Introduction to AlertKick
AlertKick is monitoring, on-call, and security for Linux infrastructure in one service. One agent collects metrics, eBPF security events, and SSH activity; managed pollers check websites, certificates, and domains from multiple regions; escalation policies and rosters make sure the right person is paged; and AI triage explains what a security event actually means before anyone is woken up.
What AlertKick does
Section titled “What AlertKick does”| Area | What you get | Start here |
|---|---|---|
| Server monitoring | CPU, memory, disk, network, processes, Docker containers, with default thresholds and custom check profiles | Server monitoring |
| Uptime monitoring | HTTP/HTTPS, TCP, DNS, SSL certificate, and domain-expiry monitors checked from several regions | Monitor types |
| Heartbeats | Dead-man’s-switch monitoring for cron jobs, backups, and scheduled work | Heartbeats |
| Alerting and on-call | Escalation policies, rosters, rotations, overrides and swaps, Follow the Sun schedules, quiet hours, maintenance windows | Escalation policies |
| Notifications | Slack, Telegram, WhatsApp, SMS, email, mobile push, webhooks | Notification channels |
| Inbound alerts | Prometheus, Grafana, Datadog, Nagios, Zabbix, Sentry, CI pipelines, generic webhook, email, and more | Inbound alert sources |
| eBPF security | Kernel-level detection of SSH logins, reverse shells, crypto miners, rootkits, new listeners, and file changes, mapped to MITRE ATT&CK | Security events |
| SSH and change control | Session and command tracking, trusted-IP rules, auto-block, SSH lockdown outside maintenance windows, change records with approve/verify/complete | Change tracking |
| Compliance | Continuous PCI DSS and SOX evidence with audit-ready PDF reports | Evidence and reports |
| AI | AI verdicts on security events, Kicker incidents and after-action reports, Claude and MCP access to your account | AI triage |
How it fits together
Section titled “How it fits together”- Agents run on your servers (Linux, Windows, Docker hosts). They ship metrics and security events over an authenticated WebSocket to the regional endpoint nearest them, and receive configuration pushes the same way. Install the agent.
- Pollers are AlertKick-managed probes that run uptime monitors from several regions. If you need checks against private networks, run an on-premise poller.
- Alerts are raised from thresholds, failed checks, missed heartbeats, security rules, or inbound integrations. Every alert is bound to an escalation policy that decides who is notified, through which channel, and how long to wait before escalating.
- Rosters decide who is on call at any moment. Policies can page a roster instead of a named person, so the schedule, not the policy, changes when people rotate. Roster management.
- The consolidated view shows alerts, security events, monitor state, and server health across every region in one place. The consolidated view.
Where to go next
Section titled “Where to go next”- New account: Quick start and Account setup.
- Already monitoring: Working with alerts covers acknowledging, resolving, and reading the escalation timeline.
- Security teams: What is eBPF, then Customizing detection rules.
- Automation: the API reference and the Claude and MCP connector.
- On the move: the mobile app for push notifications and acknowledging alerts from your phone.