Skip to main content
Glama
orchestra-hq

Orchestra MCP Server

Official
by orchestra-hq

Create a monitor

create_monitor

Creates a monitor that groups failures into one incident and controls alerting, with options to match events, set grouping, and mute alerts.

Instructions

Create a monitor: a rule for which failures to group into one incident, and how that incident alerts. match picks the events it claims, groupBy what makes two of them one incident, and action what happens to it - including mute, which claims the events and raises no incident or alert at all. Left out, order puts the new monitor last, so it only claims events no existing monitor claims.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
nameYes
matchYesWhich events a monitor claims: AND across dimensions, OR within a list. At least one dimension has to be given. A monitor matching every dimension by saying nothing would claim every event on the account, which is never what an author means.
orderNo
actionNoWhat happens to the events this monitor claimed. ``mute`` claims them and sends no alert - the known-broken-thing case. They are still recorded, on incidents the monitor owns, so a mute is silent without being invisible.
enabledNo
groupByYes
triggerNo
descriptionNo
X-Orchestra-Account-IdNoAct on this account rather than the one the credential resolves to. Omit it to use the credential's own account. An API key is issued to a single account, so it may only name that account; an OAuth token may name any account its grant covers.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed5 schema fields changedv0.1.2
    • addedInput schema / properties / groupBy / items / anyOf
      Added value: +[
      +  {
      +    "description": "What makes two events this monitor claimed one incident.\n\nEvery value but ``MONITOR`` resolves to a typed column that already exists on\n``incident_events``. ``MONITOR`` means \"everything this monitor claims is one\nincident\", which is served by ``monitor_id`` on the incident instead.",
      +    "enum": [
      +      "asset",
      +      "task",
      +      "pipeline",
      +      "connection",
      +      "monitor"
      +    ],
      +    "type": "string"
      +  },
      +  {
      +    "pattern": "^\\$",
      +    "type": "string"
      +  }
      +]
    • removedInput schema / properties / groupBy / items / description
      Removed value: -"What makes two events this monitor claimed one incident.\n\nEvery value but ``MONITOR`` resolves to a typed column that already exists on\n``incident_events``. ``MONITOR`` means \"everything this monitor claims is one\nincident\", which is served by ``monitor_id`` on the incident instead."
    • removedInput schema / properties / groupBy / items / enum
      Removed value: -[
      -  "asset",
      -  "task",
      -  "pipeline",
      -  "connection",
      -  "monitor"
      -]
    • removedInput schema / properties / groupBy / items / type
      Removed value: -"string"
    • addedInput schema / properties / groupBy / maxItems
      Added value: +32
  2. Changed6 schema fields changedv0.1.1
    • changedInput schema / properties / match / properties / integrations / items / enum
      Previous value: -[
      -  "AIRBYTE_CLOUD",
      -  "AIRBYTE_SERVER",
      -  "AIRFLOW",
      -  "ARCH",
      -  "ALTERYX_SERVER",
      -  "ANTHROPIC",
      -  "AWS_EC2",
      -  "AWS_ECS",
      -  "AWS_EMR",
      -  "AWS_EKS",
      -  "AWS_FIREHOSE",
      -  "AWS_GLUE",
      -  "AWS_LAMBDA",
      -  "AWS_RDS",
      -  "AWS_REDSHIFT",
      -  "AWS_S3",
      -  "AWS_BEDROCK",
      -  "AWS_SAGEMAKER",
      -  "AWS_SECRETS_MANAGER",
      -  "AWS_SES",
      -  "AWS_STEP_FUNCTIONS",
      -  "AZURE",
      -  "AZURE_CONTAINER_APPS",
      -  "AZURE_DATA_FACTORY",
      -  "AZURE_DATA_LAKE_STORAGE",
      -  "AZURE_KEY_VAULT",
      -  "AZURE_KUBERNETES_SERVICE",
      -  "AZURE_LOGIC_APPS",
      -  "AZURE_SYNAPSE_ANALYTICS",
      -  "AZURE_VM",
      -  "BAUPLAN",
      -  "BOOMI",
      -  "CDATA",
      -  "CENSUS",
      -  "CLICKHOUSE",
      -  "COALESCE",
      -  "COUNT",
      -  "DATADOG",
      -  "DATABRICKS",
      -  "DATAPROC",
      -  "DATAZEN",
      -  "DBT",
      -  "DBT_CORE",
      -  "DLT",
      -  "DOMO",
      -  "DREMIO",
      -  "DUCKDB",
      -  "EMAIL",
      -  "ESTUARY",
      -  "ETLEAP",
      -  "FABRIC",
      -  "FABRIC_SYNAPSE",
      -  "FIVETRAN",
      -  "FORTRA",
      -  "GCP_BIG_QUERY",
      -  "GCP_CLOUD_RUN",
      -  "GCP_CLOUD_FUNCTIONS",
      -  "GCP_CLOUD_STORAGE",
      -  "GCP_DATAFLOW",
      -  "GCP_DATAFORM",
      -  "GCP_DATASTREAM",
      -  "GCP_LOOKER",
      -  "GKE",
      -  "GITHUB_ACTIONS",
      -  "GOOGLE_CLOUD",
      -  "HEVO",
      -  "HEX",
      -  "HIGHTOUCH",
      -  "HTTP",
      -  "HUBSPOT",
      -  "INFORMATICA_IICS",
      -  "INFORMATICA_POWERCENTER",
      -  "KAFKA",
      -  "KEBOOLA",
      -  "KLEENE",
      -  "LIGHTDASH",
      -  "LINUX_SSH",
      -  "MATILLION",
      -  "MATILLION_ETL",
      -  "METAPLANE",
      -  "MICROSOFT_TEAMS",
      -  "MICROSTRATEGY",
      -  "MONGODB",
      -  "MOTHERDUCK",
      -  "MYSQL",
      -  "N8N",
      -  "NIMBLE",
      -  "NOTION",
      -  "OMNI",
      -  "OPEN_AI",
      -  "ORCHESTRA",
      -  "PARADIME",
      -  "PAGER_DUTY",
      -  "PINECONE",
      -  "PORTABLE",
      -  "POSTGRES",
      -  "POWER_AUTOMATE",
      -  "POWER_BI",
      -  "PREFECT_CLOUD",
      -  "PYTHON",
      -  "QLIK",
      -  "QLIK_REPLICATE",
      -  "QUICKBOOKS",
      -  "RENDER",
      -  "RIVERY",
      -  "RUDDERSTACK",
      -  "SALESFORCE",
      -  "SAP",
      -  "SFTP",
      -  "SHAREPOINT",
      -  "SIGMA",
      -  "SISENSE",
      -  "SLACK",
      -  "SNOWFLAKE",
      -  "SNOWPLOW",
      -  "SODA",
      -  "SQL_MESH",
      -  "SQL_SERVER",
      -  "STITCH",
      -  "STREAMKAP",
      -  "TABLEAU_CLOUD",
      -  "TALEND_CLOUD",
      -  "THOUGHTSPOT",
      -  "TOBIKO_CLOUD",
      -  "WEAVIATE",
      -  "WEBHOOK",
      -  "WELD",
      -  "WINDOWS_SSH"
      -]New value: +[
      +  "AIRBYTE_CLOUD",
      +  "AIRBYTE_SERVER",
      +  "AIRFLOW",
      +  "ARCH",
      +  "ALTERYX_SERVER",
      +  "ANTHROPIC",
      +  "AWS_EC2",
      +  "AWS_ECS",
      +  "AWS_EMR",
      +  "AWS_EKS",
      +  "AWS_FIREHOSE",
      +  "AWS_GLUE",
      +  "AWS_LAMBDA",
      +  "AWS_RDS",
      +  "AWS_REDSHIFT",
      +  "AWS_S3",
      +  "AWS_BEDROCK",
      +  "AWS_SAGEMAKER",
      +  "AWS_SECRETS_MANAGER",
      +  "AWS_SES",
      +  "AWS_STEP_FUNCTIONS",
      +  "AZURE",
      +  "AZURE_CONTAINER_APPS",
      +  "AZURE_DATA_FACTORY",
      +  "AZURE_DATA_LAKE_STORAGE",
      +  "AZURE_KEY_VAULT",
      +  "AZURE_KUBERNETES_SERVICE",
      +  "AZURE_LOGIC_APPS",
      +  "AZURE_SYNAPSE_ANALYTICS",
      +  "AZURE_VM",
      +  "BAUPLAN",
      +  "BOOMI",
      +  "CDATA",
      +  "CENSUS",
      +  "CLICKHOUSE",
      +  "COALESCE",
      +  "COUNT",
      +  "DATADOG",
      +  "DATABRICKS",
      +  "DATAPROC",
      +  "DATAZEN",
      +  "DBT",
      +  "DBT_CORE",
      +  "DLT",
      +  "DOMO",
      +  "DREMIO",
      +  "DUCKDB",
      +  "EMAIL",
      +  "ESTUARY",
      +  "ETLEAP",
      +  "FABRIC",
      +  "FABRIC_SYNAPSE",
      +  "FIVETRAN",
      +  "FORTRA",
      +  "GCP_BIG_QUERY",
      +  "GCP_CLOUD_RUN",
      +  "GCP_CLOUD_FUNCTIONS",
      +  "GCP_CLOUD_STORAGE",
      +  "GCP_DATAFLOW",
      +  "GCP_DATAFORM",
      +  "GCP_DATASTREAM",
      +  "GCP_LOOKER",
      +  "GKE",
      +  "GITHUB_ACTIONS",
      +  "GOOGLE_CLOUD",
      +  "HEVO",
      +  "HEX",
      +  "HIGHTOUCH",
      +  "HTTP",
      +  "HUBSPOT",
      +  "INFORMATICA_IICS",
      +  "INFORMATICA_POWERCENTER",
      +  "KAFKA",
      +  "KEBOOLA",
      +  "KLEENE",
      +  "LIGHTDASH",
      +  "LINUX_SSH",
      +  "MARIADB",
      +  "MATILLION",
      +  "MATILLION_ETL",
      +  "METAPLANE",
      +  "MICROSOFT_TEAMS",
      +  "MICROSTRATEGY",
      +  "MONGODB",
      +  "MOTHERDUCK",
      +  "MYSQL",
      +  "N8N",
      +  "NIMBLE",
      +  "NOTION",
      +  "OMNI",
      +  "OPEN_AI",
      +  "ORCHESTRA",
      +  "PARADIME",
      +  "PAGER_DUTY",
      +  "PINECONE",
      +  "PORTABLE",
      +  "POSTGRES",
      +  "POWER_AUTOMATE",
      +  "POWER_BI",
      +  "PREFECT_CLOUD",
      +  "PYTHON",
      +  "QLIK",
      +  "QLIK_REPLICATE",
      +  "QUICKBOOKS",
      +  "RENDER",
      +  "RIVERY",
      +  "RUDDERSTACK",
      +  "SALESFORCE",
      +  "SAP",
      +  "SFTP",
      +  "SHAREPOINT",
      +  "SIGMA",
      +  "SISENSE",
      +  "SLACK",
      +  "SNOWFLAKE",
      +  "SNOWPLOW",
      +  "SODA",
      +  "SQL_MESH",
      +  "SQL_SERVER",
      +  "STITCH",
      +  "STREAMKAP",
      +  "TABLEAU_CLOUD",
      +  "TALEND_CLOUD",
      +  "THOUGHTSPOT",
      +  "TOBIKO_CLOUD",
      +  "WEAVIATE",
      +  "WEBHOOK",
      +  "WELD",
      +  "WINDOWS_SSH"
      +]
    • addedInput schema / properties / match / properties / labels
      Added value: +{
      +  "additionalProperties": {
      +    "items": {
      +      "additionalProperties": false,
      +      "description": "One place on an event body a label is read from, and the values that match there.",
      +      "properties": {
      +        "path": {
      +          "type": "string"
      +        },
      +        "values": {
      +          "items": {
      +            "type": "string"
      +          },
      +          "minItems": 1,
      +          "type": "array"
      +        }
      +      },
      +      "required": [
      +        "path",
      +        "values"
      +      ],
      +      "type": "object"
      +    },
      +    "minItems": 1,
      +    "type": "array"
      +  },
      +  "maxProperties": 32,
      +  "propertyNames": {
      +    "maxLength": 64,
      +    "minLength": 1,
      +    "pattern": "^[a-zA-Z0-9_.:/-]+$",
      +    "type": "string"
      +  },
      +  "type": "object"
      +}
    • addedInput schema / properties / order / anyOf
      Added value: +[
      +  {
      +    "type": "integer"
      +  },
      +  {
      +    "type": "null"
      +  }
      +]
    • removedInput schema / properties / order / default
      Removed value: -0
    • removedInput schema / properties / order / type
      Removed value: -"integer"
    • removedInput schema / properties / window
      Removed value: -{
      -  "anyOf": [
      -    {
      -      "format": "duration",
      -      "gt": "PT0S",
      -      "type": "string"
      -    },
      -    {
      -      "type": "null"
      -    }
      -  ]
      -}
  3. First observedv0.1.0

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=false and destructiveHint=false, so the safety profile is covered. The description adds real behavioral context beyond that: a left-out order places the monitor last so it only claims unclaimed events, and mute claims events without raising an incident or alert. It does not cover auth requirements (the account-id header) or duplicate-name behavior.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the definition, then three sentences that each carry distinct information (match/groupBy/action mapping, the mute exception, the order default). No filler and every clause earns its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return values need not be explained. For a 9-parameter mutation tool with nested objects, the description covers the semantically hardest concepts well. Gaps are the account-scoping/auth requirement and the less central parameters (trigger, enabled, severity).

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is only 33%, so the description carries extra burden and partially meets it: it explains match, groupBy, action, the mute flag, and the order default with real meaning ('what makes two of them one incident'). However name, enabled, trigger, severity, assignee, and description are not addressed at all in the description.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource and then defines what a monitor actually is (a rule mapping failures to incidents). The distinction from update_monitor/reorder_monitors is implied by 'Create' plus the explanation of creation-time defaults like order. An agent can tell what this tool produces without opening the schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Usage is implied through semantics rather than stated: the match description explains the 'at least one dimension' requirement and the watch-out that an empty match would claim every event. But nothing says when to reach for create_monitor versus update_monitor, reorder_monitors, or list_monitors.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.