# Connector reference

> Every Continuum Link connector, what it asks for when you connect it, and what its saved panel shows.

39 connectors are registered. 29 connect directly and 10 need the
[local agent](/foliums/blueprintr-user-guide/continuum/local-agent). All of them are
[Continuum Link](/foliums/blueprintr-user-guide/continuum/continuum-link), so all
of them need an Enterprise plan and `continuum_integrations.manage`, and none of
them draws on a canvas.

Every connector can be found by free-text search when linking a stratum. Where a
credential field has no label of its own, the form calls it **API token**.

## Alerting and on-call

| Connector | Credential | Other fields | Panel |
| --- | --- | --- | --- |
| [PagerDuty](/foliums/blueprintr-user-guide/continuum/pagerduty) | API token | PagerDuty region, Imported content | Service identity, open incidents, incident coverage, ownership, on-call coverage, related services |
| [incident.io](/foliums/blueprintr-user-guide/continuum/incident-io) | API key | Catalog types, relationship fields, attributes, history days, remediation counts | Catalog entry and related incidents, or one incident with durations and follow-ups |
| [Rootly](/foliums/blueprintr-user-guide/continuum/rootly) | API key | Content audience, ownership context, on-call coverage, action item counts | Service response and history, or one incident's lifecycle |
| [Jira Service Management Operations](/foliums/blueprintr-user-guide/continuum/jira) | Atlassian sign-in | Site, counts-only | Alert scope with open, unacknowledged and snoozed counts, or an on-call schedule |
| FireHydrant | API key | None | Service tier and active incidents, or one incident |
| Splunk On-Call | API credentials (JSON) | None | One incident, paged teams and state transitions |
| xMatters | Password | Instance URL, Username | A group, a person or an event, with recent events |

## Observability

| Connector | Credential | Other fields | Panel |
| --- | --- | --- | --- |
| [Datadog](/foliums/blueprintr-user-guide/continuum/datadog) | Datadog credentials | Datadog site, content audience, saved detail, approved tag keys, Software Catalog, SLOs, default SLO window | Host, monitor, catalog service or reliability objective |
| New Relic | User API key | Region (optional) | Entity identity, alert severity, reporting state and tags |
| Dynatrace | API token | Environment URL | Entity identity and open problems by category, with a timeline |
| Elastic Observability | API key | Kibana URL | Alert rule identity, active count and execution status |
| Splunk Observability Cloud | Access token | Realm | Detector state, active incidents by severity, current signals |
| SolarWinds Observability SaaS | API token | Data centre | Entity identity, health state, maintenance and telemetry age |
| Grafana Alerting | Service account token | Grafana URL | Firing alerts for a label matcher, or one alert rule's state |

> [!IMPORTANT]
> Every cloud connector reaches its provider from Blueprintr over HTTPS and is
> blocked from private, loopback, link-local, carrier-NAT and metadata addresses.
> Any URL field in these tables must name a publicly reachable host: Grafana,
> Alertmanager, Kibana, Dynatrace environment, self-hosted GitLab, xMatters and
> ServiceNow included. An internal host needs one of the on-premise connectors
> below, and Grafana, Alertmanager, Elastic, Dynatrace and GitLab are not among
> them.

## Monitoring

| Connector | Credential | Other fields | Panel |
| --- | --- | --- | --- |
| [LogicMonitor](/foliums/blueprintr-user-guide/continuum/logicmonitor) | Bearer token | Company, content audience, saved detail, group scope, maintenance context, instance datapoints | Device, DataSource instance or resource group |
| [Auvik](/foliums/blueprintr-user-guide/continuum/auvik) | API key | Region, Username, site scope, audience, saved detail, alert history period, optional sections | Device context and recent alert history |
| AWS CloudWatch | None | A verified AWS cloud connection and a region | An alarm with recent state changes, or a log group with event volume |
| Azure Monitor | Client secret | Tenant ID, Client ID, Subscription ID | Resource identity, alerts by severity, recent alerts |
| Google Cloud Monitoring | Service account key (JSON) | Project ID | Alert policy and its conditions |
| Prometheus Alertmanager | Password | Alertmanager URL, Username (optional) | Alert counts for a matcher, top labels, firing since |

CloudWatch is the one cloud connector that stores no credential of its own. It
reuses a verified
[cloud connection](/foliums/blueprintr-user-guide/continuum/cloud-connections),
so the form offers a connection and region picker instead of a token field.

That connection's role needs nine CloudWatch and Logs actions the discovery role
does not grant. The form lists them under **Required IAM actions for the backing
role**; add them before expecting alarm or log-group data. On an organisation-mode
connection the form also asks for a 12-digit member account id.

Alertmanager always requires a secret to save the connection. For an
unauthenticated instance, leave **Username** blank and type any placeholder in
**Password**. It is never sent without a username.

Google Cloud Monitoring shows alert-policy configuration only. Its panel states
"Open incidents unavailable".

## Uptime and synthetics

| Connector | Credential | Other fields | Panel |
| --- | --- | --- | --- |
| Pingdom | API token | None | Check identity, uptime percentage, average response, state changes |
| Better Stack Uptime | API token | None | Monitor identity, SLA and incident counts, active incidents |
| UptimeRobot | API key | None | Monitor identity, recent health and window totals |
| Checkly | API key | Account ID | Check identity, sampled results, latest runs |
| Site24x7 | OAuth credentials (JSON) | OAuth client ID, Data centre (optional) | Monitor state, account-wide fleet status, current problem monitors |

## Service management and source control

| Connector | Credential | Other fields | Panel |
| --- | --- | --- | --- |
| [Jira Cloud work items](/foliums/blueprintr-user-guide/continuum/jira) | Atlassian sign-in | Site, counts-only | One work item, a saved filter or a JQL scope |
| [ServiceNow CMDB](/foliums/blueprintr-user-guide/continuum/servicenow) | Password | Instance URL, Username, Snapshot audience, Saved detail, Open work | Configuration item with lifecycle, environment, ownership groups and discovery dates; relationships from the CI's side with the total; optional open incident and change counts |
| [GitHub](/foliums/blueprintr-user-guide/continuum/github) | Fine-grained access token | Verification repository, optional organisation, enabled reads, audience and detail | Repository context scoped by branch/workflow, labels, environment and path; separate work and CI, optional deployment, commit and release evidence |
| GitLab | Access token | Instance URL (optional) | Project identity, activity, recent issues and pipelines |

> [!NOTE]
> GitHub and GitLab take a pasted access token. There is no sign-in button on the
> Continuum connection form; Jira is the only connector that signs you in.

## On-premise, through the local agent

These ten appear in the connector list but cannot be selected until the
organisation has an enrolled agent online that can serve them. Until then the
option is disabled and its label says why: set up an agent, the agent is offline,
or upgrade the agent. Blueprintr never stores their credentials. Set in the
agent's own configuration, a credential never leaves your network; sent from the
Continuum Local panel instead (the agent must allow it), it passes through
Blueprintr to the agent without being saved. The connection form has no
credential field, and shows the account each product needs under its notice.

| Connector | Credential parts in the agent config | Other fields | Panel |
| --- | --- | --- | --- |
| SolarWinds Orion | `username` and `password` | Orion server URL | Node identity, health metrics, active alerts, interfaces, volumes |
| Zabbix | `token` | Zabbix frontend URL | Host identity, unresolved problems, current problems |
| PRTG Network Monitor | `token` | PRTG server URL | Device identity, sensor counts, unhealthy sensors |
| Checkmk | `username` and `password` | Checkmk URL, Site | Host identity, service states, current problems |
| Icinga 2 | `username` and `password` | API URL | Host identity, service states, active problems |
| ManageEngine OpManager | `token` | OpManager URL | Device identity, active alarms |
| WhatsUp Gold | `username` and `password` | WhatsUp Gold URL | Device identity and active monitor counts |
| NetBox | `token` | NetBox URL, Custom fields to show, Snapshot audience | Device or virtual machine identity, primary addresses, interfaces with MACs, addresses and cabled peers, and the listed custom fields |
| Infoblox | `username` and `password` | Grid Manager URL, WAPI version, Extensible attributes to show | A host, an address or a network: DNS records, IPAM state, DHCP leases and fixed addresses, network utilization and the listed extensible attributes |
| Veeam Backup & Replication | `username` and `password` | Backup server URL, REST API version, Restore point target | Protection verdict, age of the last good restore point, jobs protecting the machine and their last result, recent failures |

For SolarWinds Orion, Checkmk, Icinga 2 and Infoblox the username is part of the
agent's credential, so the connection form does not ask for it. It shows what that
account needs instead; set the username with the password, in the agent config or
from the Continuum Local panel.

Each one wants a dedicated account that can only read, on a known port, and most
need a certificate given to the agent. A port in the connector's URL replaces
the default. The
[Continuum Local page](/foliums/blueprintr-user-guide/continuum/local-agent)
explains the certificate column.

| Connector | Least-privilege account | Default port | Certificate |
| --- | --- | --- | --- |
| SolarWinds Orion | No administrator, node management or unmanage rights | 17774 | Self-signed on install |
| Zabbix | Role type User, Read on the host groups to show | 443 | Depends on the install |
| PRTG Network Monitor | API key with Read access, Read-only user | 443 | Self-signed on install |
| Checkmk | Role copied from Guest, plus Read access to all hosts and folders | 443 | Depends on the install |
| Icinga 2 | ApiUser with `objects/query/Host` and `objects/query/Service` only | 5665 | Icinga's own CA |
| ManageEngine OpManager | API key with Read access only | 8060. Write it in the URL: without a port, the connector uses 443 | Self-signed on install |
| WhatsUp Gold | Read-only user that can read the Entire Network group | 9644 | Depends on the install |
| NetBox | View on devices, interfaces, IP addresses, VMs and VM interfaces only; Write enabled off | 443 | Depends on the install |
| Infoblox | Own admin group with API access and read-only permissions, no superuser | 443 | Issued to www.infoblox.com: replace it first |
| Veeam Backup & Replication | Veeam Backup Viewer role only | 9419 | Self-signed on install |

### NetBox

Supports NetBox 4.0 and later; verify refuses an older release,
because before 4.0 NetBox ignores the list of fields Blueprintr asks for and
would send config contexts. Enter the token alone, without the word Token or
Bearer. v1 tokens are 40 characters; v2 tokens (NetBox 4.5 and later) begin
`nbt_` and include the part after the dot. Either works. Blueprintr never asks
for config contexts or comments. It asks for custom fields only when you list
some under Custom fields to show; left blank, or set to `none`, no custom field
value leaves NetBox. NetBox cannot send only some custom fields, so while any
are listed, NetBox sends Blueprintr every custom field value on the device or
virtual machine: panels show only the listed ones, and the rest are deleted with
the request within minutes. A custom field named like a credential is never
shown, even when listed. If you keep secrets in custom fields, leave the list
blank. The panel is for Blueprint editors unless you choose all Blueprint
readers.

### Infoblox

Leave the WAPI version blank on NIOS 8.6 and later (2.12). The
certificate NIOS installs with is issued to www.infoblox.com, so replace it with
one for the Grid Master's address before giving it to the agent as `caFile`; the
Continuum Local page has the steps. While any extensible attributes are shown,
the grid sends Blueprintr all of an object's extensible attributes: panels show
only the listed ones, and the rest are deleted with the request within minutes.
Enter `none` and Blueprintr never asks for them. If you keep secrets in
extensible attributes, use `none`. Panels are for Blueprint editors only, since
leases and MAC addresses can identify people on client networks.

### Veeam Backup & Replication

Needs version 12 or later and agent 0.2.0 or
later, which keeps Veeam's access token on the agent. On 12.0, set the REST API
version to `1.1-rev0`. The build number in the verify message needs the Backup
Administrator role, and is left out for a Backup Viewer. The tab measures a
restore point's age on the backup server's own clock. A job that includes a
machine through a folder, tag or cluster is found through the machine's restore
points, not through the job definition. Panels are for Blueprint editors only.

## Reading any panel

Whatever the connector, the same rules hold.

- Data is fetched with the connection's credential, not the reader's. A source
  link opens the provider, which applies its own permissions.
- A panel is a named projection of the provider's response. The raw upstream
  object is never stored as-is.
- A failed read never becomes a zero. Sections are marked unavailable or partial,
  and partial counts are lower bounds.
- A provider that cannot be reached leaves the saved snapshot in place. The tab
  keeps its last successful body and the banner reads "Last refresh failed". A
  first link that cannot fetch is refused, so no tab is created.
- A saved panel reaches everyone who can read the blueprint unless its connector
  has an audience setting or keeps its panels for editors. Datadog, LogicMonitor,
  Auvik, Rootly, ServiceNow, GitHub and NetBox have the setting, and Infoblox and
  Veeam Backup & Replication panels are always for Blueprint editors only. On a
  public blueprint every other panel is visible to anonymous readers, embeds and
  exports.
- 24 connectors are indexed so **Suggest Continuum Links** can propose matches
  without asking the platform: PagerDuty, incident.io, Rootly, FireHydrant,
  xMatters, Datadog, New Relic, Dynatrace, Elastic, Splunk Observability,
  SolarWinds Observability SaaS, Grafana Alerting, LogicMonitor, Auvik, Azure
  Monitor, Google Cloud Monitoring, Pingdom, Better Stack, UptimeRobot, Checkly,
  Site24x7, ServiceNow CMDB, GitHub and GitLab. The index holds object names,
  links and one-way digests of identifiers, under the same audience and detail
  settings. Datadog, GitHub, GitLab,
  incident.io, New Relic, ServiceNow CMDB and xMatters index only some of their
  object types, so their matches are held back for review and also checked live.
  Every other connector is checked live.
- Counts describe what was retrieved at the stated time. They are not a statement
  that the component is healthy now.
