{"product_id":"enrich-openobserve-alerts-with-log-context-notify-via-novu","title":"Enrich OpenObserve Alerts with Log Context \u0026 Notify via Novu","description":"\u003ch3\u003eEnrich OpenObserve Alerts with Log Context and send smarter notifications via Novu\u003c\/h3\u003e\n\u003cp\u003eThis n8n workflow listens for selected \u003cstrong\u003eOpenObserve\u003c\/strong\u003e alerts, automatically pulls nearby log evidence for context, redacts sensitive fields, suppresses duplicate notifications during a cooldown, and then delivers an enriched incident payload to \u003cstrong\u003eNovu\u003c\/strong\u003e responders (or outputs a preview).\u003c\/p\u003e\n\n\u003ch3\u003eWhat this workflow does\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eTriggers on OpenObserve alerts\u003c\/strong\u003e and receives the alert payload through the OpenObserve trigger.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eNormalizes and validates\u003c\/strong\u003e key fields such as alert ID\/name, service, severity, and timestamp, then derives a stable incident key.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eQueries surrounding logs\u003c\/strong\u003e using a bounded OpenObserve SQL query for the configured log stream and service field, searching around the alert time window.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eSelects the closest log record\u003c\/strong\u003e and, when found, uses OpenObserve “Search Around” to retrieve additional surrounding context.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eBuilds an incident brief\u003c\/strong\u003e by limiting evidence size and redacting common secret-like fields, then prepares a \u003cstrong\u003eNovu\u003c\/strong\u003e payload and an idempotent notification key.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eSuppresses duplicates with cooldown\u003c\/strong\u003e by checking an n8n \u003cstrong\u003eData Table\u003c\/strong\u003e for prior notification state; alerts are suppressed unless severity increases.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eNotifies via Novu\u003c\/strong\u003e (or returns a preview payload in preview mode) and then \u003cstrong\u003eupserts cooldown state\u003c\/strong\u003e back to the n8n Data Table.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eUse cases\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003eWhen OpenObserve fires an alert, give responders immediate \u003cstrong\u003elog-backed context\u003c\/strong\u003e without manually searching dashboards.\u003c\/li\u003e\n  \u003cli\u003eReduce alert fatigue by preventing repeated notifications during an incident cooldown period.\u003c\/li\u003e\n  \u003cli\u003ePrepare a clean, responder-ready incident payload by \u003cstrong\u003eredacting sensitive fields\u003c\/strong\u003e before sending to notifications.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eTechnical details\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eIntegrations:\u003c\/strong\u003e OpenObserve (alerts + log search) and Novu (incident\/notification delivery).\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003en8n nodes\/logic:\u003c\/strong\u003e \u003ccode\u003eif\u003c\/code\u003e, \u003ccode\u003eset\u003c\/code\u003e, \u003ccode\u003ecode\u003c\/code\u003e, \u003ccode\u003edata table\u003c\/code\u003e, and the \u003cstrong\u003eblackswampain8n-nodes-novunovu\u003c\/strong\u003e Novu node.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eState management:\u003c\/strong\u003e stores notification state and cooldown timestamps in an n8n Data Table for idempotent behavior.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"N8N Commerce","offers":[{"title":"Default Title","offer_id":45978926776499,"sku":"N8N-19330","price":60.99,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0749\/6279\/6723\/files\/kyZkfN5HrpHpuYQZOwZUf_NJLURwSu.png?v=1788859413","url":"https:\/\/buyflowscripts.com\/products\/enrich-openobserve-alerts-with-log-context-notify-via-novu","provider":"N8N Commerce","version":"1.0","type":"link"}