> For the complete documentation index, see [llms.txt](https://docs.enginsight.com/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.enginsight.com/docs/manual/english/platform-usage/alerts/overview/add-alert.md).

# Add Alert

{% hint style="warning" %}
**Please note**: A new beta version of this view is available. You can find it under [Alerts (BETA)](/docs/manual/english/platform-usage/alerts-beta.md) → [Add Alert (BETA)](/docs/manual/english/platform-usage/alerts-beta/overview-beta/add-alert-beta.md).

To use the new view, enable **Enable Beta Features** under Settings → [User Account](/docs/manual/english/administration/settings/user-account.md#advanced-settings).
{% endhint %}

***

<i class="fa-computer-mouse">:computer-mouse:</i> Click **Create Alert** in the upper-right corner of the [alerts overview](/docs/manual/english/platform-usage/alerts/overview.md#alerts-overview) to create a new Alert. The **Alerts** → **Add** view opens.

<i class="fa-computer-mouse">:computer-mouse:</i> Click **Expand** to display all available settings for a section. Click **Collapse** to collapse an expanded section again.

After configuring all settings, click **Add Alert** to save and create the new Alert.

<i class="fa-computer-mouse">:computer-mouse:</i> Click **Back** to return to the list view.

{% hint style="danger" %}
**Please note**: If you leave this view without clicking **Add Alert**, all configured settings will be permanently lost.
{% endhint %}

***

## Alert Type

Here you can select the Enginsight component for which the Alert should be created.

The metrics and scenarios that can trigger an Alert vary depending on the selected Alert type.

The following options are available:

<table><thead><tr><th width="199.71484375">Option</th><th>Description</th></tr></thead><tbody><tr><td>Host (Pulsar)</td><td>Create an Alert for a server or client on which the Enginsight Pulsar agent is running.</td></tr><tr><td>Endpoint (Observer)</td><td>Create an Alert for a website or domain monitored by the Enginsight Observer component.</td></tr><tr><td>Observation (Watchdog)</td><td>Create an Alert for an observation, such as configured SNMP, ping, or port monitoring performed by the Enginsight Watchdog component.</td></tr><tr><td>Watchdog (Watchdog)</td><td>Create an Alert for network device detection performed by the Enginsight Watchdog component.</td></tr><tr><td>SIEM Workflow (Loggernaut)</td><td>Create an Alert for a new event in the Enginsight SIEM triggered by a specific workflow.</td></tr><tr><td>SIEM Tracer (Model)</td><td>Create an Alert for the SIEM Tracer component, which performs AI-based time-series analysis.</td></tr></tbody></table>

***

## General Settings

The following options are available:

<table><thead><tr><th width="199.71484375">Option</th><th>Description</th></tr></thead><tbody><tr><td>Reference (Left Field)</td><td><p>Specify the objects to which the Alert should apply.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>The default reference operator is <strong>Exclusively</strong>.</p></div><p><i class="fa-computer-mouse">:computer-mouse:</i> Click the field to expand a list of all available options.<br></p><p>The following options are available:</p><ul><li><strong>Exclusively</strong>: The Alert applies only to the object specified in the <strong>Reference</strong> field.</li><li><strong>Any with Tags</strong>: An object must have the tag or tags specified below for the Alert to apply to it.</li></ul></td></tr><tr><td>Reference (Right Field)</td><td><p><i class="fa-eye">:eye:</i> This option is visible only if you selected <strong>Exclusively</strong> in the reference operator field.</p><p></p><p>Select the specific object to which the Alert should apply.</p><p></p><p><i class="fa-computer-mouse">:computer-mouse:</i> Click the <strong>Reference</strong> field to expand a list of all available objects, then select an object. Alternatively, use the free-text input to find an object in the list more quickly.</p></td></tr><tr><td>Tags</td><td><p><i class="fa-eye">:eye:</i> This option is visible only if you selected <strong>All with Tags</strong> in the reference operator field.<br></p><p>Specify the tag or tags that must be assigned to an object for the Alert to apply to it.</p><p></p><p><i class="fa-computer-mouse">:computer-mouse:</i> Click the <strong>Tags</strong> field to expand a list of all available tags, then select a tag. Alternatively, use the free-text input to find a tag in the list more quickly.<br><br><i class="fa-computer-mouse">:computer-mouse:</i> Click the <strong>Remove</strong> icon <i class="fa-xmark">:xmark:</i> next to a tag to remove it from the <strong>Tags</strong> field.</p></td></tr><tr><td>Metric Attribute/Scenario</td><td><p>Select the specific metric or scenario that should trigger an Alert.<br><br><i class="fa-computer-mouse">:computer-mouse:</i> Click the <strong>Metric Attribute/Scenario</strong> field to expand a list of all metrics and scenarios available for the selected <a href="#alert-type">Alert type</a>, then select an option. Alternatively, use the free-text input to find a metric or scenario in the list more quickly.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>The metrics and/or scenarios available for an Alert vary depending on the selected <a href="#alert-type">Alert type</a>.</p></div><div data-gb-custom-block data-tag="hint" data-style="success" data-icon="lightbulb" class="hint hint-success"><p>For more information about the specific Alerts you can create, refer to our Knowledge Base article: <a href="https://docs.enginsight.com/docs/knowledge-base/alarme/welche-spezifischen-alarme-kann-ich-in-enginsight-definieren">Welche spezifischen Alarme kann ich in Enginsight definieren?</a></p></div></td></tr><tr><td>Description</td><td>Enter a meaningful display name for the Alert.</td></tr></tbody></table>

***

## Notifications

Here you can specify which users should be notified and through which channels when an Alert is triggered.

The following options are available:

<table><thead><tr><th width="199.71484375">Option</th><th>Description</th></tr></thead><tbody><tr><td>Add a User</td><td><p>Select the user who should be notified when an Alert is triggered.</p><p></p><p><i class="fa-computer-mouse">:computer-mouse:</i> Click the <strong>Add a User</strong> field to expand a list of all available users, then select one or more users. Alternatively, use the free-text input to find users in the list more quickly.</p><p></p><p><i class="fa-computer-mouse">:computer-mouse:</i> Click the <strong>Delete</strong> icon <i class="fa-trash">:trash:</i> next to an added user to remove them from the <strong>Add a User</strong> field.</p></td></tr><tr><td>Add a Group</td><td><p>Select the user group that should be notified when an Alert is triggered.</p><p></p><p><i class="fa-computer-mouse">:computer-mouse:</i> Click the <strong>Add a Group</strong> field to expand a list of all available user groups, then select one or more groups. Alternatively, use the free-text input to find groups in the list more quickly.</p><p></p><p><i class="fa-computer-mouse">:computer-mouse:</i> Click the <strong>Delete</strong> icon <i class="fa-trash">:trash:</i> next to an added group to remove them from the <strong>Add a Group</strong> field.</p></td></tr><tr><td>Additional Notification via SMS</td><td><p>Specify that an SMS notification should be sent in addition to an email when an Alert is triggered.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>The notification is sent to the phone number stored in your user account. You can change it in the <a href="/pages/zDjhjpgw25AahV9TADms#your-personal-information">user account settings</a>.</p></div><p>Enable the toggle <i class="fa-slider">:slider:</i> next to <strong>Additional Notification via SMS</strong> to allow SMS notifications.</p><div data-gb-custom-block data-tag="hint" data-style="danger" class="hint hint-danger"><p><strong>Please note</strong>: To receive SMS notifications, you must first configure this in the Enginsight configuration file.</p></div><div data-gb-custom-block data-tag="hint" data-style="success" data-icon="lightbulb" class="hint hint-success"><p>For more information about configuring SMS notifications, refer to our Knowledge Base article: <a href="https://docs.enginsight.com/docs/knowledge-base/alarme/wie-konfiguriere-ich-in-enginsight-den-versand-von-sms-benachrichtigungen-bei-alarmen">Wie konfiguriere ich in Enginsight den Versand von SMS-Benachrichtigungen bei Alarmen?</a></p></div></td></tr><tr><td>Additional Notification via Slack</td><td><p>Specify that a Slack notification should be sent in addition to an email when an Alert is triggered.</p><p></p><p>Enable the toggle <i class="fa-slider">:slider:</i> next to <strong>Additional Notification via Slack</strong> to allow Slack notifications.</p></td></tr><tr><td>Slack Channel</td><td><p><i class="fa-eye">:eye:</i> This field is visible only if you enabled <strong>Additional Notification via Slack</strong>.<br></p><p>Enter the webhook URL of the Slack channel through which the additional notification should be sent.</p><div data-gb-custom-block data-tag="hint" data-style="danger" class="hint hint-danger"><p><strong>Please note</strong>: To display notifications in Slack, you must first create a webhook in Slack and then <a href="/pages/43VrhDhzxu4BUYAdwDsd">add it as a webhook</a> in the Enginsight platform. For information about creating webhooks in Slack, refer to the <a href="https://docs.slack.dev/messaging/sending-messages-using-incoming-webhooks/">official vendor documentation</a>.</p></div></td></tr><tr><td>Additional Notification via Mattermost</td><td><p>Specify that a Mattermost notification should be sent in addition to an email when an Alert is triggered.</p><p></p><p>Enable the toggle <i class="fa-slider">:slider:</i> next to <strong>Additional Notification via Mattermost</strong> to allow Mattermost notifications.</p></td></tr><tr><td>Mattermost Channel</td><td><p><i class="fa-eye">:eye:</i> This field is visible only if you enabled <strong>Additional Notification via Mattermost</strong>.</p><p></p><p>Enter the webhook URL of the Mattermost channel through which the additional notification should be sent.</p><div data-gb-custom-block data-tag="hint" data-style="danger" class="hint hint-danger"><p><strong>Please note</strong>: To display notifications in Mattermost, you must first create a webhook in Mattermost and then <a href="/pages/43VrhDhzxu4BUYAdwDsd">add it as a webhook</a> in the Enginsight platform. For information about creating webhooks in Mattermost, refer to the <a href="https://developers.mattermost.com/integrate/webhooks/incoming/">official vendor documentation</a>.</p></div></td></tr><tr><td>Additional Notification via Microsoft Teams</td><td><p>Specify that a Microsoft Teams notification should be sent in addition to an email when an Alert is triggered.</p><p></p><p>Enable the toggle <i class="fa-slider">:slider:</i> next to <strong>Additional Notification via Microsoft Teams</strong> to allow Microsoft Teams notifications.</p></td></tr><tr><td>Teams Channel</td><td><p><i class="fa-eye">:eye:</i> This field is visible only if you enabled <strong>Additional Notification via Microsoft Teams</strong>.</p><p></p><p>Enter the webhook URL of the Microsoft Teams channel through which the additional notification should be sent.</p><div data-gb-custom-block data-tag="hint" data-style="danger" class="hint hint-danger"><p><strong>Please note</strong>: To display notifications in Microsoft Teams, you must first create a webhook in Teams and then <a href="/pages/43VrhDhzxu4BUYAdwDsd">add it as a webhook</a> in the Enginsight platform. For information about creating webhooks in Teams, refer to the <a href="https://learn.microsoft.com/en-us/microsoftteams/platform/webhooks-and-connectors/how-to/add-incoming-webhook?tabs=newteams%2Cdotnet">official vendor documentation</a>.</p></div></td></tr></tbody></table>

***

## Automation

Here you can select the webhook used to connect the Alert to third-party software, if required. You can also select a plugin to run on a specific host.

The following options are available:

<table><thead><tr><th width="199.71484375">Option</th><th>Description</th></tr></thead><tbody><tr><td>Webhooks: Webhook</td><td><p>Select the webhook through which the Alert should be forwarded to third-party software.</p><div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p><strong>Please note</strong>: Before you can select a webhook here, you must first create it under Alerts → <a href="/pages/vEPTg3S7smJkITUvQsyg">Webhooks</a>.</p></div><p><i class="fa-computer-mouse">:computer-mouse:</i> Click the <strong>Webhook</strong> field to expand a list of all available webhooks, then select a webhook. Alternatively, use the free-text input to find webhooks in the list more quickly.</p><p></p><p><i class="fa-computer-mouse">:computer-mouse:</i> Click the <strong>Remove</strong> icon <i class="fa-trash">:trash:</i> next to an added webhook to remove it from the <strong>Webhook</strong> field.</p></td></tr><tr><td>Plugins: Host</td><td><p>Select the host on which the plugin selected below should run when the Alert is triggered.</p><div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p><strong>Please note</strong>: This list includes only hosts that have been explicitly permitted to run plugins through a <a href="/pages/AbA24oUtZnDfL7wgYRUZ">policy</a> or the <a href="/pages/hfDUrE7rucAeQCpSAqCs">host settings</a>.</p></div><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>If you leave this field empty, all hosts permitted to run plugins are selected automatically.</p></div><p><i class="fa-computer-mouse">:computer-mouse:</i> Click the <strong>Host</strong> field to expand a list of all available hosts, then select a host. Alternatively, use the free-text input to find hosts in the list more quickly.</p><p></p><p><i class="fa-computer-mouse">:computer-mouse:</i> Click the <strong>Remove</strong> icon <i class="fa-trash">:trash:</i> next to an added host to remove it from the <strong>Host</strong> field.</p></td></tr><tr><td>Plugins: Plugin</td><td><p>Select the plugin that should run on the selected host when the Alert is triggered.</p><div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p><strong>Please note</strong>: Before you can select a plugin here, you must first add it under Hosts → <a href="/pages/SwkVqMiI3RLMEQNlnEJm">Plugins</a>.</p></div><p><i class="fa-computer-mouse">:computer-mouse:</i> Click the <strong>Plugin</strong> field to expand a list of all available plugins, then select a plugin. Alternatively, use the free-text input to find plugins in the list more quickly.</p><p></p><p><i class="fa-computer-mouse">:computer-mouse:</i> Click the <strong>Remove</strong> icon <i class="fa-trash">:trash:</i> next to an added plugin to remove it from the <strong>Plugin</strong> field.</p></td></tr></tbody></table>

***

## Additional Options

Here you can set the alert severity and configure additional options.

The following options are available:

<table><thead><tr><th width="199.71484375">Option</th><th>Description</th></tr></thead><tbody><tr><td>Urgency</td><td><p>Select the category to which the alert should be assigned.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>The default urgency is <strong>Warning</strong>.</p></div><p>Click the <strong>Urgency</strong> field to expand a list of all available options, then select an Alert category.<br></p><p>The following options are available:</p><ul><li><strong>Information</strong>: If there are open Issues triggered by the corresponding Alert, a notification is sent monthly.</li><li><strong>Warning</strong>: If there are open Issues triggered by the corresponding Alert, a notification is sent weekly.</li><li><strong>Critical</strong>: If there are open Issues triggered by the corresponding Alert, a notification is sent daily.</li></ul></td></tr><tr><td>Notify if Alert was Resolved</td><td><p>Allow a notification to be sent when the Alert is resolved.</p><div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p><strong>Please note</strong>: This does not apply to incidents, meaning one-time events that remain open until they are manually marked as reviewed.</p></div><p>Enable the toggle <i class="fa-slider">:slider:</i> next to <strong>Notify if Alert was Resolved</strong> to enable this option.</p></td></tr><tr><td>Alert Active</td><td><p>Enable the Alert so that it can trigger notifications and, optionally, perform additional actions.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>This option is enabled by default.</p></div><p>Enable the toggle <i class="fa-slider">:slider:</i> next to <strong>Alert Active</strong> to enable this option.</p></td></tr><tr><td>Inform Responsible Persons</td><td><p>Allow responsible users defined, for example, in the host or endpoint settings to be notified even if they have not been explicitly configured as recipients.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>This option is enabled by default.</p></div><p>Enable the toggle <i class="fa-slider">:slider:</i> next to <strong>Inform Responsible Persons</strong> to enable this option.</p></td></tr></tbody></table>

***

## Further Resources

**Knowledge Base**

* [Welche spezifischen Alarme kann ich in Enginsight definieren?](https://docs.enginsight.com/docs/knowledge-base/alarme/welche-spezifischen-alarme-kann-ich-in-enginsight-definieren)
* [Wie konfiguriere ich in Enginsight den Versand von SMS-Benachrichtigungen bei Alarmen?](https://docs.enginsight.com/docs/knowledge-base/alarme/wie-konfiguriere-ich-in-enginsight-den-versand-von-sms-benachrichtigungen-bei-alarmen)
