The Seabhac data source plugin puts your monitors, fleet analytics and DMARC data into Grafana, next to your own infrastructure metrics. You can build dashboards from it, use failed checks as annotations on any graph, and write Grafana alert rules against it.

It reads from the Seabhac API with an organization API key, so queries count towards your monthly API quota. See Quota usage for how the plugin keeps that low.

Requirements

  • Grafana 12.3 or newer (self-hosted or Grafana Cloud).
  • A Seabhac API key. See Creating an API Key.

Setup

  1. Install the plugin and restart Grafana. Until it is published to the Grafana catalog, copy the release archive into your plugins directory and allow it with allow_loading_unsigned_plugins = seabhac-monitoring-datasource under [plugins] in grafana.ini.
  2. In Grafana, go to Connections → Data sources → Add new data source and pick Seabhac.
  3. Paste your API key. Leave API URL empty unless you’ve been given a different endpoint.
  4. Click Save & test. A successful test also shows how much of this month’s API quota is left.

You can also provision the data source from a file:

apiVersion: 1
datasources:
  - name: Seabhac
    uid: seabhac
    type: seabhac-monitoring-datasource
    secureJsonData:
      apiKey: $SEABHAC_API_KEY

Queries

QueryReturnsGood for
Monitor: metricsLatency, uptime and check-specific fields for one monitor, bucketed over timeTime series panels
Monitor: up/downup (1 = healthy run, 0 = failed) and duration_ms, one series per regionState timelines, alerting
Monitor: failed runsEach failed run with its error messageAnnotations
Fleet: trendUptime %, job counts and average duration across all monitors (optionally one check type)Overview dashboards
Fleet: status distributionJob count per statusPie charts
Fleet: failure reasons / top failing monitorsMost common errors / least healthy monitorsTables
DMARC: volume & pass rateDaily message and pass counts, one series per domainBar charts
DMARC: fail reasonsCounts of both-pass, DKIM-only failures, SPF-only failures and so onPie charts
DMARC: top source IPs / failing IPs / senders / ASNs / countries / reportersRanked tablesTables, geomap

Fields (on time series queries) keeps only the value fields you list, e.g. up or avg_latency_ms,max_latency_ms.

Monitor: up/down and failed runs read a monitor’s most recent 500 runs. On a monitor that runs every minute, that covers about the last 8 hours. For longer ranges, use Monitor: metrics, which is pre-aggregated.

Template variables

Create a variable of type Query, pick the Seabhac data source, and choose Monitors (optionally filtered by check type), Regions, DMARC domains or Check types. Use it in queries as $monitor, $dmarc_domain and so on.

Annotations

In Dashboard settings → Annotations, add a Seabhac annotation with the Monitor: failed runs query. Every failed check then shows up as a marker on every graph in the dashboard, tagged with its check type and region.

Alerting

The plugin runs queries on the Grafana server, so Grafana alerting works with it. For example, to alert when a monitor is down:

  1. Query A: Monitor: up/down, your monitor, Fields = up.
  2. Expression B: Reduce A with Last, mode Drop non-numeric values. You get one value per region.
  3. Expression C: Threshold B is below 1.
  4. Set the pending period to e.g. 5m to ride out single blips.

Each region gets its own alert instance (labelled region=...). For “down in at least two regions”, add a Math expression such as $C summed across series, or route on the region label.

Alert rules use quota too. A rule evaluated every minute makes about 43,000 queries a month. The plugin’s cache and batching share results between rules and dashboards, but set the evaluation interval to what you actually need.

Quota usage

Grafana re-runs every panel’s query on every refresh, which would use up an API allowance quickly. The plugin reduces this in several ways:

  • Batching: all queries in a refresh go out as one POST /v1/batch call, which counts as one request.
  • Caching: results are reused for 30–60 seconds (10 minutes for monitor and region lists). Panels and alert rules asking for the same data share a single fetch.
  • Aligned time ranges: ranges are snapped to whole minutes, so refreshes within the same minute are cache hits.

As a rough guide, one dashboard refreshing every 5 minutes uses about 9,000 requests a month, however many panels it has. If you use up the quota, panels show Seabhac API quota exhausted until the next month or a plan upgrade.