Skip to content

External Event Detection

Document Purpose

This document covers the second step in the detection rule configuration process. After completing the configuration, return to the main document to continue with Step 3: Associate Incidents.

The External Event Detection feature receives anomaly records from third-party systems. When these records are sent to the system via the Webhook address preset in the detection rule, the system automatically converts them into standard monitor events, which can then be associated with alert policies and visualization dashboards for unified monitoring and management.

It is suitable for scenarios where anomaly events or records generated by third-party systems (such as Prometheus, Zabbix, Nagios, etc.) are sent to Guance via POST requests to a specified URL, after which event data is generated to enable unified cross-platform alert management.

Use Cases

  • Integrate with third-party monitoring systems to consolidate scattered alerts into the Guance platform.
  • Receive anomaly events from custom business systems to enable business monitoring and alerting.
  • Aggregate monitoring data across multi-cloud and hybrid cloud environments for unified visualization and analysis.

Default Configuration

Basic Configuration

Configuration Item Description
Monitor Name Custom monitor name used to identify this external event detector.
Webhook URL The system automatically generates a unique Webhook URL by default. You can append custom parameters to mark the purpose of the URL.

Format: http://<domain>/api/v1/push-events/<random string>

The third-party system must send anomaly events to this URL via POST requests.

Advanced Configuration

Mark as Change Events: When enabled, all events reported by this monitor are automatically treated as change events and displayed on the timeline of the corresponding entity. The system does not change the source of the event itself, nor does it affect the existing filtering and statistics logic of the Event Center.

Event Data Format

External event data is actively reported to Guance by third-party systems, which provide the necessary event data. An event and anomaly record is generated only when the corresponding fields are detected and matched.

Required Fields (The five fields under the event object must be included for a successful match with the system):

Field Type Description
status string Event status. Valid values: fatal (fatal), error (critical), warning (warning), info (information), ok (normal)
title string Event title, used to describe the core content of the event.
message string Event details, used to describe the specific information of the event.
dimension_tags object Dimension tags used to identify the event source, e.g., {"host": "server01", "service": "nginx"}.
check_value number Check value, the numeric value used for trigger condition evaluation.

Optional Fields:

Field Type Description
extraData object Custom extension fields, which can be used for variable substitution in event notification templates.

Request Example:

{
    "event": {
        "status": "warning",
        "title": "外部事件监控器测试1",
        "message": "你好,这是外部事件监控器的message",
        "dimension_tags": {"heros": "caiwenji"},
        "check_value": 20
    },
    "extraData": {
        "name": "xxxxxxxx"
    }
}

For more details, refer to External Event Monitor Event Reception.

Subsequent Configuration

After completing the detection rule configuration, you also need to make the following related settings:

  1. Associate Incidents.

  2. Alert Configuration: Select an alert policy, and set up notification targets and the mute period.

  3. Associate: Associate a dashboard for quick navigation and data viewing.

  4. Permissions: Set operation permissions to control who can edit or delete this monitor.

  5. Associate Entity: After enabling "Mark as Change Events", the event is automatically associated with the entity with the matching name in the Unified Catalog. You can view the change history in the timeline view on the Events tab of the entity details page.