Integrations
Fits the stack you already run
Ember reads your alerts, logs, traces, metrics, deploys and changelogs from the tools already in your environment. It posts the root cause, drafted fix and incident timeline back where the incident lives. Two-way on Team.
Where the incident starts
Ember opens the incident the moment an alert fires, reading the alarm, the affected service and the on-call context before the first responder opens their laptop.
PagerDuty
Inbound webhook opens the incident with alarm, service and on-call context.
Opsgenie
Alert payload feeds the initial read alongside the current duty rotation.
Grafana Alerting
Alert rules and annotation events trigger Ember with the panel context attached.
CloudWatch
SNS-routed alarms arrive with metric namespace, dimensions and breach data.
The evidence Ember reads
Error logs, distributed traces and stack frames are pulled for the incident window, correlated on a timeline, and cited in the ranked root cause.
Datadog
Queries log events and APM traces over the incident window.
Loki
LogQL queries pull log streams for the affected service across the alarm period.
Sentry
Error events and stack traces are correlated with deploy releases.
Honeycomb
Trace queries surface slow spans and anomalous columns over the alarm window.
Tempo
Distributed traces fetched by trace ID are attached to the cause evidence.
OpenTelemetry
OTLP log and trace data flows directly when a Collector is already in use.
New Relic
NRQL queries pull error rate, latency percentiles and traces for the window.
Saturation, error rate and latency
Metric queries run against the alarm window to confirm saturation, error rate and latency signals that logs alone do not show.
Prometheus
PromQL queries pull saturation, error rate and latency during the incident.
Grafana
Metric panels and dashboards are queried for the relevant service and window.
What changed before the alarm
Recent commits, releases and infrastructure changes are correlated with the alarm time. When the timing lines up, Ember says so and raises the confidence accordingly.
GitHub
Recent commits, PR merges and Actions runs are correlated with the alarm.
GitLab
Merge requests and pipeline events contribute to the deploy correlation.
Kubernetes
Deployment events, pod restarts and HPA scale events feed the change log.
Terraform
Plan and apply runs surface infrastructure changes near the alarm time.
Where Ember posts back
Ember posts the ranked cause, fix and timeline into the channel or ticket where the incident already lives. It does not ask the team to move to a new tool.
Slack
Ember posts the root cause and fix into the incident channel. Two-way on Team: approve a drafted rollback directly from the thread.
Jira
Incident tickets are created or updated with the ranked cause, confidence and timeline.
Confluence
Postmortem drafts export to a Confluence page with the full incident timeline.
Notion
Postmortem drafts export to a Notion page with the timeline and action items included.
Don't see your tool? Tell us what you run and we will add it to the roadmap.
Put Ember on your next incident.
Start free and run a real incident in a minute, or talk to us about Team and Scale.