Skip to content
Slack

Slack integration

Slack is where the team already is when something breaks. A message in a busy channel is a notification nobody is accountable for reading, so ITOC360 posts the incident there and pages a named engineer at the same time.

How ITOC360 connects to Slack

The incident, in the channel

Every incident opens a message carrying what fired, which service it belongs to and who is on call for it — so the people watching the channel know as much as the person being paged.

Acknowledge without leaving

Acknowledge, escalate or resolve from the message. The responder is usually already in Slack, and a page that makes them find a laptop first is a page that takes longer to answer.

A channel is not an escalation

Posting and paging happen together. If nobody acknowledges, the escalation policy carries on through voice and SMS to the next person, whatever the channel is doing.

One thread, one timeline

Acknowledgements and status changes from Slack land in the incident's audit trail with actor and timestamp, so the postmortem is not reconstructed from scrollback.

A busy channel is a good place to tell a team something and a bad place to make somebody responsible for it. ITOC360 treats it as exactly that: the incident is posted where the team is already looking, and the person on call is paged on their own account at the same moment.

The message carries what fired, the service it belongs to and who has it. Acknowledging, escalating or resolving from that message writes to the incident's timeline, so the record of who did what does not live in a scrollback nobody can search a month later.

How it works

Monitoring sources
Alibaba CloudMonitor
Amazon CloudWatch
AppDynamics
Argo CD
AWS Budget
AWS GuardDuty
Azure Activity Logs
Azure Cost Budget
Azure DevOps
Azure Log Alerts
Azure Metric Alerts
Azure Service Health
Checkmk
Cortex
CrowdStrike
Datadog
Dynatrace
Elastic
GitHub
GitLab
Google Cloud Monitoring
Google Security Command Center
Grafana
Grafana Loki
Grafana Mimir
Graylog
InfluxDB
Instana
Jenkins
Jira
Kibana
Linear
ManageEngine OpManager
Microsoft Sentinel
Microsoft Teams
MongoDB Atlas
n8n
Netdata
New Relic
Pingdom
Postman
Prometheus
PRTG Network Monitor
Rollbar
Salesforce
Sentry
ServiceNow
SignalFx
SigNoz
Site24x7
Slack
SolarWinds Orion
StatusCake
Statuspage.io
Terraform Cloud
Twilio
VictoriaMetrics
Zabbix
Zapier
Growing integration library
ITOC360 core
Alert Ingestion & Deduplication
Noise Reduction / Grouping
Routing engine
On-call Schedule
Escalation Policy
Rotations
Notification layer
SMS
Voice Call
E-mail
Responder actions
Acknowledge
Assign
Resolve
Post-incident
Timeline Report

Common questions

How does ITOC360 connect to Slack?

Through a Slack app your workspace administrator installs. It is granted the channels you choose rather than the whole workspace, and the token is stored encrypted and never returned in plaintext.

Which channel does an incident go to?

Whichever you route it to. Channels can be set per service or per escalation policy, so a database alert and a billing alert do not have to land in the same place.

Can we acknowledge an incident from Slack?

Yes. Acknowledge, escalate and resolve are on the message itself, and each action is recorded against the incident with who took it and when.

Does posting to Slack replace being paged?

No, and that is deliberate. The message is for the people watching; the page is for the person responsible. If the page is not acknowledged the escalation policy continues regardless of the channel.

What happens if Slack is down?

Slack is a channel, not the escalation path. Voice, SMS, push and email continue through your policy, so an outage at Slack does not become an outage in your response.

Connect Slack and stop missing alerts

Free to start, no card, and no agent to deploy on your monitoring host.