Start log triage from an incident webhook
When an incident starts, searching logs and finding the right runbook both take time. Use a webhook to kick off a focused log search and collect a concise summary.
Trigger
Webhook received
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Action
Search logs
Searches datadog logs with advanced filtering capabilities. important notes: - sort parameter is not supported by the datadog logs api and will cause errors - time parameters must be in milliseconds (13-digit unix timestamps) - limit parameter is passed as string to the api - log content is nested under 'content' field in api response useful for troubleshooting, monitoring application behavior, and analyzing log patterns.
Why this helps
Responders lose time gathering the same incident context across logs, alerts, and documentation.
- Start log triage from an HTTP request
- Use service and time window details supplied with the request
- Return a concise summary for the chosen report channel
Setup
Build it in a few focused steps.
- 1Connect Datadog and Box once in the Notis portal.
- 2Create an automation named Webhook log triage.
- 3Tell Notis: When this webhook starts, search Datadog logs for the supplied service and millisecond time range, summarize relevant results, and include only Box runbook context I provide.
- 4Pick the webhook trigger and choose where run reports go.
- 5Test with one real incident example and a valid 13-digit millisecond time range.
Questions about this workflow
What does the webhook need to provide?
Provide enough context to search, such as the service or query and start/end times in milliseconds. The Datadog log action requires 13-digit Unix millisecond timestamps.
Can this conclude the root cause automatically?
It can summarize matching log results. Treat conclusions as leads and verify them against the underlying evidence.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link Box to Datadog. A trigger fires from one place; an action lands in another.
Box triggers
Datadog actions
Recurring trigger
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Create Dashboard
Create a dashboard in datadog. dashboards provide customizable visualizations for monitoring your infrastructure, applications, and business metrics in a unified view.
Webhook trigger
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Create downtime
Creates a new downtime in datadog to suppress alerts during maintenance windows or planned outages. useful for preventing false alarms during deployments or maintenance.
Collaboration Details Changed
Triggers when a collaboration's details change (e.g., role, status, expiration). This trigger monitors a specific collaboration and detects when any meaningful field changes, such as role, status, expiration date, access type, or acknowledgment status.
Create event
Creates a new event in datadog. events are useful for tracking deployments, outages, configuration changes, and other important occurrences.
Comment Changed
Triggers when a comment's content or details change in Box. This trigger monitors a specific Box comment and detects when any meaningful field changes, such as message text edits, tagged message changes, or modification timestamp updates.
Create monitor
Creates a new datadog monitor to track metrics, logs, or other data sources with configurable alerting thresholds and notifications.
New File Comment Added
Triggers when a new comment is added to a file in Box. This trigger monitors a specific Box file and fires when new comments are detected.
Create SLO
Create a service level objective (slo) in datadog. slos help you define and track reliability targets for your services, enabling data-driven decisions about service quality and reliability investments.
File Metadata Changed
Triggers when a file's metadata or properties change in Box. This trigger monitors a specific Box file and fires when changes are detected in key fields like name, description, size, modification time, parent folder, or status.
Create Synthetic API Test
Create a synthetic api test in datadog. creates a new synthetic api test that continuously monitors api endpoints from multiple locations worldwide. useful for proactive monitoring of api uptime, performance, and functionality.
File Shared Link Changed
Triggers when a file's shared link settings change in Box. This trigger monitors a specific Box file's shared link and fires when changes are detected in the shared link configuration, such as access level, permissions, password protection, expiration date, or vanity URL.
Create Webhook
Create a webhook in datadog. webhooks enable you to receive notifications from datadog monitors and alerts to external services and applications.
New File Version Uploaded
Triggers when a new file version is uploaded to a file in Box. This trigger monitors a specific Box file and fires when new versions are detected.
Delete Dashboard
Delete a dashboard in datadog. permanently removes a dashboard from your organization. this action cannot be undone. use with caution.
Connect any two apps with Notis in the middle.
Box and Datadog, or any other combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Datadog.