Skip to content
Notis

Start log triage from an incident webhook

When an incident starts, searching logs and finding the right runbook both take time. Use a webhook to kick off a focused log search and collect a concise summary.

Trigger

Webhook received

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

Action

Search logs

Searches datadog logs with advanced filtering capabilities. important notes: - sort parameter is not supported by the datadog logs api and will cause errors - time parameters must be in milliseconds (13-digit unix timestamps) - limit parameter is passed as string to the api - log content is nested under 'content' field in api response useful for troubleshooting, monitoring application behavior, and analyzing log patterns.

Why this helps

Responders lose time gathering the same incident context across logs, alerts, and documentation.

  • Start log triage from an HTTP request
  • Use service and time window details supplied with the request
  • Return a concise summary for the chosen report channel

Setup

Build it in a few focused steps.

  • 1Connect Datadog and Box once in the Notis portal.
  • 2Create an automation named Webhook log triage.
  • 3Tell Notis: When this webhook starts, search Datadog logs for the supplied service and millisecond time range, summarize relevant results, and include only Box runbook context I provide.
  • 4Pick the webhook trigger and choose where run reports go.
  • 5Test with one real incident example and a valid 13-digit millisecond time range.

Questions about this workflow

What does the webhook need to provide?

Provide enough context to search, such as the service or query and start/end times in milliseconds. The Datadog log action requires 13-digit Unix millisecond timestamps.

Can this conclude the root cause automatically?

It can summarize matching log results. Treat conclusions as leads and verify them against the underlying evidence.

When this happens · Trigger

Do this · Action

Supported Triggers and Actions

Notis builds workflows that link Box to Datadog. A trigger fires from one place; an action lands in another.

Box triggers

Datadog actions

Recurring trigger

Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.

TriggerScheduled

Create Dashboard

Create a dashboard in datadog. dashboards provide customizable visualizations for monitoring your infrastructure, applications, and business metrics in a unified view.

ActionInstant

Webhook trigger

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

TriggerInstant

Create downtime

Creates a new downtime in datadog to suppress alerts during maintenance windows or planned outages. useful for preventing false alarms during deployments or maintenance.

ActionInstant

Collaboration Details Changed

Triggers when a collaboration's details change (e.g., role, status, expiration). This trigger monitors a specific collaboration and detects when any meaningful field changes, such as role, status, expiration date, access type, or acknowledgment status.

TriggerPolling

Create event

Creates a new event in datadog. events are useful for tracking deployments, outages, configuration changes, and other important occurrences.

ActionInstant

Comment Changed

Triggers when a comment's content or details change in Box. This trigger monitors a specific Box comment and detects when any meaningful field changes, such as message text edits, tagged message changes, or modification timestamp updates.

TriggerPolling

Create monitor

Creates a new datadog monitor to track metrics, logs, or other data sources with configurable alerting thresholds and notifications.

ActionInstant

New File Comment Added

Triggers when a new comment is added to a file in Box. This trigger monitors a specific Box file and fires when new comments are detected.

TriggerPolling

Create SLO

Create a service level objective (slo) in datadog. slos help you define and track reliability targets for your services, enabling data-driven decisions about service quality and reliability investments.

ActionInstant

File Metadata Changed

Triggers when a file's metadata or properties change in Box. This trigger monitors a specific Box file and fires when changes are detected in key fields like name, description, size, modification time, parent folder, or status.

TriggerPolling

Create Synthetic API Test

Create a synthetic api test in datadog. creates a new synthetic api test that continuously monitors api endpoints from multiple locations worldwide. useful for proactive monitoring of api uptime, performance, and functionality.

ActionInstant

File Shared Link Changed

Triggers when a file's shared link settings change in Box. This trigger monitors a specific Box file's shared link and fires when changes are detected in the shared link configuration, such as access level, permissions, password protection, expiration date, or vanity URL.

TriggerPolling

Create Webhook

Create a webhook in datadog. webhooks enable you to receive notifications from datadog monitors and alerts to external services and applications.

ActionInstant

New File Version Uploaded

Triggers when a new file version is uploaded to a file in Box. This trigger monitors a specific Box file and fires when new versions are detected.

TriggerPolling

Delete Dashboard

Delete a dashboard in datadog. permanently removes a dashboard from your organization. this action cannot be undone. use with caution.

ActionInstant

Connect any two apps with Notis in the middle.

Box and Datadog, or any other combination from 1,000+ integrations.

When this happens · Trigger

Do this · Action

Save your first hour today.

7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Datadog.