Skip to main content
When a tripwire fires, Thumper delivers the alert to every configured destination - the fan-out is automatic. Each alert plugin gets the same enriched event. A plugin that fails is logged and skipped; one bad destination never drops the alert for the others.

Available integrations

The alert event

Every alert plugin’s alert() method receives the same event dict: Enrichment fields are present when the sensor can supply them - fs_usage on macOS provides process and user; the atime fallback does not.

Roll your own

An alert plugin implements a single alert(event) method and raises on failure. The same event dict above is what you deliver. See Writing a plugin for the directory layout, manifest, and the AlertPlugin class (including the built-in test() that sends a synthetic event through the real send path).