Appearance
AWS CloudWatch
AWS CloudWatch alarms reach Exhale through an SNS HTTPS subscription. Each tenant gets a unique HTTPS URL token. Exhale scrubs the nested alarm payload, upserts a Pulse (
source=aws_cloudwatch), and runs triage when NewStateValue is ALARM.
This is ingest (creates Pulses). For metric and alarm enrichment at triage time, see AWS CloudWatch context.
See Sources for how CloudWatch fits with the other incoming webhooks.
On the hosted app, use the URL Connections copies. It starts with https://exhaleoncall.com/webhooks/. The customer host does not publish /v1/webhooks/....
Endpoint
After Connect in Connections → Sources → Observability & alerts → AWS CloudWatch:
Preferred (keeps tokens out of proxy access logs):
POST https://exhaleoncall.com/webhooks/aws-cloudwatchSend header X-Exhale-Webhook-Token: {token}.
Path form (also supported):
POST https://exhaleoncall.com/webhooks/aws-cloudwatch/{token}token— opaque URL segment; this token authenticates the delivery.- Response: 202 Accepted with
pulse_id,status,created, andmessagefor alarm notifications.
Unknown tokens return 404. Disabled or expired-trial tenants return 403.
Customer setup
- Sign in as admin → Connections → Sources → AWS CloudWatch.
- Click Connect AWS CloudWatch and copy the webhook URL.
- In AWS, create an SNS topic and an HTTPS subscription pointing at the
Exhale URL.
- Confirm the subscription manually by opening the
SubscribeURLfrom the SNSSubscriptionConfirmationemail/payload in a browser (or GET that URL). Exhale acks the confirmation with 202 and does not create a Pulse — and does not auto-confirmSubscribeURL. - Route CloudWatch alarms to that SNS topic.
- Send test alert creates a synthetic ALARM pulse and marks the integration configured.
See Amazon SNS's official guide: Subscribing an HTTPS endpoint to an Amazon SNS topic. See Amazon CloudWatch's official guide: Notifying users on alarm changes.
Rotate webhook token replaces the previous URL right away. Update SNS and re-confirm after rotating.
SNS + payload shape
SNS Type | Behavior |
|---|---|
SubscriptionConfirmation | Ack only — open SubscribeURL yourself; no Pulse |
Notification | Nested CloudWatch JSON in Message → Pulse |
UnsubscribeConfirmation | Ack only; no Pulse |
| Alarm field | Required | Notes |
|---|---|---|
AlarmName | Yes | External id (optionally :{Region}:{AccountId}) |
NewStateValue | No | ALARM, OK, INSUFFICIENT_DATA |
Lifecycle mapping
| CloudWatch state | Pulse status |
|---|---|
| ALARM | Received → triage |
| OK | Resolved |
INSUFFICIENT_DATA | Updates the payload when a pulse already exists; no new pulse |
Example
bash
TOKEN="your-url-token"
curl -i -X POST "https://exhaleoncall.com/webhooks/aws-cloudwatch/${TOKEN}" \
-H "Content-Type: application/json" \
-d '{"Type":"Notification","Message":"{\"AlarmName\":\"HighCPU\",\"NewStateValue\":\"ALARM\"}"}'Related
SNS HTTPS subscriptions require a one-time SubscribeURL confirmation (Exhale logs the URL; confirm from AWS or the operator runbook). See Errors & authentication for structured errors, 413 size limits, Redis delivery dedupe, and token rotation.