aethercert
Monitoring and alerting

Certificate expiry monitoring and alerting

aethercert watches every certificate in the inventory, every job and every agent, records what happened in one event log, and sends the events that need a person to the monitoring you already run.

The event log and expiry detection are included in every plan. Push integrations and the Prometheus endpoint require Pro, MSP or MSP Plus. See plans and limits

The organization's event log.
01Monitoring and alerting

What it does

A scanner checks continuously for certificates that are within 14 days of expiry or already expired - managed and discovered alike - and for agents that stopped checking in. Each condition becomes an event, and a matching resolved event follows when it clears.

Events land in the organization's event log with the actor that caused them. On Pro and MSP plans, the alert-worthy ones are pushed to a webhook, a syslog/CEF collector or an SNMP trap receiver, and fleet metrics are available as a Prometheus endpoint for CheckMK, Prometheus, Grafana or Zabbix.

How it works

  1. 01

    Detect

    Expiry and agent health are scanned on a fixed cadence; job, deployment and configuration changes are recorded as they happen.

  2. 02

    Classify

    A curated catalog decides each event's severity and whether it is pushed. Routine bookkeeping stays in the log only.

  3. 03

    Deliver

    Push integrations receive the event as JSON, CEF or an SNMP trap. Webhooks are HMAC-signed when you set a secret.

  4. 04

    Resolve

    When a certificate is renewed or an agent returns, a resolved event closes the condition.

Key capabilities

Expiry alerts

Expiring soon (14 days), expired and resolved, for every non-revoked certificate in the inventory.

Failure alerts

Failed jobs and failed deployments, after retries are exhausted, plus deployment rollbacks.

Agent health

Offline and back-online events for every agent.

Event log with actor

Who created, changed or deleted what - certificates, deploy targets, CAs, members - kept for 7, 30 or 90 days by plan.

Push integrations

Webhooks, syslog with CEF and SNMP traps for SIEM and NOC tooling.

Prometheus metrics

Certificates by status and expiry bucket, agents by status, job outcomes and heartbeat age - with no per-certificate labels.

Compared with checking by hand

By handWith aethercert
Calendar reminders for each expiry date.Expiry is checked continuously and resolved automatically after renewal.
A failed renewal script fails silently.A failed job produces a critical event and a push notification.
No record of who changed a certificate or deployment.Every change is in the event log with its actor.

Works with your monitoring

Anything that accepts a webhook, syslog/CEF or SNMP traps, and anything that scrapes Prometheus metrics.

Security considerations

Signed webhooks

With a shared secret set, every webhook delivery is HMAC-signed, so the receiver can verify it came from aethercert.

Scoped metrics keys

The metrics endpoint uses its own API key, separate from user sessions, created by an admin.

Low-cardinality metrics

Metrics carry no certificate names, agent IDs or email addresses - per-entity detail stays in the dashboard.

Example: an expiring certificate reaches your SIEM

A discovered certificate on a server nobody remembered.

  1. scanportal.example.com is found 13 days before expiry.
  2. eventcertificate.expiring_soon (warning) is written to the event log.
  3. pushThe event is sent to your syslog collector in CEF format.
  4. resolveAfter a managed replacement is deployed, certificate.expiry_resolved follows.

Frequently asked questions

Monitoring and alerting

Do I get an email when a certificate is about to expire?

Expiry events are recorded in the event log on every plan and pushed to your webhook, syslog/CEF or SNMP receiver on Pro and MSP plans. aethercert does not send expiry warnings to users by email.

Can I use CheckMK, Zabbix or Grafana?

Yes. Point them at the Prometheus-format metrics endpoint with an API key; the documentation has examples for each.

How long is the event log kept?

7 days on Community, 30 days on Standard and 90 days on Pro and MSP plans.

Know before a certificate lapses

Every certificate in the inventory is watched from the first scan.

Community plan, no card required. Open registration - your account is ready in a few minutes.