> ## Documentation Index
> Fetch the complete documentation index at: https://docs.jesta.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Alert integrations

> Where a fired tripwire goes.

When a tripwire fires, Thumper delivers the alert to **every** configured
destination - the fan-out is automatic. Each alert plugin gets the same enriched
event. A plugin that fails is logged and skipped; one bad destination never drops
the alert for the others.

## Available integrations

| Integration | Status | Notes |
| - | - | - |
| **Loki** | Available | Pushes a structured log event to a Loki stream. |
| **Splunk (HEC)** | Coming soon | Sends each event to Splunk via the HTTP Event Collector as a SIEM destination. |
| **Generic webhook** | Available | One HTTP POST per alert (JSON body) to a URL you control. Optional signing secret adds `X-Thumper-Timestamp` + `X-Thumper-Signature` so the receiver can reject forged or replayed requests. |
| **Your own** | - | Slack, PagerDuty, EDR… \~30 lines. See below. |

## The alert event

Every alert plugin's `alert()` method receives the same event dict:

| Field | Meaning |
| - | - |
| `alert_id`, `deployment_id`, `tripwire_id`, `endpoint_id` | Identifiers |
| `tripwire_name`, `endpoint_hostname`, `token_type` | Display fields |
| `accessed_path`, `process`, `pid`, `os_user`, `event_type` | Enrichment from the endpoint monitor (`fs_usage`) |
| `timestamp`, `triggered_by` | When + a compact summary |

Enrichment fields are present when the sensor can supply them - `fs_usage` on
macOS provides process and user; the atime fallback does not.

## Roll your own

An alert plugin implements a single `alert(event)` method and raises on failure.
The same `event` dict above is what you deliver. See
[Writing a plugin](/thumper/writing-plugins) for the directory layout, manifest,
and the `AlertPlugin` class (including the built-in `test()` that sends a
synthetic event through the real send path).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.