Monitor error spikes in Slack
Turn a sudden burst of one error into a single, classified alert — production only, severity already decided — instead of a wall of duplicate noise.
01source
02pipeline · 2 steps
- 01CTLfilter.matchenv = prod only
- 02ENRclassifyseverity → page | notify | ignore
03destinations · 1
- toslackSlackchannel#alerts
the event
You emit error.spike with this shape. The TypeScript SDK keeps the call type-safe, and the event is stored whole — so every field below is available to the pipeline by name.
- servicestring
- errorstringerror class
- countnumberin window
- windowstringe.g. 5m
- envstringprod | staging
emit it
From your code with the TypeScript SDK — or any language over the REST endpoint and signed webhook ingress.
import { ingest } from "@ingestlayer/sdk";
await ingest("error.spike", {
service: "checkout",
error: err.name,
count: windowCount,
window: "5m",
env: process.env.NODE_ENV,
});route it to Slack
Post to any channel in your workspace. Connect once with OAuth, pick the channel per pipeline.
- 01
connect your workspace
Authorize the ingestlayer Slack app over OAuth from the destinations page. We hold only a channel-scoped bot token, in-region, in the same KMS as your other credentials.
- 02
pick a channel
Choose any public channel, or invite the bot to a private one. The channel is set per pipeline, so different events can land in different places.
- 03
map the message
Reference event fields with $event.* in the message template. The default renders a titled block with the event name and its key fields.
┌─ #alerts ──────────────────────────────┐ │ ingestlayer APP │ │ user.signed_up │ │ email ada@acme.com │ │ plan pro │ │ source marketing-site │ └─────────────────────────────────────────┘
notes
- Slack rate-limits to roughly one message per second per channel; bursts are queued and retried, never dropped.
- The bot must be a member of a private channel before it can post there — invite it explicitly.
- Block Kit caps a message at 50 blocks and 3000 characters per text field; oversized events are truncated with a link to the full payload.
questions
- Can staging stay out of the on-call channel?
- Filter on env so only production spikes page anyone; staging can route to a quieter place or nowhere.
- How is severity decided?
- classify weighs the error class and count against your prompt and returns a typed severity the pipeline branches on.
- Will one bad minute spam the channel?
- You emit one spike event per window, so a burst is summarized as a count rather than streamed error by error.
error spikes, routed elsewhere
- Monitor error spikes in DiscordDiscord
- Monitor error spikes in TelegramTelegram
- Monitor error spikes in EmailEmail
- Monitor error spikes in WebhookWebhook
- Monitor error spikes in PostgresPostgres
- Monitor error spikes in NotionNotion
more, into Slack
- Track user signups in Slacktrack
- Monitor failed payments in Slackmonitor
- Route support escalations in Slackalert
- Track waitlist signups in Slacktrack
- Track new subscriptions in Slacktrack
- Track canceled subscriptions in Slacktrack
- Track successful payments in Slacktrack
- Track trial conversions in Slacktrack
- Track form submissions in Slacktrack
- Track feature usage in Slacktrack
- Track file uploads in Slacktrack
- Monitor failed logins in Slackmonitor
- Monitor usage-limit hits in Slackmonitor
- Monitor cron-job health in Slackmonitor
- Monitor CI/CD build status in Slackmonitor
- Flag high-value leads in Slackalert
- Catch churn-risk signals in Slackalert
- everything you can pipe to Slackhub