Loggly’s alert feature is available only on paid plans (Standard, Pro); the free Lite plan has no alerting. The 30-day trial needs no credit card and includes full alert functionality.
In Flashduty On-call
You can obtain an integration push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, select Channel and open a channel
- Select Configuration → Integrations → Private integration, then click Add an integration
- Select Loggly, then click Save
- Open the generated integration card and copy the Push URL
Use a shared integration
- In the Flashduty console, select Integration Center → Alert Events
- Select Loggly and enter an integration name
- Configure the default route and select a channel; after creation, add more rules under Route if needed
- Click Save and copy the generated Push URL
Configure Loggly
1
Create or edit an alert
Sign in to Loggly, open Alerts, and create a new alert based on a saved search, or edit an existing one.
2
Add an HTTP Endpoint
In the alert’s notification methods, choose HTTP Endpoints:After saving, confirm this HTTP Endpoint is enabled in the alert’s notification list.
- Paste the full Flashduty push URL into the URL field. The URL must include
integration_key - Set the request method to POST (Loggly supports both POST and GET; Flashduty’s push endpoint only accepts POST)
3
Turn on the auto-resolve timeout
Loggly’s HTTP Endpoints notification has no recovery event: as long as the alert condition holds, Loggly keeps re-sending the same alert on every check (for example, checking every minute while the condition holds for 30 minutes sends 30 notifications). Once the condition clears, Loggly simply stops sending — it never tells Flashduty the alert recovered.In the channel that receives these alerts, turn on the auto-resolve timeout. Set the timeout to cover at least 2-3 of the saved search’s check intervals (for example, 30 minutes for a 1-minute check interval, or 3 hours for a 1-hour interval), counted from Incident trigger.
4
Verify
Loggly’s HTTP Endpoints has no separate test-delivery button. Make the saved search match in a real environment (for example, temporarily lower the threshold, or trigger a log line the search would match), confirm the matching alert appears in Flashduty, then restore the threshold.
Alert Key
Flashduty keys the alert on the Loggly account subdomain (
owner_subdomain) combined with the alert-definition ID. The alert-definition ID is parsed from edit_alert_link (the alert’s edit-page URL) — the number after /alerts/edit/, for example 8188 in .../alerts/edit/8188.
A request is rejected if edit_alert_link is missing, or is not shaped like /alerts/edit/<numeric ID>.
Repeated notifications from the same alert definition while its condition holds merge into one Flashduty alert instead of opening a new one each time; changes to the alert name, hit count, time window, or query do not affect the Alert Key.
Severity
Loggly’s HTTP Endpoints notification carries no severity field, so every alert triggers at Warning. A saved search crossing its hit-count threshold is not on its own an outage signal; raise the severity with an alert rule in Flashduty if a given saved search warrants it.
Labels
FAQ
I configured an HTTP Endpoint but never receive an alert. Why?
I configured an HTTP Endpoint but never receive an alert. Why?
First confirm the account is on a paid plan (Standard/Pro) or still within the 30-day trial — the free Lite plan has no alerting. Then confirm this HTTP Endpoint is checked/enabled in the alert’s notification methods, and that the saved search is actually matching data.
Why does the alert never close?
Why does the alert never close?
Loggly’s generic HTTP Endpoints has no recovery event; once the condition clears, Loggly simply stops sending and never announces a recovery. Turn on the channel’s auto-resolve timeout, or close the alert manually in Flashduty.
Is it normal to get many deliveries for the same alert in a short time?
Is it normal to get many deliveries for the same alert in a short time?
Yes. As long as the saved search’s condition keeps holding, Loggly keeps re-sending on every check. Flashduty merges these deliveries into the same alert instead of opening a new one each time.
Can the payload be customized?
Can the payload be customized?
No. The HTTP Endpoints JSON shape is fixed by Loggly and its fields cannot be changed. Loggly offers separate native integrations for PagerDuty, Slack, and OpsGenie if you need to forward alerts elsewhere, but those do not go through this integration.