EvoHub Docs Sign in

Integrations

Graylog

Use with AI
View as MarkdownThis page as plain text, for pasting into an AI tool Open in ClaudeAsk Claude questions about this page Open in ChatGPTAsk ChatGPT questions about this page
Connect to Cursor / VS Code / ClaudeSearch and read these docs from your AI tool (MCP server)

MCP server URL

https://docs-dev.evohub.io/mcp

Claude Code

claude mcp add --transport http evohub-docs-docs https://docs-dev.evohub.io/mcp

Claude (claude.ai and Claude Desktop): Settings → Connectors → Add custom connector, and paste the URL above.

Claude Desktop — claude_desktop_config.json

{
  "mcpServers": {
    "evohub-docs-docs": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote",
        "https://docs-dev.evohub.io/mcp"
      ]
    }
  }
}

Cursor — ~/.cursor/mcp.json

{
  "mcpServers": {
    "evohub-docs-docs": {
      "url": "https://docs-dev.evohub.io/mcp"
    }
  }
}

VS Code — .vscode/mcp.json

{
  "servers": {
    "evohub-docs-docs": {
      "type": "http",
      "url": "https://docs-dev.evohub.io/mcp"
    }
  }
}

EvoHub receives Graylog alerts through an HTTP Notification attached to your event definitions. Each event opens an EvoHub alert. Graylog does not send a notification when the condition clears, so these alerts are resolved in EvoHub.

Set it up

Create the integration

In EvoHub, go to On-Call → Integrations → + Add Integration, choose Graylog, pick an Escalation Policy and click Create Integration. Copy the Webhook URL.

Create the notification

In Graylog, go to Alerts → Notifications → Create Notification, choose HTTP Notification and set URL to your webhook URL.

Test it

Click Execute Test Notification. EvoHub answers with success and opens no alert; the integration's Last Event updates.

Attach it to event definitions

Go to Alerts → Event Definitions, edit each definition that should page, and add the notification on the Notifications step.

Graylog's fixed JSON body is read as it is; there is nothing to template.

What EvoHub reads

EvoHub alert Taken from
Title event_definition_title.
Description event.message, followed by the first three backlog messages.
Labels Every field in event.fields, plus event_key and event_definition_id.
Fingerprint The event definition ID and event.key (the group-by value).

Severity

Graylog priority EvoHub severity
4 (critical) critical
3 (high) high
2 (normal) medium
1 (low) low

Resolve and deduplication

  • Graylog sends no recovery notification. Resolve the alert in EvoHub when the problem is fixed.
  • Each firing of the same event definition with the same group-by key, while the alert is open, is recorded as Retriggered. Use Group by fields in the event definition to get one alert per host or service.

Last updated