RMM Labs
Integrations 4 min read 28 September 2026 By Fred

Connect Xcellerate AIG to your monitoring stack and SIEM: Prometheus, Grafana, OpenTelemetry, webhooks and alerts

Put your AI traffic next to the rest of your systems: Prometheus metrics, OTLP traces, JSON logs, signed webhooks and alerts by e-mail or Slack.

Xcellerate AIG puts your AI traffic into the monitoring tools you already run: Prometheus and Grafana for metrics, any OpenTelemetry trace store for per-request traces, JSON container logs for your log shipper, and signed webhooks for your SIEM, SOAR or ITSM. Alerting tells the right people by e-mail, Slack or webhook when a budget runs out, a provider key stops working or a guardrail blocks a prompt.

TL;DR

  • Prometheus scrapes /metrics, traces go out over OTLP/HTTP and logs are JSON on stderr.
  • Signed webhooks (HMAC-SHA256) feed your SIEM, SOAR or ITSM. There is no dedicated SIEM connector.
  • Alerts go out by e-mail, Slack or webhook.

Before you start

  • You have the Admin role in AIG. Metrics & tracing, Webhooks and Alerting are admin screens.
  • Prometheus can reach https://<your-gateway>/metrics on your internal network. The endpoint is not routed on the public entry point.
  • For traces: an OTLP/HTTP endpoint (Tempo, Jaeger, OpenTelemetry Collector or a hosted APM), usually ending in /v1/traces, plus any ingest header or token.
  • For webhooks: an HTTPS receiver (internal is fine) that verifies HMAC signatures. For Slack: an incoming webhook URL. For e-mail alerts: outbound mail set up in General settings.

Connect your monitoring stack

1. Metrics for Prometheus and Grafana

Open All screens → General settings → Metrics & tracing and enable metrics. You can restrict scraping by IP address or CIDR range, by basic auth, or both. Add a Prometheus scrape job for /metrics. Import the Grafana dashboard that ships with the deployment files and paste its address in Dashboard URL.

2. Traces over OpenTelemetry

On the same page, switch on Export traces. Paste the OTLP/HTTP endpoint and, if needed, an ingest token under Extra request headers. Set Service name and Sample (%). Fill in Trace link template with {trace_id} so the log drawer links straight to the trace.

3. Webhooks for your SIEM, SOAR or ITSM

Go to All screens → Webhooks and click Add endpoint. Enter a name and URL and tick the events you need; nothing is subscribed by default. Copy the signing secret (shown once), press Test and follow Recent deliveries.

4. Alerts by e-mail, Slack or webhook

Go to All screens → Alerting and click Add a channel: an e-mail list, a Slack incoming webhook or a URL. Press Send a test. Then switch on one of the five seeded rules (all off by default) or add your own: event, optional condition, throttle in minutes and channels.

5. Health checks for self-hosted AIG

Point your load balancer or uptime monitor at /up (liveness) and /up/ready (readiness).

What happens after you connect

  • Metrics: request and error rates, latency and first-token histograms, tokens, spend, retries, key rotations and key health, in-flight requests, queue depth, cache hit rate, circuit state, guardrail evaluations and tool calls. Label cardinality is capped.
  • Traces: one span per request (model, provider, tokens, cost, key, team), with child spans per upstream attempt, tool call and guardrail verdict. An incoming traceparent is continued.
  • Logs: one JSON line on stderr with node and request ID. X-Request-Id ties the caller, your logs and the AIG request log together.
  • Webhooks: a JSON POST with X-XC-Event, X-XC-Delivery, X-XC-Timestamp and X-XC-Signature: sha256=…, an HMAC-SHA256 of <timestamp>.<body>. Failed deliveries are retried on a growing schedule, then marked Given up; you can then retry them yourself.
  • Live charts appear under Traffic → Observability.

Good to know

  • There is no dedicated Splunk, Microsoft Sentinel or Elastic connector. Your SIEM takes in AIG through these standard outputs.
  • Alert channels are e-mail, Slack and webhook; there is no Microsoft Teams channel.
  • If the trace store is down, AIG drops those batches and raises an event you can alert on. Requests are never slowed down.
  • Rotating a webhook secret has no grace period, so update the receiver first. Loopback and cloud-metadata addresses are always refused as webhook targets.
  • A rule with an unparsable condition never fires. Throttle 0 means every occurrence.

Troubleshooting

  • /metrics returns 404 "metrics are disabled" (turn metrics on), 403 "forbidden" (IP not allowed) or 401 "unauthorised" (check basic auth).
  • Observability shows "Nothing sampled yet…": check that the scheduler container is running and that metrics are enabled.
  • A rule shows "No channels — nobody would be told": add at least one channel.
  • A webhook stays in Retrying or Given up: check the receiver, then use Retry.

Read more about observability, the audit log and request logs.

Want to see AIG in your own Grafana and SIEM? Talk to us about AIG.

Frequently asked questions

Is there a Splunk, Sentinel or Elastic connector?
No. Your SIEM takes in AIG through the standard outputs: signed webhooks, JSON logs, OTLP traces or Prometheus metrics.
Can AIG send alerts to Microsoft Teams?
No. Alert channels are e-mail, a Slack incoming webhook or your own webhook URL.
Which health endpoints does self-hosted AIG expose?
/up for liveness and /up/ready for readiness.
Sources: Verified against the Xcellerate AIG source code by the product team on 2026-09-28. Feature pages: https://rmmlabs.io/en/contact; https://rmmlabs.io/en/products/aig/features/audit-log; https://rmmlabs.io/en/products/aig/features/observability; https://rmmlabs.io/en/products/aig/features/request-logs.

Ready to solve time registration compliance?

Xcellerate OPS covers Belgian 2027 time registration requirements out of the box — no extra module needed.

Related articles