Skip to main content
Plan requirement: This feature requires an On-call Pro or higher subscription. Learn more

Use Cases

The system uses templates when assigning incidents in the following scenarios:
The system uses Golang template syntax to parse data, supporting logic, loops, pipelines, and common functions. For more functions, refer to sprig function library.
For security reasons, the following sprig functions are disabled. Using them in a template causes a function "xxx" not defined parse error:If you need a unique identifier inside a template, use incident variables such as {{.IncidentID}} or {{.LabelsMD5}}. If you need environment-specific values, pass them in via alert labels or field mappings instead of reading host environment variables from the template.

Configuring Templates

1

Create Custom Template

Go to Template Management page, click Create Custom Template or Copy Default Template
2

Edit Template Content

Edit content by notification channel, can reference fields from the variable list below
3

Save Template

Click Save to complete creation

Apply Template

1

Enter Escalation Rules

Go to Channel → Escalation Rules, click Edit
2

Select Template

In rule configuration, select which template to use for notifications
3

Save Configuration

Click Save to complete configuration. See Configure Escalation Rules

Variable Reference

Reference Examples

Incident Variables

Complete variable list for incident objects:

FAQ

  • Manually created incidents have no labels
  • Auto-created incidents have labels, same as the first merged alert’s labels
Go to Incident List → view incident details to see all label information.
When creating custom templates, the system uses mock data to check syntax. Mock data covers limited scenarios; rendering may fail at runtime, and system falls back to default template.
Recommend checking if variable exists before referencing:
Use toHtml function to handle:
Add $ before external variable:
Use index function:
Use jsonGet function to extract values by path from valid JSON. Syntax reference at gjson.dev.
imageSrcToURL: Convert image_key or URL to accessible address (for Dingtalk/Slack App)
transferImage: Upload image to third-party platform (for Feishu/Lark App)
Image size cannot exceed 10 MB, supports JPG, PNG, WEBP, GIF, BMP formats.

Channel Templates

Different notification channels support different template formats and limitations.
Requires Feishu/Lark integration configured first. Supports message card format; system auto-removes empty render lines caused by non-existent labels.Default Template (render all labels):
Feishu/Lark App Notification

Feishu/Lark App Notification Effect

Minimal Template (show key labels only):

Card Fields and Bottom Action Buttons

When editing a Feishu/Lark app template, the Additional info tab next to the Content tab provides a card-fields switch panel (“These fields are rendered by the system. Use the switches to show or hide them at the bottom of the message.”), which controls whether 7 system fields — channel, snooze deadline, severity, aggregated alert count, responders, the details button, and AI analysis — are rendered at the bottom of the card.Create war room can be configured on Feishu/Lark app, Dingtalk app, and Slack app templates (backed respectively by the feishu_app_war_room_enabled, dingtalk_app_war_room_enabled, and slack_app_war_room_enabled fields, off by default; save the template to apply the change). The switch itself is labelled Create war room, and the panel describes it as “Once enabled, a dedicated Create War Room button is shown at the bottom of the card when the group-creation conditions are met.”
  • On: when the incident is not closed, has no war room yet, and has responders, the card for that channel shows a dedicated 👥 Create War Room button at the bottom; clicking it starts group creation
  • Off: no such button is shown
Keep custom actions after incident closure is offered on Feishu/Lark app, Dingtalk app, Slack app, and Microsoft Teams templates; the WeCom app template does not offer it (the panel does not render the switch for that channel). It is backed by the incident_card_closed_action_apps field — an array of the channel keys for which the capability is enabled (e.g. ["feishu_app"]), off by default (an empty array means off); save the template to apply the change.
  • On (panel description: “Enabled. Configured custom actions can be run from the message card for 3 days after the incident is closed. After that, run them from the incident details.”): configured custom actions can still be run directly from the message card for 3 days after the incident is closed; after that, run them from the incident details page
  • Off (panel description: “Disabled. Custom actions are hidden from the message card after the incident is closed. You can still run them from the incident details.”): the message card no longer shows the custom actions entry once the incident is closed; they can still be run from the incident details page
Together with the 7 card-field switches above, the Additional info panel holds 9 switches on Feishu/Lark app, Dingtalk app, and Slack app templates, 7 on Microsoft Teams, and 6 on WeCom app (see the channel template tabs below).The card’s bottom action area has changed as well: More Actions (that placeholder is its label) is now a dropdown select menu holding custom actions, snooze durations, and unacknowledge — the war room button is no longer one of its entries.

Bot Templates

Template formats supported by group chat bots.
Supports message card, rich text, and plain text formats. Max message 4000 bytes, truncated if exceeded.

Other Channels

Default Template:

Configure Escalation Rules

Define incident notification rules and escalation mechanisms

Configure Personal Preferences

Customize notification time periods and channel preferences