AlertMagic - Payloads

The Payloads page lists every payload (notification) received by AlertMagic for your Integrations, and is the first place to look when checking what happened to a particular alert.

Choosing what to show

Use Integration and Version at the top of the page to show the payloads of one integration, or of one version of it. Both start at All.

The page's address keeps your chosen integration, version, filters and time range, so you can bookmark it or send it to a colleague.

The payload timeline

Above the table, a timeline shows how many payloads were received over time. Each bar is split by how processing ended, using the same colours as the icons in the Notification column:

Colour Outcomes
Green Processed successfully, De-duplicated, Stopped by Incident Spec
Light blue Suppressed by maintenance window, Discarded with down parent
Amber Delayed pending parent
Red Failed
Blue Queued, still being processed
Grey Anything else

Hover over a bar to see the counts for that period. Use the zoom buttons to change how long each bar covers, from 15 minutes to a day. The timeline goes back as far as payloads are kept.

Drag across the timeline to select a period: the table then lists only the payloads received in it, and the search box shows the matching Received filter. When the page opens, the last 24 hours are selected.

The payload list

The table shows the relevant details for each payload, including:

  • Valid - whether the received JSON payload was valid.
  • Type - what processing concluded: Incident(s) Created, Incident(s) Updated, No Incident(s) Created or Updated, or Payload Received while it is still being processed.
  • Notification - how processing ended, each with its own icon. Outcomes include: Processed successfully, De-duplicated, Discarded with down parent, Delayed pending parent, Stopped by Incident Spec, and Suppressed by maintenance window (shown with a slashed-bell icon).
  • IMS Outcome - the result of any writes to the Issue Management System.
  • Failure Reason - when something went wrong, the reason.
  • The Integration name and configuration Version that processed it.
  • When the payload was Received.
  • The Problem Signature, Incident ID and Incident No. of the incident AlertMagic last created or updated for it.

More columns can be shown with the Columns button, including the Tracking ID that correlates the payload with the various logs.

The table can be searched, filtered, sorted, and downloaded.

Icons in the Type column

Icon Meaning
Amber plus Incident(s) Created
Green U Incident(s) Updated
Grey N No Incident(s) Created or Updated, for example because processing failed or has not finished
Purple D Discarded, see below
Blue spinner Payload Received, still being processed

Discarded payloads (coming in the next 4.6 update)

A payload is discarded when AlertMagic processed it but created or updated no incident, for example because a maintenance window suppressed it, or because no Incident Spec handled the alert. These are the payloads the Metrics page counts as Discarded, and they can point to alerts your configuration does not handle yet.

  • In the Type column, a discarded payload shows a purple D, the same purple the Metrics page uses for Discarded.
  • The Notification column shows how processing ended as usual, followed by (Discarded).
  • To list only discarded payloads, choose Discarded in the Notification column's filter. It can be combined with other outcomes, or excluded.

Discarded covers every outcome that created or updated no incident, so a payload suppressed by a maintenance window is listed under both Suppressed by maintenance window and Discarded. On the timeline, a discarded payload is counted in the colour of its outcome.

The detail panes

Selecting a payload splits the right side of the screen into two halves:

  • The top section shows the payload's raw JSON as received from the Alert Management System (such as LogicMonitor), together with a breakdown of the fields that were parsed from it - the same fields the configuration's expressions reference.
  • The bottom section shows the logs AlertMagic wrote while processing the payload (information, warning, and error levels), with a count of each level above them. Successful processing normally shows no errors; when an alert fails, these logs are invaluable, as they usually indicate exactly which configuration or NCalc expression was at fault.

Replaying a payload

A payload can be replayed, sending it through processing again: select it and choose Replay, or double-click it. This is particularly useful after correcting configuration: replay the failed payload and confirm it now processes as intended.

Saving a payload as a test payload

Any received payload can be saved as a test payload against a configuration version, so it can be re-used when authoring and testing your configuration in Alert Studio. Select a payload and choose Save as Test Payload.

A dialog lets you:

  • Choose the target Integration and Version - these default to the ones the payload belongs to, but you can pick any version, including a draft (unpublished) one.
  • Give the test payload a Name and an optional Description.

The payload's body is copied as-is. Once saved, the test payload appears in Alert Studio under that version's Tests / Payloads tab, where it can be used to test your incident and problem expressions. A link is offered that takes you straight there, opening Alert Studio at the right integration and version with that tab already selected.

Reconnection

Reconnection

Reconnection

timed out

timed out

Attempt of

Reload
An unhandled error has occurred. Reload 🗙