Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
117 changes: 117 additions & 0 deletions docs/providers/documentation/nagios-provider.mdx
Original file line number Diff line number Diff line change
@@ -0,0 +1,117 @@
---
title: "Nagios Provider"
sidebarTitle: "Nagios"
description: "Nagios provider allows you to receive host and service alerts from Nagios in Keep."
---

import AutoGeneratedSnippet from '/snippets/providers/nagios-snippet-autogenerated.mdx';

<AutoGeneratedSnippet />

# Nagios Provider

The Nagios provider allows you to forward host and service notifications from
Nagios into Keep using a webhook-based integration.

This provider is intentionally lightweight and focuses on the most common
integration path for Nagios Core: custom notification commands that POST a JSON
payload to Keep.

## Overview

The provider supports:

- Host notifications
- Service notifications
- Problem and recovery flows through `notification_type`
- State/severity normalization into Keep alerts

## Webhook Configuration

To configure Nagios to send alerts to Keep:

1. Create a custom notification command that sends an HTTP POST request.
2. Set the target URL to your Keep webhook endpoint:

```text
{keep_webhook_api_url}
```

3. Add an `X-API-KEY` header using a Keep API key with webhook permissions.
4. Build the request body from standard Nagios macros.

Example payload for a **service** notification:

```json
{
"alert_type": "service",
"notification_type": "$NOTIFICATIONTYPE$",
"timestamp": "$LONGDATETIME$",
"host_name": "$HOSTNAME$",
"host_display_name": "$HOSTDISPLAYNAME$",
"host_address": "$HOSTADDRESS$",
"service_name": "$SERVICEDESC$",
"service_display_name": "$SERVICEDESC$",
"service_state": "$SERVICESTATE$",
"service_state_type": "$SERVICESTATETYPE$",
"service_attempt": "$SERVICEATTEMPT$",
"service_output": "$SERVICEOUTPUT$",
"service_perfdata": "$SERVICEPERFDATA$",
"service_check_command": "$SERVICECHECKCOMMAND$"
}
```

Example payload for a **host** notification:

```json
{
"alert_type": "host",
"notification_type": "$NOTIFICATIONTYPE$",
"timestamp": "$LONGDATETIME$",
"host_name": "$HOSTNAME$",
"host_display_name": "$HOSTDISPLAYNAME$",
"host_address": "$HOSTADDRESS$",
"host_state": "$HOSTSTATE$",
"host_output": "$HOSTOUTPUT$"
}
```

## Suggested Command Example

One practical approach is to use `curl` from a custom Nagios notification
command:

```bash
/usr/bin/curl -X POST \
-H "Content-Type: application/json" \
-H "X-API-KEY: <KEEP_API_KEY>" \
-d '<JSON_PAYLOAD_FROM_MACROS>' \
'<KEEP_WEBHOOK_URL>'
```

You can then attach that command to `host_notification_commands` and
`service_notification_commands` in your Nagios object definitions.

## State Mapping

### Host States

| Nagios State | Keep Status | Keep Severity |
|:-------------|:------------|:--------------|
| UP | RESOLVED | INFO |
| DOWN | FIRING | CRITICAL |
| UNREACHABLE | FIRING | CRITICAL |

### Service States

| Nagios State | Keep Status | Keep Severity |
|:-------------|:------------|:--------------|
| OK | RESOLVED | INFO |
| WARNING | FIRING | WARNING |
| CRITICAL | FIRING | CRITICAL |
| UNKNOWN | FIRING | INFO |

## Useful Links

- [Nagios Standard Macros](https://assets.nagios.com/downloads/nagioscore/docs/nagioscore/4/en/macrolist.html)
- [Nagios Notifications](https://assets.nagios.com/downloads/nagioscore/docs/nagioscore/4/en/notifications.html)
7 changes: 7 additions & 0 deletions docs/snippets/providers/nagios-snippet-autogenerated.mdx
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
{/* This snippet is automatically generated using scripts/docs_render_provider_snippets.py
Do not edit it manually, as it will be overwritten */}


## In workflows

This provider can't be used as a "step" or "action" in workflows. If you want to use it, please let us know by creating an issue in the [GitHub repository](https://github.com/keephq/keep/issues).
3 changes: 3 additions & 0 deletions keep/providers/nagios_provider/__init__.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
from keep.providers.nagios_provider.nagios_provider import NagiosProvider

__all__ = ["NagiosProvider"]
140 changes: 140 additions & 0 deletions keep/providers/nagios_provider/nagios_provider.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,140 @@
"""
Nagios Provider is a class that provides a way to receive alerts from Nagios
using webhook notifications.
"""

from keep.api.models.alert import AlertDto, AlertSeverity, AlertStatus
from keep.contextmanager.contextmanager import ContextManager
from keep.providers.base.base_provider import BaseProvider
from keep.providers.models.provider_config import ProviderConfig


class NagiosProvider(BaseProvider):
"""
Receive Nagios host and service notifications into Keep via webhooks.
"""

webhook_documentation_here_differs_from_general_documentation = True
webhook_description = ""
webhook_template = ""
webhook_markdown = """
To send alerts from Nagios to Keep, configure a custom notification command:

1. Create a notification command that POSTs JSON to `{keep_webhook_api_url}`.
2. Add header `X-API-KEY` with your Keep API key (webhook role).
3. Use Nagios macros such as `$NOTIFICATIONTYPE$`, `$HOSTNAME$`, `$HOSTSTATE$`,
`$HOSTOUTPUT$`, `$SERVICEDESC$`, `$SERVICESTATE$`, and `$SERVICEOUTPUT$` to
build the JSON payload.
4. Attach the command to your host and/or service notification definitions.
5. For a complete example, see the [Keep documentation](https://docs.keephq.dev/providers/documentation/nagios-provider).
"""

PROVIDER_DISPLAY_NAME = "Nagios"
PROVIDER_TAGS = ["alert"]
PROVIDER_CATEGORY = ["Monitoring"]
WEBHOOK_INSTALLATION_REQUIRED = True

HOST_STATUS_MAP = {
"UP": AlertStatus.RESOLVED,
"DOWN": AlertStatus.FIRING,
"UNREACHABLE": AlertStatus.FIRING,
}

HOST_SEVERITY_MAP = {
"UP": AlertSeverity.INFO,
"DOWN": AlertSeverity.CRITICAL,
"UNREACHABLE": AlertSeverity.CRITICAL,
}

SERVICE_STATUS_MAP = {
"OK": AlertStatus.RESOLVED,
"WARNING": AlertStatus.FIRING,
"CRITICAL": AlertStatus.FIRING,
"UNKNOWN": AlertStatus.FIRING,
}

SERVICE_SEVERITY_MAP = {
"OK": AlertSeverity.INFO,
"WARNING": AlertSeverity.WARNING,
"CRITICAL": AlertSeverity.CRITICAL,
"UNKNOWN": AlertSeverity.INFO,
}

def __init__(
self, context_manager: ContextManager, provider_id: str, config: ProviderConfig
):
super().__init__(context_manager, provider_id, config)

def dispose(self):
"""
Dispose of the provider.
"""
pass

def validate_config(self):
"""
Nagios webhook integration does not require provider-side configuration.
"""
pass

@staticmethod
def _format_alert(
event: dict, provider_instance: "BaseProvider" = None
) -> AlertDto | list[AlertDto]:
"""
Format Nagios notification payload into Keep alert format.

Supported payloads are intentionally simple and map closely to Nagios
host/service notification macros configured in the webhook command.
"""
alert_type = (event.get("alert_type") or "service").lower()

if alert_type == "host":
state = event.get("host_state", "DOWN")
output = event.get("host_output", "No output provided")
return AlertDto(
id=event.get("host_name"),
name=event.get("host_display_name") or event.get("host_name"),
status=NagiosProvider.HOST_STATUS_MAP.get(state, AlertStatus.FIRING),
severity=NagiosProvider.HOST_SEVERITY_MAP.get(
state, AlertSeverity.CRITICAL
),
description=output,
source=["nagios"],
hostname=event.get("host_name"),
state=state,
lastReceived=event.get("timestamp"),
timestamp=event.get("timestamp"),
notification_type=event.get("notification_type"),
raw_output=output,
host_address=event.get("host_address"),
)

state = event.get("service_state", "CRITICAL")
output = event.get("service_output", "No output provided")
return AlertDto(
id=event.get("service_name") or event.get("host_name"),
name=event.get("service_display_name") or event.get("service_name"),
status=NagiosProvider.SERVICE_STATUS_MAP.get(state, AlertStatus.FIRING),
severity=NagiosProvider.SERVICE_SEVERITY_MAP.get(
state, AlertSeverity.CRITICAL
),
description=output,
source=["nagios"],
hostname=event.get("host_name"),
host_address=event.get("host_address"),
service_name=event.get("service_name"),
check_command=event.get("service_check_command"),
state=state,
lastReceived=event.get("timestamp"),
timestamp=event.get("timestamp"),
notification_type=event.get("notification_type"),
raw_output=output,
current_attempt=event.get("service_attempt"),
state_type=event.get("service_state_type"),
performance_data=event.get("service_perfdata"),
)


if __name__ == "__main__":
pass
Loading