Skip to main content

Event Tasks

Store and track events for analysis and troubleshooting.

events.store​

Display Name: Store Event

Save an event to Nudgebee for later troubleshooting and analysis. Events can trigger notifications, AI analysis, and appear in the event timeline.

Deduplication by finding_id

Events are uniquely identified by the combination of tenant, account_id, and finding_id. If you submit an event with a finding_id that already exists for the same tenant and account, no new event will be created. Instead, the existing event will be updated with the new values for labels, priority, subject_name, subject_namespace, subject_type, cloud_resource_id, subject_owner, and subject_owner_kind. Fields like title, description, starts_at, and evidences are not updated on deduplication.

To create a separate event for each occurrence, ensure each event has a unique finding_id (e.g., append a timestamp or sequence number: PR_kwDOIzHflc7SOPfp::1, PR_kwDOIzHflc7SOPfp::2).

Top-Level Parameters​

FieldTypeRequiredDefaultDescription
eventobjectYes—The event object (see below).
trigger_notification_imbooleanNotrueAuto-trigger IM notifications.
trigger_ai_analysisbooleanNotrueAuto-trigger AI analysis.

Event Object Fields​

FieldTypeRequiredDefaultDescription
account_idaccountNoCurrent workflow accountNB Account ID.
titlestringYes—Title for the event.
descriptionstringYes—Description for the event.
aggregation_keystringYes—Event type (used for playbook matching).
finding_idstringYes—Unique event ID at source. This is the dedup key — repeated values for the same tenant+account update the existing event. To create a separate event for each occurrence, use a unique value (e.g., PR_kwDOIzHflc7SOPfp::1).
finding_typestringYes—Event type at source.
subject_namestringYes—Event subject name.
statusstringYes—FIRING, RESOLVED, or CLOSED.
prioritystringYesINFODEBUG, INFO, LOW, MEDIUM, or HIGH.
sourcestringNoautomationEvent source (e.g., prometheus, pagerduty_webhook, automation, etc.).
categorystringNo—Event category.
subject_typestringNo—Event subject type.
subject_namespacestringNo—Event subject namespace.
subject_nodestringNo—Event subject node.
service_keystringNo—Event subject service key.
starts_attimestampNo—Event start time (ISO 8601).
ends_attimestampNo—Event end time (ISO 8601).
fingerprintstringNo—Event fingerprint for deduplication.
clusterstringNoAuto-derived from account nameCluster name.
principalstringNo—Event user/actor.
subject_ownerstringNo—Event subject parent.
subject_owner_kindstringNo—Event subject parent type.
labelsobjectNo—Key-value labels for auto investigation.
evidencesarrayNo—Evidence attachments (see Evidence schema below).

Evidence Object Fields​

FieldTypeRequiredDefaultDescription
typestringNomarkdownEvidence type.
dataobjectYes—Evidence data.
filenamestringYes—Evidence filename.
additional_infoobjectNo—Additional details for evidence.

Output​

NameTypeDescription
idstringCreated event ID.