Alert notification settings
After you integrate Financial-grade Identity Verification, you can configure monitoring rules to monitor API stability or intercept abnormal system requests, such as API abuse or unauthorized account access. When a stability issue or abnormal request occurs, you can configure alerts to be sent via phone, SMS, and DingTalk. This topic describes how to configure monitoring rules and alert notifications.
Configuration procedure
Configuring alert notifications consists of two steps:
Configure monitoring rules: In this step, you configure API stability and system security monitoring rules for your service. This includes setting the rule type, threshold, action, and monitoring status.
Configure alert notifications: After you configure monitoring rules, you must configure notifications in CloudMonitor to receive alerts. Supported notification methods include phone calls, SMS, DingTalk, and email.
Prerequisites
You have integrated Financial-grade Identity Verification. For more information, see Integrate Financial-grade Identity Verification.
Step 1: Configure monitoring rules
You can configure monitoring rules for your product in the monitoring rule configuration module. Alibaba Cloud supports both stability rules and security rules. When a threshold is met, the system sends an alert.
Sign in to the Identity-verification-based E-KYC console.
In the left-side navigation pane, choose .
In the Monitoring Rule Configuration section, select a Rule Type. Then, under Rule Settings, click +Add, configure the monitoring rule, and click Save.
You can add up to 15 monitoring rules.
Rule type
Description
Stability rule
Monitors the
InitFaceVerifyinitialization API of Financial-grade Identity Verification. For server-only integration mode, this is your business API.The following stability rule dimensions are supported:
Request volume increase over the last hour is greater than
Request volume increase over the last hour is less than
Average response time in the last 5 minutes is greater than
API request parameter error rate in the last hour is greater than
API request success rate in the last 5 minutes is less than
Security rule
Configure security rules.
The following security rule dimensions are supported:
Number of occurrences of the same ID number is greater than
Ratio of authentication failures with subcode 205 is greater than
Ratio of authentication failures with subcode 206 is greater than
Authentication success rate is less than
NoteSecurity monitoring rules vary by solution. For supported rules, see the page.
NoteTo prevent frequent notifications for low call volumes, rules are activated only after the following minimum call thresholds are met:
Low request success rate in the last 5 minutes: More than 20 calls.
High average response time in the last 5 minutes: More than 20 successful calls.
A significant increase in request volume compared to the previous hour: More than 100 calls in both the current and previous windows.
A significant decrease in request volume compared to the previous hour: More than 100 calls in both the current and previous windows.
High request parameter error rate in the last hour: More than 100 calls.
Low authentication success rate: More than 100 calls.
A high percentage of failed authentications due to liveness attack 205: More than 100 calls.
A high percentage of failed authentications due to liveness attack 206: More than 100 calls.
Step 2: Configure alert notifications
After you configure the monitoring rules, you must configure notifications in CloudMonitor. You must complete this configuration to receive alerts. The procedure is as follows:
2.1 Alert contacts and contact groups
Go to the CloudMonitor console.
Create an alert contact.
On the Alert Contact tab, click Create Contact.
In the Set Alert Contact panel, enter the name, mobile number, email address, or webhook URL for the alert contact as needed. Leave the Alert Notification Language set to its default, Auto.
Auto means that CloudMonitor automatically sets the language for alerts based on the language specified when you registered your Alibaba Cloud account.
After you verify the information, click Confirm.
Create an alert contact group.
On the Alert Contact Group tab, click Create Contact Group.
In the Create Contact Group panel, enter a name for the group, select the alert contacts to add, and click Confirm.
Add alert contacts to an alert contact group in bulk.
On the Alert Contact tab, select the alert contacts that you want to add to a group, and click Add to Alert Contact Group.
In the Confirm Information dialog box, select the target alert contact group and click OK.
For more information, see Create an alert contact or an alert contact group.
2.2 CloudMonitor subscription
On the Alert Notification page in the Financial-grade Identity Verification console, go to the Alert Notification Configuration section and click Go to Subscription. This opens the Create Subscription Policy page in CloudMonitor.
On the Create Subscription Policy page, configure the subscription policy as described in the following table.
Module
Field
Description
Basic information
Name
The name of the subscription policy.
Description
Optional. A description of the subscription policy.
Alert subscription
Subscription Type
Select System Event.
Product: Select Identity Verification.
Event Type: Identity Verification > Exception.
We recommend leaving other subscription scopes empty.
Merge and noise reduction
Merge Content
We recommend leaving this field empty. If you select merge content fields, subscribed events are grouped by the selected fields for merging, noise reduction, and notification. For example, if you merge by event name and 100 alerts for three distinct events are triggered in one cycle, you will receive only three merged notifications.
Denoise
To prevent alert fatigue, the system enforces a default 10-minute suppression period, which can be overridden by a longer custom period. We recommend selecting Trigger immediately, no suppression.
Notification
Notification Configuration
Select the desired notification recipients.
Custom Notification Method
You can keep the default settings or customize the notification configuration.
Push and integration
Push Channel
Optional. If you configure a push channel, all raw subscribed events (without merging or noise reduction) are pushed directly to the configured channel.
For more information, see Manage event subscriptions (Recommended).