Authoring Error Tracking Alerts

作者 PostHog469d1773e9cb無授權條款收錄於 2026年10月8日更新於 2026年10月8日

Author error tracking alerts that fire when an issue is created, reopened, or starts spiking. Use when the user asks to set up error notifications, route exceptions to Slack/webhook/Linear, or evaluate which error events are worth alerting on. Covers trigger-event selection, integration choice, dedup against existing alerts, and shipping with the canonical message body shape.

僅含說明DevOps & Cloud
AI 產生的概覽

撰寫 PostHog 錯誤追蹤警示,在問題建立、重新開啟或暴增時觸發,並導向 Slack、Webhook 或 Linear。

功能
引導代理建立 PostHog 錯誤追蹤警示:從三種生命週期觸發事件中挑選一種、與現有警示去重、選擇整合與目標頻道,並以標準訊息內容建立警示。內容也涵蓋依問題範圍的屬性篩選、命名慣例,以及驗證與回報格式。產出的是已設定的警示,而非分析結果或檔案。
適用情境
適用於使用者要求設定錯誤或例外通知、在啟用錯誤追蹤後需要一組初始警示,或貼上問題連結並要求再次發生時通知的情況。不適用於調整暴增偵測器、調查正在發生的故障,或設定以數量為門檻的日誌警示。
執行需求
需要存取 PostHog 的錯誤追蹤警示、整合與頻道相關 MCP 工具,以及已連接的目標整合,例如 Slack、Webhook URL 或 Linear/GitHub/GitLab。僅為指示文件,未附帶指令碼。

Authoring error tracking alerts

Authoring an error tracking alert is a routing problem, not a measurement problem. The trigger events already exist and fire on real conditions in the ingestion pipeline — your job is to pick the right trigger for the user's intent, dedupe against what's already configured, and wire a destination they can actually act on.

When to use this skill

  • The user asks to set up alerts / notifications for errors or exceptions in their project.
  • The user wants a starter set of alerts after enabling error tracking.
  • The user pastes an issue link and asks "notify me when this happens again" — usually _reopened with a per-issue property filter.

When not to use this skill

  • Tuning the spike detector itself (multiplier, window, threshold). That lives behind the spike detection config endpoint and is not exposed via MCP today.
  • Investigating an active incident — query the issue / its events directly via posthog:query-error-tracking-issue and posthog:query-error-tracking-issue-events instead of authoring more alerts mid-fire.
  • Configuring volume-threshold alerts (count of $exception events over a window). That's a logs-style alert and is not in scope here — error tracking alerts ride the lifecycle events instead.

Tools

ToolJobWhere it fits
posthog:error-tracking-alerts-listList existing alerts; dedupe before creating.Step 2 — dedupe.
posthog:integrations-listFind the user's Slack workspace id (filter by kind=slack).Step 3 — pick channel.
posthog:integrations-channels-retrieveList Slack channels for a workspace.Step 3 — pick channel.
posthog:error-tracking-alerts-createCreate the alert (HogFunction with type=internal_destination).Step 4 — ship.
posthog:error-tracking-alerts-partial-updateToggle, rename, or modify an existing alert.When tuning, not authoring.
posthog:error-tracking-alerts-deleteSoft-delete an alert.When the user says "remove".

Trigger events — pick exactly one per alert

There are three lifecycle events. Each has a different "noise vs urgency" trade-off — picking the wrong one is the most common cause of alert fatigue here.

EventFires whenUse when
$error_tracking_issue_createdA brand-new issue first appears.Small projects, or projects where every new error type is genuinely worth a look. Floods large/noisy projects.
$error_tracking_issue_reopenedA previously resolved issue starts emitting again.Catch regressions on issues someone already triaged. The safest "I want to know if this comes back" trigger.
$error_tracking_issue_spikingThe spike detector flags abnormal volume on an issue.Production projects with high baseline volume. Threshold/multiplier is shared across the project — check spike config before using.

If the user is vague ("alert me on errors"), default to _spiking. It's the most signal-dense trigger and the least likely to cause alert fatigue. Confirm explicitly before proceeding.

Workflow

1. Confirm intent

You need three things from the user before creating anything:

  • Which trigger event. If unspecified, recommend _spiking and ask for confirmation. Do not silently pick one.
  • Which channel. Slack channel name, webhook URL, Linear team, etc. Never hardcode a production channel. If the user says "the dev channel", ask for the exact channel id or name.
  • Which scope. All issues (most common), or scoped to a specific issue / exception type / assignee.

2. Dedupe against existing alerts

Call posthog:error-tracking-alerts-list. Filter the response client-side by filters.events[].id.

  • If an alert exists for the same event delivering to the same channel, stop. Tell the user it already exists and ask whether they want to change anything (in which case use error-tracking-alerts-partial-update) or skip.
  • Multiple alerts on the same event for the same channel produce duplicate Slack messages — the user almost never wants this.
  • Multiple alerts on the same event for different channels (e.g. one for #oncall, one for the oncall webhook) is fine and sometimes intentional. Confirm.

PostHog's "alerts configured" recommendation only inspects filters.events — adding per-issue filters.properties does not affect the status the recommendations card reports.

3. Pick the integration

For Slack:

  1. posthog:integrations-list with kind=slack → pick the integration id (an integer).
  2. posthog:integrations-channels-retrieve with that id → pick the channel id (e.g. C0123ABC). Channel names like "#oncall" are accepted but channel ids are preferred — they survive renames.

For webhook: the user supplies a single https:// URL. Refuse http:// URLs.

For Linear / GitHub / GitLab: confirm the integration is connected via posthog:integrations-list first, then ask the user which project / repository / team to file issues into.

4. Create the alert

Call posthog:error-tracking-alerts-create with:

json
{  "type": "internal_destination",  "template_id": "template-slack",  "name": "<short, channel-attributed name>",  "enabled": true,  "filters": {    "events": [{ "id": "$error_tracking_issue_created", "type": "events" }]  },  "inputs": {    "slack_workspace": { "value": <slack_integration_id_int> },    "channel": { "value": "<channel_id>" },    "text": { "value": "..." },    "blocks": { "value": [...] }  }}

The canonical Slack blocks payload for each event lives in references/block-templates.md. Copy the matching block verbatim — it matches the in-product alert wizard, so agent-created alerts look identical to UI-created ones.

For per-issue scoping — created / reopened only, spiking events carry no exception properties — add to filters:

json
"properties": [  { "key": "$exception_issue_id", "value": "<issue_uuid>", "operator": "exact", "type": "event" }]

Other useful property filters: $exception_types (exception class names, an array), name (issue title). See references/event-triggers.md for the full property surface per event.

5. Verify

Echo the alert back to the user with: name, trigger event (human-readable), destination, and a one-line preview of the message body. Do not echo Slack workspace ids or webhook URLs — those are sensitive. Tell the user how to disable: "you can pause this alert by setting enabled: false via error-tracking-alerts-partial-update or by toggling it in the destinations UI."

Naming convention

Use <trigger> · <channel> (auto) so the user can scan their alert list and spot agent-created entries. Examples:

  • Issue spiking · #oncall (auto)
  • Issue reopened · #regressions-webhook (auto)
  • Issue created · Linear/Eng (auto)

Do not use the issue title in the name — alerts can match many issues, and the title becomes stale once the issue evolves.

Token-economy rules

  • One posthog:error-tracking-alerts-list call up front, not per candidate.
  • Reuse a single integration lookup for multiple alerts going to the same workspace.
  • Confirm the channel / URL with the user before creating each alert. Never batch-create alerts to a destination the user has not explicitly named.
  • Cap iteration at 1 round per alert. If the user wants three alerts, that's three create calls — not three create calls per alert.

Output

Report what you did, in this shape:

  • For each shipped alert: name, trigger event, destination (channel name or webhook host — never the full URL), enabled state.
  • For each skipped alert: trigger + channel + why (already exists, user declined, missing integration).
  • Anything the user should do next: enable the spike detection config (if they picked _spiking and the detector hasn't been turned on), wire up source maps (so the alert's stack trace links resolve), or tune the alert filters after watching it for a day.

Related skills

  • triaging-error-issues — work out which issues actually matter before wiring alerts for them
  • investigating-error-issue — deep-dive an issue an alert fired for
  • authoring-log-alerts — the same alerting job, but for log lines instead of exceptions

來源與署名

來源:PostHog/ai-plugin位於skills/authoring-error-tracking-alerts提交469d177

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架

更多來自 PostHog/ai-plugin 的技能

Writing Simplified Technical English

PostHog

套用 ASD-STE100 簡化技術英語規則,讓代理撰寫的文字語意明確、方便執行。

Writing & Content2026年10月8日

Working With Task Comments

PostHog

透過 PostHog MCP exec 調度器讀取並解讀 PostHog 任務、成品和畫布上的留言。

Productivity & Workflow2026年10月8日

Working With Skills

PostHog

指導代理使用 PostHog 的 skill-* MCP 工具來探索、讀取、建立、更新與重構技能。

AI & Agents2026年10月8日

Working With Scouts

PostHog

說明如何把監看工作委派給 PostHog Signals 偵察代理、處理其回報,並長期調校整個代理團隊的操作手冊。

AI & Agents2026年10月8日

Validating And Publishing Canvases

PostHog

Validate and publish a canvas source project safely: the source-project shape, declared capabilities, reading the current version pointer, iterating on validation diagnostics, guarded publishing with expected_current_version_id, staging a draft build and promoting it, waiting out the queued build, and recovering from a 409 version_conflict or a 429 capacity limit without overwriting concurrent work. Use whenever a canvas edit is ready to save, a draft build is wanted, a canvas publish or build returns diagnostics or a conflict, or a task needs to understand canvas version history.

待分類2026年10月8日

Understanding Billing Usage

PostHog

Explains PostHog billing usage and spend from the customer's visible Billing MCP tools. Use when the user asks why usage or spend is high, which product or project is driving usage, what a usage type means, how to reduce usage, what changed over time, why they got a usage change alert, or whether a spike/drop alert was real or noisy. Also use before product-specific analytics skills when the user names a billable PostHog product metric such as events, recordings, feature flag requests, exceptions, survey responses, synced rows, logs, AI events, AI credits, or Inbox credits. Starts from Billing usage/spend tools, then routes to customer-visible product MCP surfaces for deeper investigation.

待分類2026年10月8日