ScienceLogic Integration
Create, acknowledge and resolve alerts in ilert based on events from ScienceLogic SL1.
ScienceLogic SL1 is an IT operations and AIOps platform that monitors and manages IT infrastructure, applications and cloud environments.
With ilert's ScienceLogic integration, events detected by SL1 automatically create alerts in ilert. That way, you will never miss a critical event and always alert the right person using ilert's on-call schedules, automatic escalation, and multiple alerting channels including SMS, phone calls, push notifications and Slack. The integration is bi-directional in the sense that acknowledging an event in SL1 acknowledges the corresponding alert in ilert, and clearing (healthy) an event resolves the alert. Alerts created in ilert also contain a backlink to the originating event in SL1.
In ilert: Create a ScienceLogic alert source
Go to Alert sources → Alert sources and click on Create new alert source.

Search for ScienceLogic in the search field, click on the ScienceLogic tile, and click on Next.

Give your alert source a name, optionally assign teams, and click Next.
Select an escalation policy by creating a new one or assigning an existing one.

Select your alert grouping preference and click Continue setup. You may click Do not group alerts for now and change it later.

The next page shows additional settings such as custom alert templates or notification priority. Click on Finish setup for now.
On the final page, ilert generates a ScienceLogic URL for this alert source. Copy this URL — you will need it in ScienceLogic in the next step.

You can find the ScienceLogic URL again later under the alert source's Settings tab.
In ScienceLogic: Configure the credential
ScienceLogic sends events to ilert through a Run Book automation that posts to the ilert ScienceLogic URL. The URL is stored in a SOAP/XML credential.
In the SL1 navigation, go to Manage → Credentials.

Click Create New to create a new SOAP/XML credential, or open the existing ilert Credential if it was provided by the ilert PowerPack.

Configure the credential with the following values, then click Save & Close:
Content Encoding:
text/xmlMethod:
POSTHTTP Version:
http/1.1URL: paste the ScienceLogic URL you copied from the ilert alert source
Assign the credential to the organization whose devices you want to monitor (e.g.
ILERT).

In ScienceLogic: Configure the automation policies
The integration uses three Run Book automation policies that keep alerts in ilert in sync with the state of the event in SL1:
ilert policy (created)
An event is created
Creates an alert
ilert policy (acknowledged)
An event is acknowledged
Acknowledges the alert
ilert policy (cleared)
An event is cleared / healthy
Resolves the alert
In the SL1 navigation, go to Registry → Run Book → Automation.

Confirm that the three ilert policy entries are present and their Policy State is Enabled.
Open a policy by clicking its wrench (edit) icon to review its configuration. Each policy aligns the devices and events you want to forward and runs the matching ilert Run Book action (for example, ilert action(accept) for the acknowledged policy). Set the Organization, Aligned Devices and Aligned Events to match what you want to monitor, then click Save.

That's it. When a matching event occurs in SL1, an alert is created in ilert. Acknowledging the event acknowledges the alert, and clearing the event resolves it.
FAQ
Will alerts in ilert be resolved automatically?
Yes. As soon as the corresponding event in SL1 is cleared (returns to healthy), the ilert policy (cleared) automation policy resolves the alert in ilert.
Can I use ScienceLogic with multiple alert sources in ilert?
Yes. Create an additional ScienceLogic alert source in ilert, then add another credential in SL1 using the new ScienceLogic URL and align the relevant automation policies to it.
Which events are forwarded to ilert?
Only the events aligned in the automation policies. Adjust the Aligned Devices and Aligned Events of each policy to control what is forwarded. Selecting (All events) forwards every event for the aligned devices.
Last updated
Was this helpful?