings are fixed. How alerts are processed →

CallHeim

Point SolarWinds Orion at CallHeim and see what it does with your alerts.

Explore the platform, connect one source, and send yourself a test page by e-mail (early access).

Early access · every workspace starts with a 14-day trial for up to 5 seats, no card required