SolarWinds Papertrail

SolarWinds Papertrail delivers cloud-hosted log management for faster troubleshooting of infrastructure and application issues. Combined with xMatters, this integration with relays critical insight data to the correct people and systems to help them coordinate and resolve incidents faster.

This workflow lets you send actionable alerts to on-call resources when xMatters gets a signal from Papertrail. Responders can initiate an incident with the press of a button, or you can build on the flow to perform automated resolution tasks.

How it works

When an alert is generated in Papertrail, it sends a JSON-formatted webhook to xMatters, based on user-defined alert rules. A Papertrail Alert trigger in xMatters parses the webhook and initiates a flow. The webhook includes essential alert data you can use to enrich notifications to users or when building automated tasks.

Install the workflow

The following instructions describe how to install the workflow through the xMatters one-click installation process.

  1. Go to the Workflow Templates page and click the SolarWinds Papertrail tile.
  2. On the Set up the Workflow tab, give the workflow a name (this must be unique in your instance) and add an optional description.
    • You can edit these later, if needed.

  3. Click Next to set up the connection.
  4. Choose the authentication method you want to use to generate the trigger URL.
  5. Click Next.
  6. Copy the trigger URL — you’ll use this to configure the webhooks in SolarWinds Papertrail.
    • The trigger URL includes the recipients parameter, which specifies who should be notified. By default, this parameter is set to notify you (the logged in user), but you can set it to target any user or group you want.

  7. Click Open Workflow.

Configure Papertrail to send requests to the trigger URL

To have Papertrail send an alert to xMatters, you must first have at least one saved search in Papertrail.

You can create a new saved search or use an existing saved search:

  • To save a new Papertrail search:
    • Go to Events and search for the logs you want Papertrail to alert on. Refine the returned matches, then click Save Search.
    • On the Save Search window, give the search a unique name, then click Save & Setup an Alert.
  • To set up an alert on an existing Papertrail search:
    • On the Dashboard, click the pencil icon on the saved search and select New Alert.

Set recipients in the trigger URL

The trigger expects the recipients in the trigger URL. When you copy the URL from xMatters, it includes the recipients parameter: recipients=<yourname>. Of course, you don’t want to receive all the alerts.

To change the recipients for alerts from this webhook, swap out your name for the people or groups you want to target. For example, to target the 'DatabaseTeam', 'Antares Service Team', and 'HR & Marketing' groups, add recipients=databaseteam,antares%20service%20team,HR%20%26%20Marketing to the trigger URL. Remember to URL-encode any special characters, including spaces, in your group names.

We recommend using groups so you can take advantage of the xMatters group features — rotations, escalations, and absences — to reach the right on-call people to jump on an issue.

How to use the workflow

When a condition you've set fires, it sends a signal to xMatters, which creates an alert and notifies the individual or the on-call members of the people or groups you set as recipients in the webhook URL. When the trigger receives a signal saying the issue is resolved, it automatically terminates related alerts in xMatters.

Next Steps

Now that you've installed the workflow, you can use it as-is, or customize it to suit your needs better. Here are some examples of things you can add to the workflow to customize it: