Prerequisites
The connector should already be set up, with a Connector Profile and a Linked Account. See Getting Started on the Grafana connector page.Receive Grafana webhook events
StackOne creates and manages the webhook subscriptions automatically when the account is connected, and removes them when the account is disconnected. There are no manual steps in Grafana.
Alerting events arrive through a webhook contact point named StackOne Events and a notification policy route that forwards every alert to it. The route is added with continue enabled, so your existing contact points keep receiving alerts. IRM events arrive through one IRM outgoing webhook per selected event, named StackOne Events - <trigger>. StackOne finds your IRM API URL automatically from the Grafana IRM app.
- Alerting events require the
alert.provisioning:writepermission (included in the Editor and Admin roles). - IRM events require the
grafana-irm-app.outgoing-webhooks:writepermission (included in the Admin role) and the Grafana IRM app enabled on the stack. - Only alerts from Grafana-managed alert rules are delivered as Alerting events.
Available webhook events
The following Grafana events can be enabled. Only events selected in StackOne are subscribed.
Alert events
Events from Grafana Alerting rule state changes.
- Alert Firing Event (
alert.firing) — Fired when one or more alert instances of a rule start firing - Alert Resolved Event (
alert.resolved) — Fired when every alert instance in a notification group returns to normal
IRM alert group events
Events from Grafana IRM alert groups.
- IRM Alert Group Created (
alert group created) — Fired when a new IRM alert group is created from an incoming alert - IRM Alert Group Acknowledged (
acknowledge) — Fired when an alert group is acknowledged - IRM Alert Group Resolved (
resolve) — Fired when an alert group is resolved - IRM Alert Group Silenced (
silence) — Fired when an alert group is silenced (event.until carries the silence end) - IRM Alert Group Unsilenced (
unsilence) — Fired when a silenced alert group is unsilenced - IRM Alert Group Unresolved (
unresolve) — Fired when a resolved alert group is reopened - IRM Alert Group Unacknowledged (
unacknowledge) — Fired when an acknowledgement is removed from an alert group - IRM Alert Group Escalation (
escalation) — Fired when an escalation chain reaches a Trigger webhook step that references the StackOne webhook - IRM Alert Group Status Changed (
status change) — Fired when an alert group changes state (acknowledge, resolve, silence, unsilence, unresolve, or unacknowledge); event.type carries the underlying action - IRM Alert Group Personal Notification (
personal notification) — Fired when IRM sends a personal notification to a user for an alert group (event.user carries the notified user)
IRM schedule events
Events from Grafana IRM on-call schedules. Available in Grafana Cloud IRM only.
- IRM Schedule On-Call Changed (
on-call changed) — Fired when the set of users on call for a schedule changes - IRM Schedule Shift Started (
shift started) — Fired when an on-call shift starts in a schedule - IRM Schedule Shift Ended (
shift ended) — Fired when an on-call shift ends in a schedule - IRM Schedule Going On-Call (
going on-call) — Fired when a user is about to go on call (shift carries the start and end)
IRM shift swap events
Events from Grafana IRM shift swap requests. Available in Grafana Cloud IRM only.
- IRM Shift Swap Created (
shift swap created) — Fired when a shift swap request is created - IRM Shift Swap Taken (
shift swap taken) — Fired when a shift swap request is taken by another user
Delivery format
Details of how Grafana delivers events to StackOne.
Grouped alert notifications
Each Alerting request is one Grafana notification that can contain several alert instances in its alerts list. StackOne groups notifications by alert rule name, and the event identifier is the alert rule UID of the first alert. The full notification is included in the event data.
IRM deliveries
Each IRM request carries one event. The event identifier is the alert group, schedule, or shift swap request ID, and the event date is the IRM event time. Enabling IRM Alert Group Status Changed together with the individual state events delivers each state change twice (once per event). The IRM Alert Group Escalation event only fires when an escalation chain includes a Trigger webhook step that uses the StackOne Events - escalation webhook.
Signed requests
On Grafana 12 and later, Alerting requests are signed with HMAC-SHA256 in the X-Grafana-Alerting-Signature header. Grafana IRM does not sign outgoing webhooks.