Overview

The PagerDuty integration polls the PagerDuty Audit Records API and the Incidents API to ingest:

  • Incident creation, acknowledgement, escalation, and resolution
  • Service, escalation policy, and integration changes
  • User, team, and on-call schedule modifications
  • API key and OAuth grant activity

Prerequisites

  • A PagerDuty account on a plan that includes the audit records API (Business or higher).
  • An account-level Admin or Account Owner role to create global API keys.

Step 1: Create an API key in PagerDuty

  1. Sign in to PagerDuty as an Admin.
  2. Go to Integrations → API Access Keys.
  3. Click Create New API Key.
  4. Name it atatus-siem and select Read-only API Key.
  5. Click Create Key and copy the value immediately.

Step 2: Connect PagerDuty in Atatus

  1. In Atatus, go to Security → Cloud SIEM → Integrations.
  2. Locate the PagerDuty card and click Connect.
  3. Fill in the form:
Field Description Example
API Key The read-only key from Step 1. u+xxxxxxxxxxxxxxxxxxxx
Poll Interval (minutes) How often to fetch new events. 5
Enabled Turn collection on. true
  1. Click Connect.

Verification

  • The PagerDuty card shows Configured.
  • Audit and incident events appear in Security → Cloud SIEM → Audit Logs → Events with source pagerduty.