Fleet integration
Receive critical osquery fleet events via SMS, push and voice calls
Connecting Fleet with ilert enables you to receive alerts on suspicious behavior, policy failures or host issues – and manage them via ilert’s routing, escalation, and alert grouping. This improves visibility, speeds up incident response, and reduces MTTR.
In ilert: Create a Fleet alert source
Go to Alert sources -> Alert sources and click Create new alert source.
Search for Fleet in the search field, click the Fleet tile, and then Next.
Give your alert source a name, optionally assign teams, and click Next.
Select an escalation policy by creating a new one or assigning an existing one.
Select your Alert grouping preference and click Continue setup. You may click Do not group alerts for now and change it later.
The next page shows additional settings, such as customer alert templates or notification priority. Click Finish setup for now.
On the final page, an API key and/or webhook URL will be generated. You will need it later.

In Fleet: Create a Software Vulnerability Webhook
In the top menu bar, click Software.

On the next page, click Manage automations.

Enable the Vulnerability automations toggle and set the Workflow to Webhook.
In the Destination URL field, enter the Fleet DM URL generated earlier in ilert.
Click Save to finish the setup.

In Fleet: Create a failing Policy Webhook
In the top menu bar, click Policies.

On the next page, click Manage automations, then select the Other tab.

Enable the toggle and set the Workflow to Webhook.
In the Destination URL field, enter the Fleet DM URL generated earlier in ilert.

Select the policies for which you want to receive alerts in ilert.
Click Save to complete the configuration.

FAQ
Will alerts in ilert be resolved automatically?
No, unfortunately Fleet is not compatible with ilert's resolve event.
Last updated
Was this helpful?