Send alerts to Slack, a webhook or a log collector
Send BetterShield’s high and critical alerts, or the whole activity log, to Slack, a JSON webhook or a syslog collector with BetterShield Ultra.
BetterShield emails its alerts (see Email alerts). With BetterShield Ultra, BetterShield › Ultra › Alert channels also sends them to up to five more places: a Slack channel, a webhook of your own, or a log collector over syslog. Email keeps working as before; a channel is added, never instead. Until you add one, the card says alerts go to the mailbox as before.
Add a destination
- Press Add a destination and fill in the row.
- Press Save. The whole list saves at once. If a row is missing something, nothing is saved and that row says what it needs.
- On the saved row, press Send a test message.
| Option | What it does | Default |
|---|---|---|
| Kind | Slack, Webhook (JSON) or Log collector (syslog). | Slack |
| Name | Your own label, such as the channel’s name. | Empty |
| Carries | Alerts only: the alerts that are emailed. Every event: the activity log itself. | Alerts only |
| Send | With Alerts only: High and critical, or Critical only. | High and critical |
| Which activity | With Every event: the activity log’s areas to send. At least one stays ticked. | Every area |
| Address | For Slack and a webhook, the https address to post to. | Empty |
| On | Switches the destination on or off without removing it. | On |
| Remove | Takes the row off when you save. |
For a log collector the row asks instead for Collector host, Port, Transport (UDP, TCP or Encrypted (TLS)) and Facility (user, daemon, auth, authpriv, or local0 to local7; local0 to start with). The port follows the transport, 514, or 6514 for TLS, unless you typed your own.
Alerts only, or every event
- Alerts only carries what is emailed the moment it happens: events rated high or critical. A burst arrives as one message: the first goes at once, and anything in the next five minutes joins one follow-up. Planned maintenance holds routine alerts here as it does for email, and the summary it ends with is sent.
- Every event carries the activity log in the areas you tick, whatever each event is rated, in batches. It is a feed for reading, not an interruption.
Mute all alerts, or turning off Email me about high and critical events as they happen under Settings › Email alerts, also quiets destinations set to Alerts only. It does not stop one set to Every event: switch that one off here.
What a message contains
Every message names the site and links back to its activity log. For each event it carries the kind of event, when it happened, its rating, the number of the account that acted (never a name), what it was about, and the event’s own detail. It never carries a password or key, file contents, or the network anyone connected from.
- Slack gets a short list, one line per event.
- Webhook (JSON) gets the same as a JSON body.
- Log collector (syslog) gets one RFC 5424 line per event, named bettershield, with the event’s fields in the structured-data block.
Address rules
- A Slack or webhook address must use https, be somewhere other than this site, and be on the public internet. An address inside your server’s network is refused. WordPress cannot post to a bare IPv6 address, so use a host name that also answers on IPv4.
- A log collector on the public internet must use Encrypted (TLS). One on your own network may use plain UDP or TCP once you tick This collector is on my own network. A link-local address is refused whatever is ticked.
- A saved address is never shown back, because anyone holding it could post into that channel as your site. The field then names only the host it is saved for: leave it blank to keep it.
Test and delivery
Send a test message sends one real message and says Delivered. Look for it in that channel., or Sent, not confirmed. over UDP, which cannot confirm arrival, or why it failed.
Messages never go out while a visitor loads a page or checks out. They wait for the next dashboard page, WP-CLI run or hourly task. A destination that refuses is tried again about an hour later, three tries in all; after that its messages are dropped and the activity log records Alert could not be delivered. Destinations that work keep receiving meanwhile.
Good to know
- Each site has up to five destinations. On multisite, each site sets its own.
- With Ask for my password before an action that removes a protection on (Settings › General), saving and testing ask for your password.
- What each destination receives is also listed on What BetterShield contacts.