Skip to content

Introduction to AlertKick

AlertKick is monitoring, on-call, and security for Linux infrastructure in one service. One agent collects metrics, eBPF security events, and SSH activity; managed pollers check websites, certificates, and domains from multiple regions; escalation policies and rosters make sure the right person is paged; and AI triage explains what a security event actually means before anyone is woken up.

AreaWhat you getStart here
Server monitoringCPU, memory, disk, network, processes, Docker containers, with default thresholds and custom check profilesServer monitoring
Uptime monitoringHTTP/HTTPS, TCP, DNS, SSL certificate, and domain-expiry monitors checked from several regionsMonitor types
HeartbeatsDead-man’s-switch monitoring for cron jobs, backups, and scheduled workHeartbeats
Alerting and on-callEscalation policies, rosters, rotations, overrides and swaps, Follow the Sun schedules, quiet hours, maintenance windowsEscalation policies
NotificationsSlack, Telegram, WhatsApp, SMS, email, mobile push, webhooksNotification channels
Inbound alertsPrometheus, Grafana, Datadog, Nagios, Zabbix, Sentry, CI pipelines, generic webhook, email, and moreInbound alert sources
eBPF securityKernel-level detection of SSH logins, reverse shells, crypto miners, rootkits, new listeners, and file changes, mapped to MITRE ATT&CKSecurity events
SSH and change controlSession and command tracking, trusted-IP rules, auto-block, SSH lockdown outside maintenance windows, change records with approve/verify/completeChange tracking
ComplianceContinuous PCI DSS and SOX evidence with audit-ready PDF reportsEvidence and reports
AIAI verdicts on security events, Kicker incidents and after-action reports, Claude and MCP access to your accountAI triage
  1. Agents run on your servers (Linux, Windows, Docker hosts). They ship metrics and security events over an authenticated WebSocket to the regional endpoint nearest them, and receive configuration pushes the same way. Install the agent.
  2. Pollers are AlertKick-managed probes that run uptime monitors from several regions. If you need checks against private networks, run an on-premise poller.
  3. Alerts are raised from thresholds, failed checks, missed heartbeats, security rules, or inbound integrations. Every alert is bound to an escalation policy that decides who is notified, through which channel, and how long to wait before escalating.
  4. Rosters decide who is on call at any moment. Policies can page a roster instead of a named person, so the schedule, not the policy, changes when people rotate. Roster management.
  5. The consolidated view shows alerts, security events, monitor state, and server health across every region in one place. The consolidated view.