Notification settings
The Response step of the alert creation wizard is where you decide what an alert is for. Think of notifications as operational outcomes (a Case that someone owns and resolves) rather than raw webhook fan-out.
What the step contains
The alert's notification step stacks several cards, and this page covers the middle three. The others are documented where the feature lives.
| Card | What it does |
|---|---|
| Case settings | Auto-resolve Case when the alert resolves. See Case settings. |
| Enable notifications for this alert | Turns the rest of the step on or off. |
| Notify on | Cases or Alerts. Covered below. |
| Routing | The routing labels that match a router. Covered below. |
| Custom notifications | A destination set on the alert itself. Covered below. |
| Enrichment | Runs a DataPrime query when the alert triggers and attaches the results to the notification. See Enriching notifications. |
The panel beside the step previews which routers match the labels you have selected, and reports No matching routers when none do.
Pick what triggers the notification
The Notify on card offers two options.
- Cases (badged Recommended): opens a Case when the alert fires, and notifies on that Case's life rather than on each firing. Status changes, acknowledgements, assignments and resolution all reach the destination, and the Case stays in step with PagerDuty, ServiceNow and Slack in both directions. The sequence is: the alert fires, a Case opens and tracks the response, and notifications follow it. Most teams should start here.
- Alerts: notifies each time the alert triggers, carrying alert data with no lifecycle updates. Use this for a thin, fire-and-forget signal, for example broadcasting to a chat channel, paging on threshold or forecast triggers, or driving custom webhooks. It offers two tabs, Destinations and Webhooks, the second holding the legacy outbound webhooks.
Route the notification
Coralogix matches notifications to routers by routing label rather than by a destination set on the alert. Add one or more routing labels (typically Team, service, or environment); the router whose ownership rules match delivers to its configured connector and preset. A single alert can then reach different destinations as ownership changes, without editing the alert.
For the Service label, pick an existing service from the Service Catalog (tagged Catalog) so the alert and its Case attach to the correct APM service, instead of typing a name that a typo could mismatch. Free text still works (tagged Custom) for a service that is not in the catalog yet.
If no router matches the labels you select, the wizard shows No matching routers. For the full request-to-destination chain, see How notifications flow; to author a router, see Routing rules.
Routers or custom notifications
Start with a router. Most alerts need nothing else. A router delivers on ownership: you label the alert with its Team, service, or environment, and the router that owns that scope decides where the notification goes. Ownership changes in one place, and every alert that carries the label follows it.
Custom notifications cover the case a router cannot: this one alert has to reach somewhere specific, regardless of who owns it. You set the destination on the alert itself rather than on an ownership rule.
The two work together. Coralogix delivers an alert's custom notifications as well as whatever its routing labels match, so adding one leaves the router firing as before. Where both paths reach the same connector and preset, Coralogix sends the notification once.
| Router | Custom notification | |
|---|---|---|
| Set on | An ownership rule, matched by label | The alert itself |
| Scope | Every alert carrying the label | This alert only |
| Changing where it goes | Edit the router once | Edit each alert |
| Use it for | Ownership-level delivery, which is most alerts | A destination that belongs to one alert |
Reach for a custom notification when the destination is a property of the alert rather than of the team that owns it: a single alert that has to page a specific vendor channel, or one that feeds a tool nobody else uses. For anything that follows a team, a service, or an environment, use a router.
Add a custom notification
Custom notifications sits below Routing in the alert's notification step, and is available on alerts that open a Case.
-
In the alert's notification step, with Cases selected under Notify on, turn on Custom notifications.
-
Select Add destination. Slack, PagerDuty, and email are the destinations the empty state names.
-
Pick the Connector and the Preset that formats the message. Any connector that supports Cases can be typed in by name.
-
Leave Notify for all trigger types on to notify this destination on every case event, including trigger types added in future.
-
To narrow it, turn that off and select the events you want:
Activated Acknowledged Unacknowledged Resolved Closed Priority changed Assignee changed KPI breached Olly analysis ready Reactivated -
Repeat for any other destination. An alert can carry up to 10.
Each destination keeps its own triggers, so one can notify on everything while another fires only when a case is activated. See Notification triggers for what each event means.
Tune cadence
Cadence applies when Notify on is set to Alerts. An alert that opens a Case notifies on the Case's lifecycle instead, so there is nothing to tune here.
- Notify every: how often a re-fire notification is sent while the condition stays true, for example every 10 minutes.
- Notify when resolved: turn on a follow-up notification when the condition clears. Resolution is automatic on the next evaluation cycle; resolving manually from the Incidents screen does not emit a notification.
Terraform and API users: verify the notifyOn field. Setting it to triggered_only suppresses resolved notifications even if the toggle appears on in the UI. See Troubleshoot alerting.
Case granularity
When Group by is set, the Case settings in the wizard's Details step control whether matching combinations open a Combined case or Separate cases. See Define alert details.
The number of Group by permutations is limited to 1000. When more exist, only the first 1000 are tracked.
Related resources
Next steps
Learn about alerts as a notification source type in Alerts as a notification source type.