Add a destination
Destinations are set per portal, so different teams can watch different parts of the estate. Open Alert routing in the console, choose the portal, then add an email address, a Slack channel or an HTTPS address of your own. For Slack, first connect your workspace with Connect Slack workspace: you approve the FlowSentinel app in Slack, then pick a channel from the list. For Microsoft Teams, open the channel in Teams, choose Workflows, pick Post to a channel when a webhook request is received, finish the steps and paste the link it gives you into FlowSentinel. The link is stored encrypted. Some organisations switch workflows off, in which case ask your Microsoft 365 administrator.
- 1Open Alert routing and choose the portal.
- 2Pick the channel and enter the destination.
- 3Set the severity that should be sent straight away.
- 4Leave the daily digest on to receive everything below that severity once a day.
- 5Use Test to prove the destination before you rely on it.
Only owners and super admins can add, change or remove a destination. Everyone in the organisation can see what was delivered.
When messages arrive
- Anything at or above your chosen severity is sent within about five minutes of being detected.
- Everything below it is collected into one digest sent at 08:00 UTC.
- A destination that keeps failing is retried with a growing gap, then paused after repeated failures. Resume it from the same screen once the address works again.
Webhooks
A webhook must be a public HTTPS address. Private, internal and raw IP addresses are refused. When you add one, a signing key is shown once: store it, then verify each delivery.
- The body contains a timestamp and a list of items.
- X-FlowSentinel-Timestamp carries the same timestamp.
- X-FlowSentinel-Signature is an HMAC SHA-256 of the timestamp, a full stop and the raw body, using your signing key.
- Reject anything older than a few minutes so an old delivery cannot be replayed.
Buttons and fields
Slack workspaces
| Control | What it does |
|---|---|
| Connect Slack workspaceButton | Starts Slack's authorisation for the selected portal. Shown as Connect another workspace once one is connected. |
| DisconnectButton | Removes the workspace connection. Destinations that used it are paused. |
Add a destination
| Control | What it does |
|---|---|
| PortalField | Choose a portal. Destinations are per portal. |
| ChannelField | Email, Slack, Microsoft Teams or Webhook. Teams needs a workflow link. Slack needs a connected workspace and a channel chosen with Search channels. |
| Send immediately fromField | Minimum severity that triggers an immediate message. |
| Daily digestField | Bundle lower-severity alerts into one daily message. |
| AddButton | Creates the destination. Reads Adding while saving. |
Destinations table
| Control | What it does |
|---|---|
| Route enabledField | Switch a destination off without deleting it. |
| Minimum severityField | Change the threshold in place. |
| TestButton | Sends a test message and reports Test message sent or the provider's error. |
| ResumeButton | Clears the paused state after a run of failures. |
| Remove destinationButton | The bin icon. Deletes the destination and its delivery history. |
Related