Skip to main content
Loggly is SolarWinds’ log management service. Its Alerts feature notifies you when a saved search’s hit count crosses a threshold. This integration uses Loggly’s HTTP Endpoints notification method to turn each Loggly alert into one Flashduty alert.
Loggly’s alert feature is available only on paid plans (Standard, Pro); the free Lite plan has no alerting. The 30-day trial needs no credit card and includes full alert functionality.

In Flashduty On-call


You can obtain an integration push URL in either of the following ways.

Use a dedicated integration

  1. In the Flashduty console, select Channel and open a channel
  2. Select Configuration → Integrations → Private integration, then click Add an integration
  3. Select Loggly, then click Save
  4. Open the generated integration card and copy the Push URL

Use a shared integration

  1. In the Flashduty console, select Integration Center → Alert Events
  2. Select Loggly and enter an integration name
  3. Configure the default route and select a channel; after creation, add more rules under Route if needed
  4. Click Save and copy the generated Push URL

Configure Loggly


1

Create or edit an alert

Sign in to Loggly, open Alerts, and create a new alert based on a saved search, or edit an existing one.
2

Add an HTTP Endpoint

In the alert’s notification methods, choose HTTP Endpoints:
  1. Paste the full Flashduty push URL into the URL field. The URL must include integration_key
  2. Set the request method to POST (Loggly supports both POST and GET; Flashduty’s push endpoint only accepts POST)
Loggly posts a fixed JSON object; the fields cannot be customized:
After saving, confirm this HTTP Endpoint is enabled in the alert’s notification list.
3

Turn on the auto-resolve timeout

Loggly’s HTTP Endpoints notification has no recovery event: as long as the alert condition holds, Loggly keeps re-sending the same alert on every check (for example, checking every minute while the condition holds for 30 minutes sends 30 notifications). Once the condition clears, Loggly simply stops sending — it never tells Flashduty the alert recovered.In the channel that receives these alerts, turn on the auto-resolve timeout. Set the timeout to cover at least 2-3 of the saved search’s check intervals (for example, 30 minutes for a 1-minute check interval, or 3 hours for a 1-hour interval), counted from Incident trigger.
4

Verify

Loggly’s HTTP Endpoints has no separate test-delivery button. Make the saved search match in a real environment (for example, temporarily lower the threshold, or trigger a log line the search would match), confirm the matching alert appears in Flashduty, then restore the threshold.

Alert Key


Flashduty keys the alert on the Loggly account subdomain (owner_subdomain) combined with the alert-definition ID. The alert-definition ID is parsed from edit_alert_link (the alert’s edit-page URL) — the number after /alerts/edit/, for example 8188 in .../alerts/edit/8188. A request is rejected if edit_alert_link is missing, or is not shaped like /alerts/edit/<numeric ID>. Repeated notifications from the same alert definition while its condition holds merge into one Flashduty alert instead of opening a new one each time; changes to the alert name, hit count, time window, or query do not affect the Alert Key.

Severity


Loggly’s HTTP Endpoints notification carries no severity field, so every alert triggers at Warning. A saved search crossing its hit-count threshold is not on its own an outage signal; raise the severity with an alert rule in Flashduty if a given saved search warrants it.

Labels


FAQ


First confirm the account is on a paid plan (Standard/Pro) or still within the 30-day trial — the free Lite plan has no alerting. Then confirm this HTTP Endpoint is checked/enabled in the alert’s notification methods, and that the saved search is actually matching data.
Loggly’s generic HTTP Endpoints has no recovery event; once the condition clears, Loggly simply stops sending and never announces a recovery. Turn on the channel’s auto-resolve timeout, or close the alert manually in Flashduty.
Yes. As long as the saved search’s condition keeps holding, Loggly keeps re-sending on every check. Flashduty merges these deliveries into the same alert instead of opening a new one each time.
No. The HTTP Endpoints JSON shape is fixed by Loggly and its fields cannot be changed. Loggly offers separate native integrations for PagerDuty, Slack, and OpsGenie if you need to forward alerts elsewhere, but those do not go through this integration.
For field details, see Loggly Alert Endpoints and Loggly Alerts.