Skip to content

AWS CloudWatch ​

AWS CloudWatch alarms reach Exhale through an SNS HTTPS subscription. Each tenant gets a unique HTTPS URL token. Exhale scrubs the nested alarm payload, upserts a Pulse (source=aws_cloudwatch), and runs triage when NewStateValue is ALARM.

This is ingest (creates Pulses). For metric and alarm enrichment at triage time, see AWS CloudWatch context.

See Sources for how CloudWatch fits with the other incoming webhooks.

On the hosted app, use the URL Connections copies. It starts with https://exhaleoncall.com/webhooks/. The customer host does not publish /v1/webhooks/....


Endpoint ​

After Connect in Connections → Sources → Observability & alerts → AWS CloudWatch:

Preferred (keeps tokens out of proxy access logs):

POST https://exhaleoncall.com/webhooks/aws-cloudwatch

Send header X-Exhale-Webhook-Token: {token}.

Path form (also supported):

POST https://exhaleoncall.com/webhooks/aws-cloudwatch/{token}
  • token — opaque URL segment; this token authenticates the delivery.
  • Response: 202 Accepted with pulse_id, status, created, and message for alarm notifications.

Unknown tokens return 404. Disabled or expired-trial tenants return 403.


Customer setup ​

  1. Sign in as admin → Connections → Sources → AWS CloudWatch.
  2. Click Connect AWS CloudWatch and copy the webhook URL.
  3. In AWS, create an SNS topic and an HTTPS subscription pointing at the Exhale URL.
  4. Confirm the subscription manually by opening the SubscribeURL from the SNS SubscriptionConfirmation email/payload in a browser (or GET that URL). Exhale acks the confirmation with 202 and does not create a Pulse — and does not auto-confirm SubscribeURL.
  5. Route CloudWatch alarms to that SNS topic.
  6. Send test alert creates a synthetic ALARM pulse and marks the integration configured.

See Amazon SNS's official guide: Subscribing an HTTPS endpoint to an Amazon SNS topic. See Amazon CloudWatch's official guide: Notifying users on alarm changes.

Rotate webhook token replaces the previous URL right away. Update SNS and re-confirm after rotating.


SNS + payload shape ​

SNS TypeBehavior
SubscriptionConfirmationAck only — open SubscribeURL yourself; no Pulse
NotificationNested CloudWatch JSON in Message → Pulse
UnsubscribeConfirmationAck only; no Pulse
Alarm fieldRequiredNotes
AlarmNameYesExternal id (optionally :{Region}:{AccountId})
NewStateValueNoALARM, OK, INSUFFICIENT_DATA

Lifecycle mapping ​

CloudWatch statePulse status
ALARMReceived → triage
OKResolved
INSUFFICIENT_DATAUpdates the payload when a pulse already exists; no new pulse

Example ​

bash
TOKEN="your-url-token"
curl -i -X POST "https://exhaleoncall.com/webhooks/aws-cloudwatch/${TOKEN}" \
  -H "Content-Type: application/json" \
  -d '{"Type":"Notification","Message":"{\"AlarmName\":\"HighCPU\",\"NewStateValue\":\"ALARM\"}"}'

SNS HTTPS subscriptions require a one-time SubscribeURL confirmation (Exhale logs the URL; confirm from AWS or the operator runbook). See Errors & authentication for structured errors, 413 size limits, Redis delivery dedupe, and token rotation.

Exhale by Kolstrom Systems LLC