The Seabhac data source plugin puts your monitors, fleet analytics and DMARC data into Grafana, next to your own infrastructure metrics. You can build dashboards from it, use failed checks as annotations on any graph, and write Grafana alert rules against it.
It reads from the Seabhac API with an organization API key, so queries count towards your monthly API quota. See Quota usage for how the plugin keeps that low.
Requirements
- Grafana 12.3 or newer (self-hosted or Grafana Cloud).
- A Seabhac API key. See Creating an API Key.
Setup
- Install the plugin and restart Grafana. Until it is published to the Grafana catalog, copy the release archive into your plugins directory and allow it with
allow_loading_unsigned_plugins = seabhac-monitoring-datasourceunder[plugins]ingrafana.ini. - In Grafana, go to Connections → Data sources → Add new data source and pick Seabhac.
- Paste your API key. Leave API URL empty unless you’ve been given a different endpoint.
- Click Save & test. A successful test also shows how much of this month’s API quota is left.
You can also provision the data source from a file:
apiVersion: 1
datasources:
- name: Seabhac
uid: seabhac
type: seabhac-monitoring-datasource
secureJsonData:
apiKey: $SEABHAC_API_KEY
Queries
| Query | Returns | Good for |
|---|---|---|
| Monitor: metrics | Latency, uptime and check-specific fields for one monitor, bucketed over time | Time series panels |
| Monitor: up/down | up (1 = healthy run, 0 = failed) and duration_ms, one series per region | State timelines, alerting |
| Monitor: failed runs | Each failed run with its error message | Annotations |
| Fleet: trend | Uptime %, job counts and average duration across all monitors (optionally one check type) | Overview dashboards |
| Fleet: status distribution | Job count per status | Pie charts |
| Fleet: failure reasons / top failing monitors | Most common errors / least healthy monitors | Tables |
| DMARC: volume & pass rate | Daily message and pass counts, one series per domain | Bar charts |
| DMARC: fail reasons | Counts of both-pass, DKIM-only failures, SPF-only failures and so on | Pie charts |
| DMARC: top source IPs / failing IPs / senders / ASNs / countries / reporters | Ranked tables | Tables, geomap |
Fields (on time series queries) keeps only the value fields you list, e.g. up or avg_latency_ms,max_latency_ms.
Monitor: up/down and failed runs read a monitor’s most recent 500 runs. On a monitor that runs every minute, that covers about the last 8 hours. For longer ranges, use Monitor: metrics, which is pre-aggregated.
Template variables
Create a variable of type Query, pick the Seabhac data source, and choose Monitors (optionally filtered by check type), Regions, DMARC domains or Check types. Use it in queries as $monitor, $dmarc_domain and so on.
Annotations
In Dashboard settings → Annotations, add a Seabhac annotation with the Monitor: failed runs query. Every failed check then shows up as a marker on every graph in the dashboard, tagged with its check type and region.
Alerting
The plugin runs queries on the Grafana server, so Grafana alerting works with it. For example, to alert when a monitor is down:
- Query A: Monitor: up/down, your monitor, Fields =
up. - Expression B: Reduce A with Last, mode Drop non-numeric values. You get one value per region.
- Expression C: Threshold B is below
1. - Set the pending period to e.g. 5m to ride out single blips.
Each region gets its own alert instance (labelled region=...). For “down in at least two regions”, add a Math expression such as $C summed across series, or route on the region label.
Alert rules use quota too. A rule evaluated every minute makes about 43,000 queries a month. The plugin’s cache and batching share results between rules and dashboards, but set the evaluation interval to what you actually need.
Quota usage
Grafana re-runs every panel’s query on every refresh, which would use up an API allowance quickly. The plugin reduces this in several ways:
- Batching: all queries in a refresh go out as one
POST /v1/batchcall, which counts as one request. - Caching: results are reused for 30–60 seconds (10 minutes for monitor and region lists). Panels and alert rules asking for the same data share a single fetch.
- Aligned time ranges: ranges are snapped to whole minutes, so refreshes within the same minute are cache hits.
As a rough guide, one dashboard refreshing every 5 minutes uses about 9,000 requests a month, however many panels it has. If you use up the quota, panels show Seabhac API quota exhausted until the next month or a plan upgrade.