What It Does
Use Invoke REST connection to send alert or incident data to an external HTTP endpoint from an automation — and, on the alert-created trigger, to read values out of the response and write them back onto the alert.
The action starts with a saved REST connection, which supplies the HTTP method, base URL, preset headers, and timeout. In the automation, you can customize the path, query parameters, extra headers, and JSON body for that specific request.
<aside>
💡
Keep reusable connection details in Settings → Shared Resources → Connections. Use this action's Request settings pane only for values that change per automation.
</aside>
When To Use It
Use this action when you want to:
- create or update records in another system when an alert or incident changes
- send event details to an internal webhook
- forward selected fields to a custom workflow or event pipeline
- call a team-owned API without duplicating connection credentials in every automation
- enrich a new alert with details only another system knows — the owner of a host, the environment it runs in
Before You Start
- Create and enable a REST connection in Settings → Shared Resources → Connections.
- Choose one of the supported triggers: Alert is created, Alert timeline is updated, Incident is created, or Incident timeline is updated.
- Use a POST, PATCH, or PUT connection if the endpoint needs a JSON body. GET and DELETE requests do not show the JSON body field.
- The placeholder list follows the trigger: alert triggers offer alert fields; incident triggers offer incident fields.
Configure the Action
- Go to Settings → Shared Resources → Automation Actions, then create a new automation or open an existing one.
- Choose a supported trigger.
- Select Add action → Invoke REST connection.