# LogicMonitor

> Resource, instance and group monitoring context beside the component your diagram explains.

Link a LogicMonitor device, DataSource instance or resource group to the Stratum
for the component it describes. A server can show the conditions affecting it;
a circuit can show the exact monitored interface; a site can show the observed
state of its group members. Keep your explanation alongside the saved
observation. Investigation, alert acknowledgement and configuration changes
remain in LogicMonitor.

## Connect your portal

1. You need an Enterprise licence, blueprint edit access and
   `continuum_integrations.manage` on the connection's organisation or team.
2. In LogicMonitor, create a dedicated
   [API-only user](https://www.logicmonitor.com/support/adding-an-api-only-user).
   Assign a role with **Resources View** on only the resource groups Blueprintr
   should read. Device, group, alert, instance, metric and scheduled downtime
   reads use resource permissions. Write, alert acknowledgement and Collector
   settings permissions are unnecessary. See
   [Resources role permissions](https://www.logicmonitor.com/support/resources-role-permissions).
3. Create a **Bearer** [API token](https://www.logicmonitor.com/support/api-tokens-2)
   for that user. This connector accepts Bearer tokens. LogicMonitor also
   supports LMv1 authentication, but an LMv1 access ID/key pair cannot be pasted
   into this connector's Bearer field.
4. In Blueprintr, open **Settings → Continuum** on the organisation or team, go
   to **Operational integrations**, choose **New integration**, select
   **LogicMonitor** as the **Type**, and enter a name, company and Bearer token.
   For `https://acme.logicmonitor.com`, enter `acme` as the company.
5. Review the content audience, saved detail and optional settings below,
   then select **Connect & verify**. Verification checks resource and alert
   reads with the supplied credential. A successful check with no visible
   devices is explained separately: review the user's resource-group access or
   add monitored resources. Verification does not establish complete coverage
   or verify every optional read. Save the blueprint before adding a link.

This connection uses REST v3 on commercial `logicmonitor.com` portals.
The portal host is always built as `<company>.logicmonitor.com`, so LMforGov
portals and custom API hosts cannot be reached. No local
agent is required. Credentials are encrypted and are not displayed again
after saving. LogicMonitor documents the supported authentication methods in
its [REST authentication guide](https://www.logicmonitor.com/support/rest-api-authentication).

## Choose the object your diagram describes

Open the Stratum for your server, interface or site and choose **Continuum Link**
from its **+ Add tab** menu. Only a rich stratum can host a linked tab.
Search its name, hostname or IP, or paste a current UIv4 device or group resource
URL from the portal.
Review the connection, company, object type, stable ID and instance lineage
before choosing **Link object**, especially when names repeat. A successful
first fetch is required before the binding is saved. One connection can have
one linked object on a Stratum; selecting another explicitly replaces that
connection's previous link.

| What the Stratum describes | How to select it | What to check |
| --- | --- | --- |
| A server or network device | Search a name, hostname or IP, or use `device:42` for an exact device ID. | Confirm the company and device identity; the same display name can exist more than once. |
| An interface or monitored component | Find its device, choose **Browse instances**, then select the instance. `instances:42` also lists instances on device 42. | Confirm the device, device-specific DataSource and instance. A DataSource's global ID is different from its device-specific DataSource ID. |
| An exact known instance | Use `instance:42:123:456`: device ID 42, device DataSource ID 123, instance ID 456. | Retain all three IDs; an instance name or portal instance URL alone does not establish its complete identity. |
| A site or service group | Search a group name or use `group:London` or `group:7`. | Confirm the group path and displayed direct/descendant scope. Membership describes an administrative monitoring group, not an architectural dependency. |
| A device within a group | Choose **Browse members** or use `members:7`. | This lists direct members. Browsing changes the search; it does not save a link. |

Scan and Suggest can help match diagram identifiers. Every suggestion still
needs your review. Search results are limited to what the dedicated LogicMonitor
user can read; no match does not prove that the object does not exist. Resolve
any reported search or coverage warning before relying on absence.

## Choose detail, scope and audience

These settings belong to the connection. Detail, audience, maintenance and
datapoint changes apply to subsequent fetches. The group scope is saved with
the selected object: review and relink a group to change its scope.

| Setting | New connection default | What it changes |
| --- | --- | --- |
| LogicMonitor content audience | Blueprint editors | Restricts the saved provider panel to blueprint editors. Choose the reader-visible option, **All Blueprint readers**, whose full label adds "approved metadata", only after approving the content for everyone who can read the blueprint. |
| Saved detail | Summary | Keeps object identity, operational states, counts and coverage with less monitoring detail. **Detailed** adds the affected monitoring names and member context. |
| Resource group scope | Direct members | **Include descendant groups** also includes resources within child groups when selecting a group. Duplicate memberships do not represent separate resources. |
| Maintenance context | Include maintenance windows | Adds available scheduled downtime context. Disable it to skip optional maintenance window reads. Alert downtime flags can still appear in Detailed snapshots. |
| Instance datapoints | Blank | Optionally enter up to three exact comma-separated datapoint names copied from the chosen DataSource instance. Metrics are fetched only for instance links and only when this field is populated. |

Existing connections keep their historical reader-visible detailed behaviour
until an administrator chooses otherwise. Existing settings with no maintenance
option do not enable additional maintenance reads.

Alert messages, acknowledgement comments, arbitrary resource properties and
Collector configuration are not imported. Summary information still includes
resource identity and operational metadata: it is not anonymous. Datapoint names
and availability vary by DataSource; choose names meaningful to the interface
or component rather than assuming every instance provides the same metrics.
The [instance API](https://www.logicmonitor.com/support/getting-datasource-instance-details)
and [data API](https://www.logicmonitor.com/support/getting-data) describe this
resource hierarchy.

## Read the saved observation

The panel distinguishes active alert severity, collection availability and
maintenance. Detailed snapshots also show acknowledgement and the affected
DataSource, instance and datapoint. Acknowledgement means someone has acknowledged an alert; it does
not mean the condition has recovered. Scheduled downtime can suppress
notifications while monitoring continues. A Collector problem means the
resource's current observations may be unavailable. None of these states
should be read as a general guarantee of system health. See
[LogicMonitor's scheduled downtime rules](https://www.logicmonitor.com/support/sdt-tab).

Alerting flags describe the object's local setting. The panel does not resolve
every inherited group or DataSource alert-suppression rule; check the provider
when deciding whether notifications should be sent.

Maintenance windows on an instance panel describe its parent device and can
include other monitoring scopes; they are not all specific to the selected
instance. A group panel reads schedules for the selected group, without
individually retrieving schedules for every member device or child instance.
Use each alert's downtime flag and the portal for precise maintenance scope.

Counts describe the active alerts and resources retrieved within the
connection's permissions and selected scope. If pagination cannot be completed,
the panel marks its coverage as partial; do not treat a lower bound as the full
total. Unknown, missing or unreadable information is not zero. Last NetFlow
receipt, if displayed, describes NetFlow specifically and does not establish
the freshness of all monitored data.

Optional instance metrics request the past hour and show the latest 12 samples
per selected datapoint, together with the requested/returned windows, sample
interval and missing-data information. Summary mode uses generic metric labels;
Detailed mode includes the selected datapoint names. Metric samples are never labelled with a unit. The value column is headed "Value
(unit unspecified)" and the Units row reads "Unit not supplied by LogicMonitor;
untransformed provider values". Blueprintr shows the raw numbers without
inferring a unit, converting the value or deriving a rate. Consult the DataSource definition in LogicMonitor
to interpret the sample correctly.

Opening the Stratum displays a saved snapshot and does not call LogicMonitor.
Re-fetch with the circular-arrows icon on the linked row ("Re-fetch this
integration's data"). After five minutes, the snapshot indicates
that another refresh is needed. This is a freshness reminder, not automatic
polling. Each metric has its own sample time; fetching a panel now does not
make an older provider sample current.

Use the source link to continue investigating the selected device, group or
instance in LogicMonitor. A link does not grant access: the provider still
applies the signed-in user's own permissions. Extended graphs, alert messages,
acknowledgement and configuration remain in the portal.

## Recover from failures and disconnect

A failed required read does not become an empty, healthy observation. A failed
refresh keeps the previous snapshot and shows a warning. An optional section
that cannot be retrieved is marked unavailable or partial. Check resource
permissions and token expiry, then verify the connection again. For rate
limits, wait before retrying; repeated browsing and refreshes consume the
portal's API capacity.

Use **Verify & replace** to rotate a token. The replacement is verified before
it replaces the working credential. **Suspend** stops search and refresh while saved
snapshots stay readable; **Resume** restarts it. The broken-link
icon on the linked row removes the current
binding; delete the connection after its bindings have been removed. Moving to
a different portal requires reviewing and relinking object identities; device
IDs are not portable between companies.

## Sharing and retained copies

Provider data is fetched with the connection's credential. Readers are governed
by the configured Blueprintr audience, not their individual LogicMonitor
permissions. Approved reader-visible content can reach anonymous readers of a
public blueprint, embeds, exports and configured search or AI features.
Editor-only panels use Blueprintr's existing audience controls for those reader
surfaces; editor exports and backups retain the source.

Changing a setting affects later successful fetches. Restricting the audience
does not rewrite panels already saved: refresh each linked tab successfully, or
unlink it, before treating existing LogicMonitor content as editor-only. It does
not redact independent versions, templates, exports or copies already shared. Unlinking,
suspending or revoking a token cannot recall those copies. Authored Stratum names,
link labels and notes remain your content and need a separate audience review.

## Validate before operational rollout

Automated tests exercise simulated provider responses; they do not establish
that a particular LogicMonitor tenant grants the expected access. Before
relying on this integration operationally, verify a least-privilege token,
duplicate names, an exact instance, direct and descendant group membership,
multi-page results, special-character searches and a permission-denied read in
a representative portal. Confirm metric units and gaps, scheduled downtime,
source links, freshness reminders and the published-reader audience. Check
rate limits and any feature entitlements with that tenant. The integration does
not import LogicMonitor topology or create monitoring configuration.
