Skip to main content

Notification variables

The event fields and helper functions available inside a message template.

Message templates are Go text/template.

The trap that catches everyone: event fields hang off $event, not off the template's top-level .. Writing {{"{{"}}.RuleName{{"}}"}} silently renders an empty string, and {{"{{"}}timeformat .TriggerTime{{"}}"}} fails outright with invalid value; expected int64.

{{ $event.RuleName }} correct
{{ .RuleName }} renders empty
{{ timeformat $event.TriggerTime }} correct

For a working example to copy, open the built-in dingtalk template — it is the most complete one.

Commonly used event fields​

FieldMeaning
$event.RuleNameRule name
$event.RuleNoteRule note
$event.SeveritySeverity, 1 / 2 / 3
$event.IsRecoveredWhether this is a recovery or a trigger
$event.TargetIdentTarget identifier (host name and so on)
$event.TargetNoteTarget note
$event.GroupNameBusiness group. Taken from the rule's group, not the target's
$event.TriggerValueThe value at trigger time
$event.TriggerTimeTrigger timestamp, for use with timeformat
$event.FirstTriggerTimeFirst trigger of a continuing alert — needed to compute duration
$event.LastEvalTimeLast evaluation. A recovery event uses this as its recovery time
$event.TagsJSONThe label set
$event.AnnotationsJSON.<key>Annotations, e.g. $event.AnnotationsJSON.summary
$event.RunbookURLThe runbook link set on the rule
$event.CateData source type
$event.DatasourceIdData source ID

Commonly used helper functions​

FunctionPurpose
timeformatTimestamp to readable time
humanizeDurationInterfaceSeconds to "3m 20s"
formatDecimalFix decimal places
add sub mul divArithmetic
nowCurrent time, usually now.Unix
toUpper toLower titleCase
contains match reReplaceAllString tests and replacement
split joinSplit and join
jsonMarshalTo JSON — the workhorse for webhook-style media
humanize humanizePercentageFriendlier numbers
escape unescaped safeHtmlEscaping control

The standard way to compute duration, copied from the built-in templates:

{{ $d := sub now.Unix $event.FirstTriggerTime }}{{ humanizeDurationInterface $d }}

For a recovery event use sub $event.LastEvalTime $event.FirstTriggerTime instead.

Some media types do not use templates​

callback, flashduty and pagerduty bypass message templates — their request body passes the event JSON straight through, and the UI does not offer a template picker for them. Every other media type drops the whole notification when its template is missing, and writes a failed notification record.

Site variables​

Values such as the site address are {{"{{"}}$.domain{{"}}"}} — note the dot. {{"{{"}}$domain{{"}}"}} resolves to nothing, and {{"{{"}}.domain{{"}}"}} stops working inside a range or with block.