Skip to content

Alert Scenarios

This document contains ready-to-use workflow examples for various monitoring and automation scenarios in the Sysadmin Anywhere ecosystem.

  1. Open n8n interface: http://localhost:5678
  2. Click “Import from file” or “Import from URL”
  3. Copy the JSON and paste into the import field
  4. Configure credentials for API keys and services
  5. Activate the workflow

Workflow 1: Comprehensive Infrastructure Monitoring

Section titled “Workflow 1: Comprehensive Infrastructure Monitoring”

Complete monitoring of all services, performance, and security with automatic problem escalation.

{
"name": "Infrastructure Health Monitor",
"nodes": [
{
"parameters": {
"cronExpression": "*/5 * * * *"
},
"name": "Schedule Trigger",
"type": "n8n-nodes-base.cron",
"typeVersion": 1,
"position": [240, 300]
},
{
"parameters": {
"url": "http://sysadminanywhere:8080/actuator/health",
"method": "GET"
},
"name": "Check Main Service",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [460, 200]
},
{
"parameters": {
"url": "http://directory:8080/actuator/health",
"method": "GET"
},
"name": "Check Directory Service",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [460, 300]
},
{
"parameters": {
"url": "http://inventory:8080/actuator/health",
"method": "GET"
},
"name": "Check Inventory Service",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [460, 400]
},
{
"parameters": {
"url": "http://incident:8080/actuator/health",
"method": "GET"
},
"name": "Check Incident Service",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [460, 500]
},
{
"parameters": {
"jsCode": "// Combine health check results\nconst services = [\n { name: 'Main Service', status: $input.item(0).json.status, responseTime: $input.item(0).json.responseTime || 0 },\n { name: 'Directory Service', status: $input.item(1).json.status, responseTime: $input.item(1).json.responseTime || 0 },\n { name: 'Inventory Service', status: $input.item(2).json.status, responseTime: $input.item(2).json.responseTime || 0 },\n { name: 'Incident Service', status: $input.item(3).json.status, responseTime: $input.item(3).json.responseTime || 0 }\n];\n\nconst unhealthyServices = services.filter(s => s.status !== 'UP');\nconst slowServices = services.filter(s => s.responseTime > 5000);\n\nconst results = [];\n\n// Add unhealthy services\nunhealthyServices.forEach(service => {\n results.push({\n service: service.name,\n status: service.status,\n responseTime: service.responseTime,\n severity: 'critical',\n issue: 'Service is down',\n timestamp: new Date().toISOString()\n });\n});\n\n// Add slow services\nslowServices.forEach(service => {\n results.push({\n service: service.name,\n status: service.status,\n responseTime: service.responseTime,\n severity: 'warning',\n issue: 'Service is slow',\n timestamp: new Date().toISOString()\n });\n});\n\nreturn results.map(result => ({ json: result }));"
},
"name": "Evaluate Health Status",
"type": "n8n-nodes-base.code",
"typeVersion": 2,
"position": [680, 350]
},
{
"parameters": {
"conditions": {
"string": [
{
"value1": "={{ $json.severity }}",
"operation": "equal",
"value2": "critical"
}
]
}
},
"name": "Check Critical Issues",
"type": "n8n-nodes-base.if",
"typeVersion": 1,
"position": [900, 300]
},
{
"parameters": {
"conditions": {
"string": [
{
"value1": "={{ $json.severity }}",
"operation": "equal",
"value2": "warning"
}
]
}
},
"name": "Check Warning Issues",
"type": "n8n-nodes-base.if",
"typeVersion": 1,
"position": [900, 450]
},
{
"parameters": {
"subject": "🚨 CRITICAL: {{ $json.service }} - {{ $json.issue }}",
"text": "Critical Infrastructure Alert:\n\nService: {{ $json.service }}\nStatus: {{ $json.status }}\nIssue: {{ $json.issue }}\nResponse Time: {{ $json.responseTime }}ms\nTimestamp: {{ $json.timestamp }}\n\nIMMEDIATE ACTION REQUIRED!\n\nPlease check the service and restore functionality.",
"options": {
"priority": "high"
}
},
"name": "Send Critical Email",
"type": "n8n-nodes-base.emailSend",
"typeVersion": 2,
"position": [1120, 250]
},
{
"parameters": {
"channel": "#critical-alerts",
"text": "🚨 {{ $json.service }} is {{ $json.status }}! Issue: {{ $json.issue }}. Response time: {{ $json.responseTime }}ms",
"otherOptions": {
"linkNames": true
}
},
"name": "Send Critical Slack",
"type": "n8n-nodes-base.slack",
"typeVersion": 2,
"position": [1120, 350]
},
{
"parameters": {
"toEmail": "[email protected]",
"subject": "⚠️ WARNING: {{ $json.service }} - {{ $json.issue }}",
"text": "Infrastructure Warning:\n\nService: {{ $json.service }}\nStatus: {{ $json.status }}\nIssue: {{ $json.issue }}\nResponse Time: {{ $json.responseTime }}ms\nTimestamp: {{ $json.timestamp }}\n\nPlease monitor the service performance.",
"options": {
"priority": "normal"
}
},
"name": "Send Warning Email",
"type": "n8n-nodes-base.emailSend",
"typeVersion": 2,
"position": [1120, 450]
},
{
"parameters": {
"channel": "#warnings",
"text": "⚠️ {{ $json.service }} performance issue: {{ $json.issue }}. Response time: {{ $json.responseTime }}ms",
"otherOptions": {
"linkNames": true
}
},
"name": "Send Warning Slack",
"type": "n8n-nodes-base.slack",
"typeVersion": 2,
"position": [1120, 550]
},
{
"parameters": {
"url": "http://incident:8080/api/incidents",
"method": "POST",
"body": {
"title": "{{ $json.service }} - {{ $json.issue }}",
"severity": "{{ $json.severity }}",
"description": "Service: {{ $json.service }}\\nStatus: {{ $json.status }}\\nIssue: {{ $json.issue }}\\nResponse Time: {{ $json.responseTime }}ms\\nTimestamp: {{ $json.timestamp }}",
"assignedTo": "it-team"
}
},
"name": "Create Incident",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [1340, 300]
}
],
"connections": {
"Schedule Trigger": {
"main": [
[
{
"node": "Check Main Service",
"type": "main",
"index": 0
},
{
"node": "Check Directory Service",
"type": "main",
"index": 0
},
{
"node": "Check Inventory Service",
"type": "main",
"index": 0
},
{
"node": "Check Incident Service",
"type": "main",
"index": 0
}
]
]
},
"Check Main Service": {
"main": [
[
{
"node": "Evaluate Health Status",
"type": "main",
"index": 0
}
]
]
},
"Check Directory Service": {
"main": [
[
{
"node": "Evaluate Health Status",
"type": "main",
"index": 1
}
]
]
},
"Check Inventory Service": {
"main": [
[
{
"node": "Evaluate Health Status",
"type": "main",
"index": 2
}
]
]
},
"Check Incident Service": {
"main": [
[
{
"node": "Evaluate Health Status",
"type": "main",
"index": 3
}
]
]
},
"Evaluate Health Status": {
"main": [
[
{
"node": "Check Critical Issues",
"type": "main",
"index": 0
},
{
"node": "Check Warning Issues",
"type": "main",
"index": 0
}
]
]
},
"Check Critical Issues": {
"main": [
[
{
"node": "Send Critical Email",
"type": "main",
"index": 0
},
{
"node": "Send Critical Slack",
"type": "main",
"index": 0
},
{
"node": "Create Incident",
"type": "main",
"index": 0
}
]
]
},
"Check Warning Issues": {
"main": [
[
{
"node": "Send Warning Email",
"type": "main",
"index": 0
},
{
"node": "Send Warning Slack",
"type": "main",
"index": 0
}
]
]
}
}
}

Workflow 2: Automated User Lifecycle Management

Section titled “Workflow 2: Automated User Lifecycle Management”

Automating user lifecycle: creation, lockout, deletion of inactive accounts.

{
"name": "User Lifecycle Management",
"nodes": [
{
"parameters": {
"cronExpression": "0 2 * * *"
},
"name": "Daily Schedule",
"type": "n8n-nodes-base.cron",
"typeVersion": 1,
"position": [240, 300]
},
{
"parameters": {
"url": "http://directory:8080/api/users/inactive",
"method": "GET",
"qs": {
"days": "90"
}
},
"name": "Get Inactive Users",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [460, 300]
},
{
"parameters": {
"conditions": {
"number": [
{
"value1": "={{ $json.length }}",
"operation": "larger",
"value2": 0
}
]
}
},
"name": "Check If Users Found",
"type": "n8n-nodes-base.if",
"typeVersion": 1,
"position": [680, 300]
},
{
"parameters": {
"jsCode": "// Process inactive users\nconst users = $input.all();\nconst results = [];\n\nusers.forEach(user => {\n const userData = user.json;\n const daysInactive = Math.floor((new Date() - new Date(userData.lastLoginDate)) / (1000 * 60 * 60 * 24));\n \n // Determine action based on inactive days\n let action = 'notify';\n if (daysInactive > 180) {\n action = 'disable';\n } else if (daysInactive > 365) {\n action = 'delete';\n }\n \n results.push({\n username: userData.username,\n email: userData.email,\n department: userData.department,\n lastLoginDate: userData.lastLoginDate,\n daysInactive: daysInactive,\n action: action,\n manager: userData.manager\n });\n});\n\nreturn results.map(user => ({ json: user }));"
},
"name": "Process Inactive Users",
"type": "n8n-nodes-base.code",
"typeVersion": 2,
"position": [900, 300]
},
{
"parameters": {
"values": {
"string": [
{
"name": "action",
"value": "notify"
}
]
}
},
"name": "Filter Notify Users",
"type": "n8n-nodes-base.filter",
"typeVersion": 1,
"position": [1120, 200]
},
{
"parameters": {
"values": {
"string": [
{
"name": "action",
"value": "disable"
}
]
}
},
"name": "Filter Disable Users",
"type": "n8n-nodes-base.filter",
"typeVersion": 1,
"position": [1120, 350]
},
{
"parameters": {
"values": {
"string": [
{
"name": "action",
"value": "delete"
}
]
}
},
"name": "Filter Delete Users",
"type": "n8n-nodes-base.filter",
"typeVersion": 1,
"position": [1120, 500]
},
{
"parameters": {
"toEmail": "={{ $json.email }},{{ $json.manager }}",
"subject": "Account Inactivity Notice - {{ $json.username }}",
"text": "Dear User,\n\nYour account ({{ $json.username }}) has been inactive for {{ $json.daysInactive }} days.\n\nLast login: {{ $json.lastLoginDate }}\nDepartment: {{ $json.department }}\n\nPlease log in to your account soon to maintain access. If you no longer need access, please inform IT department.\n\nIf your account remains inactive for more than 180 days, it will be automatically disabled.\n\nBest regards,\nIT Department",
"options": {
"priority": "normal"
}
},
"name": "Send Inactivity Notice",
"type": "n8n-nodes-base.emailSend",
"typeVersion": 2,
"position": [1340, 200]
},
{
"parameters": {
"url": "http://directory:8080/api/users/{{ $json.username }}/disable",
"method": "POST",
"body": {
"reason": "Automated disable due to inactivity ({{ $json.daysInactive }} days)"
}
},
"name": "Disable User Account",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [1340, 350]
},
{
"parameters": {
"url": "http://directory:8080/api/users/{{ $json.username }}",
"method": "DELETE"
},
"name": "Delete User Account",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [1340, 500]
},
{
"parameters": {
"toEmail": "[email protected]",
"subject": "User Management Actions Completed",
"text": "User Management Summary:\n\n{{ $json.action.toUpperCase() }} Actions:\nUsername: {{ $json.username }}\nEmail: {{ $json.email }}\nDepartment: {{ $json.department }}\nDays Inactive: {{ $json.daysInactive }}\nLast Login: {{ $json.lastLoginDate }}\n\nAction completed successfully.",
"options": {
"priority": "normal"
}
},
"name": "Send Management Report",
"type": "n8n-nodes-base.emailSend",
"typeVersion": 2,
"position": [1560, 350]
},
{
"parameters": {
"url": "http://incident:8080/api/audit-log",
"method": "POST",
"body": {
"action": "USER_MANAGEMENT",
"username": "{{ $json.username }}",
"actionType": "{{ $json.action }}",
"reason": "Automated user lifecycle management",
"timestamp": "{{ new Date().toISOString() }}",
"details": "Days inactive: {{ $json.daysInactive }}"
}
},
"name": "Log to Audit",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [1560, 450]
}
],
"connections": {
"Daily Schedule": {
"main": [
[
{
"node": "Get Inactive Users",
"type": "main",
"index": 0
}
]
]
},
"Get Inactive Users": {
"main": [
[
{
"node": "Check If Users Found",
"type": "main",
"index": 0
}
]
]
},
"Check If Users Found": {
"main": [
[
{
"node": "Process Inactive Users",
"type": "main",
"index": 0
}
]
]
},
"Process Inactive Users": {
"main": [
[
{
"node": "Filter Notify Users",
"type": "main",
"index": 0
},
{
"node": "Filter Disable Users",
"type": "main",
"index": 0
},
{
"node": "Filter Delete Users",
"type": "main",
"index": 0
}
]
]
},
"Filter Notify Users": {
"main": [
[
{
"node": "Send Inactivity Notice",
"type": "main",
"index": 0
}
]
]
},
"Filter Disable Users": {
"main": [
[
{
"node": "Disable User Account",
"type": "main",
"index": 0
}
]
]
},
"Filter Delete Users": {
"main": [
[
{
"node": "Delete User Account",
"type": "main",
"index": 0
}
]
]
},
"Disable User Account": {
"main": [
[
{
"node": "Send Management Report",
"type": "main",
"index": 0
},
{
"node": "Log to Audit",
"type": "main",
"index": 0
}
]
]
},
"Delete User Account": {
"main": [
[
{
"node": "Send Management Report",
"type": "main",
"index": 0
},
{
"node": "Log to Audit",
"type": "main",
"index": 0
}
]
]
}
}
}

Workflow 3: Security Threat Detection and Response

Section titled “Workflow 3: Security Threat Detection and Response”

Automatic security threat detection and immediate response.

{
"name": "Security Threat Detection",
"nodes": [
{
"parameters": {
"path": "security-events",
"method": "POST",
"responseMode": "onReceived"
},
"name": "Security Events Webhook",
"type": "n8n-nodes-base.webhook",
"typeVersion": 1,
"position": [240, 300]
},
{
"parameters": {
"conditions": {
"string": [
{
"value1": "={{ $json.severity }}",
"operation": "equal",
"value2": "critical"
}
]
}
},
"name": "Filter Critical Events",
"type": "n8n-nodes-base.filter",
"typeVersion": 1,
"position": [460, 300]
},
{
"parameters": {
"values": {
"string": [
{
"name": "eventType",
"value": "BRUTE_FORCE_ATTACK"
}
]
}
},
"name": "Filter Brute Force",
"type": "n8n-nodes-base.filter",
"typeVersion": 1,
"position": [680, 200]
},
{
"parameters": {
"values": {
"string": [
{
"name": "eventType",
"value": "SUSPICIOUS_LOGIN"
}
]
}
},
"name": "Filter Suspicious Login",
"type": "n8n-nodes-base.filter",
"typeVersion": 1,
"position": [680, 350]
},
{
"parameters": {
"values": {
"string": [
{
"name": "eventType",
"value": "PRIVILEGE_ESCALATION"
}
]
}
},
"name": "Filter Privilege Escalation",
"type": "n8n-nodes-base.filter",
"typeVersion": 1,
"position": [680, 500]
},
{
"parameters": {
"url": "http://directory:8080/api/security/block-ip",
"method": "POST",
"body": {
"ip": "={{ $json.sourceIP }}",
"reason": "Brute force attack detected",
"duration": 3600
}
},
"name": "Block IP Address",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [900, 200]
},
{
"parameters": {
"url": "http://directory:8080/api/users/{{ $json.username }}/lock",
"method": "POST",
"body": {
"reason": "Suspicious login pattern detected"
}
},
"name": "Lock User Account",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [900, 350]
},
{
"parameters": {
"url": "http://directory:8080/api/users/{{ $json.username }}/disable",
"method": "POST",
"body": {
"reason": "Privilege escalation detected - immediate action required"
}
},
"name": "Disable User Account",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [900, 500]
},
{
"parameters": {
"subject": "🔒 CRITICAL SECURITY INCIDENT: {{ $json.eventType }}",
"text": "CRITICAL SECURITY INCIDENT\n\nEvent Type: {{ $json.eventType }}\nSeverity: {{ $json.severity }}\nTimestamp: {{ $json.timestamp }}\n\nUser: {{ $json.username }}\nSource IP: {{ $json.sourceIP }}\nComputer: {{ $json.computerName }}\nDescription: {{ $json.description }}\n\nImmediate action has been taken automatically.\n\nSecurity team must investigate immediately!",
"options": {
"priority": "high"
}
},
"name": "Send Critical Security Alert",
"type": "n8n-nodes-base.emailSend",
"typeVersion": 2,
"position": [1120, 350]
},
{
"parameters": {
"channel": "#security-alerts",
"text": "🚨 CRITICAL SECURITY INCIDENT: {{ $json.eventType }} detected!\n\nUser: {{ $json.username }}\nIP: {{ $json.sourceIP }}\nComputer: {{ $json.computerName }}\n\nImmediate investigation required!",
"otherOptions": {
"linkNames": true
}
},
"name": "Send Security Slack Alert",
"type": "n8n-nodes-base.slack",
"typeVersion": 2,
"position": [1120, 450]
},
{
"parameters": {
"url": "https://api.twilio.com/2010-04-01/Accounts/YOUR_ACCOUNT/Messages.json",
"method": "POST",
"authentication": "predefinedCredentialType",
"nodeCredentialType": "twilioApi",
"body": {
"To": "+1234567890",
"From": "+1234567890",
"Body": "CRITICAL: {{ $json.eventType }} detected. Immediate action required!"
}
},
"name": "Send SMS Alert",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [1120, 550]
},
{
"parameters": {
"url": "http://incident:8080/api/incidents",
"method": "POST",
"body": {
"title": "{{ $json.eventType }} - {{ $json.username }}",
"severity": "critical",
"description": "Security incident detected:\n\nEvent: {{ $json.eventType }}\nUser: {{ $json.username }}\nSource IP: {{ $json.sourceIP }}\nComputer: {{ $json.computerName }}\nDescription: {{ $json.description }}\nTimestamp: {{ $json.timestamp }}\n\nAutomatic response actions have been taken.",
"assignedTo": "security-team",
"priority": "high"
}
},
"name": "Create Security Incident",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [1340, 450]
},
{
"parameters": {
"url": "http://incident:8080/api/audit-log",
"method": "POST",
"body": {
"action": "SECURITY_RESPONSE",
"eventType": "{{ $json.eventType }}",
"username": "{{ $json.username }}",
"sourceIP": "{{ $json.sourceIP }}",
"automaticResponse": true,
"timestamp": "{{ new Date().toISOString() }}",
"details": "Automatic security response triggered for critical event"
}
},
"name": "Log Security Response",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [1340, 550]
}
],
"connections": {
"Security Events Webhook": {
"main": [
[
{
"node": "Filter Critical Events",
"type": "main",
"index": 0
}
]
]
},
"Filter Critical Events": {
"main": [
[
{
"node": "Filter Brute Force",
"type": "main",
"index": 0
},
{
"node": "Filter Suspicious Login",
"type": "main",
"index": 0
},
{
"node": "Filter Privilege Escalation",
"type": "main",
"index": 0
}
]
]
},
"Filter Brute Force": {
"main": [
[
{
"node": "Block IP Address",
"type": "main",
"index": 0
}
]
]
},
"Filter Suspicious Login": {
"main": [
[
{
"node": "Lock User Account",
"type": "main",
"index": 0
}
]
]
},
"Filter Privilege Escalation": {
"main": [
[
{
"node": "Disable User Account",
"type": "main",
"index": 0
}
]
]
},
"Block IP Address": {
"main": [
[
{
"node": "Send Critical Security Alert",
"type": "main",
"index": 0
},
{
"node": "Send Security Slack Alert",
"type": "main",
"index": 0
},
{
"node": "Send SMS Alert",
"type": "main",
"index": 0
},
{
"node": "Create Security Incident",
"type": "main",
"index": 0
},
{
"node": "Log Security Response",
"type": "main",
"index": 0
}
]
]
},
"Lock User Account": {
"main": [
[
{
"node": "Send Critical Security Alert",
"type": "main",
"index": 0
},
{
"node": "Send Security Slack Alert",
"type": "main",
"index": 0
},
{
"node": "Send SMS Alert",
"type": "main",
"index": 0
},
{
"node": "Create Security Incident",
"type": "main",
"index": 0
},
{
"node": "Log Security Response",
"type": "main",
"index": 0
}
]
]
},
"Disable User Account": {
"main": [
[
{
"node": "Send Critical Security Alert",
"type": "main",
"index": 0
},
{
"node": "Send Security Slack Alert",
"type": "main",
"index": 0
},
{
"node": "Send SMS Alert",
"type": "main",
"index": 0
},
{
"node": "Create Security Incident",
"type": "main",
"index": 0
},
{
"node": "Log Security Response",
"type": "main",
"index": 0
}
]
]
}
}
}

Automatic generation and sending of daily system status reports.

{
"name": "Daily System Reports",
"nodes": [
{
"parameters": {
"cronExpression": "0 8 * * *"
},
"name": "Morning Schedule",
"type": "n8n-nodes-base.cron",
"typeVersion": 1,
"position": [240, 300]
},
{
"parameters": {
"url": "http://sysadminanywhere:8080/api/reports/users",
"method": "GET"
},
"name": "Get User Statistics",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [460, 200]
},
{
"parameters": {
"url": "http://inventory:8080/api/reports/computers",
"method": "GET"
},
"name": "Get Computer Statistics",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [460, 300]
},
{
"parameters": {
"url": "http://incident:8080/api/reports/security",
"method": "GET"
},
"name": "Get Security Statistics",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [460, 400]
},
{
"parameters": {
"url": "http://sysadminanywhere:8080/api/reports/performance",
"method": "GET"
},
"name": "Get Performance Statistics",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [460, 500]
},
{
"parameters": {
"jsCode": "// Generate daily report\nconst userStats = $input.item(0).json;\nconst computerStats = $input.item(1).json;\nconst securityStats = $input.item(2).json;\nconst performanceStats = $input.item(3).json;\n\nconst today = new Date().toLocaleDateString('en-US');\nconst yesterday = new Date(Date.now() - 86400000).toLocaleDateString('en-US');\n\nconst report = {\n date: today,\n period: `${yesterday} - ${today}`,\n summary: {\n totalUsers: userStats.totalUsers,\n activeUsers: userStats.activeUsers,\n newUsers: userStats.newUsers || 0,\n totalComputers: computerStats.totalComputers,\n onlineComputers: computerStats.onlineComputers,\n securityEvents: securityStats.totalEvents,\n criticalEvents: securityStats.criticalEvents,\n systemUptime: performanceStats.uptime,\n avgResponseTime: performanceStats.avgResponseTime\n },\n alerts: [],\n recommendations: []\n};\n\n// Check for issues\nif (userStats.newUsers > 10) {\n report.alerts.push(`High number of new users: ${userStats.newUsers}`);\n}\n\nif (computerStats.onlineComputers < computerStats.totalComputers * 0.9) {\n report.alerts.push(`Many computers offline: ${computerStats.totalComputers - computerStats.onlineComputers} of ${computerStats.totalComputers}`);\n}\n\nif (securityStats.criticalEvents > 0) {\n report.alerts.push(`Critical security events: ${securityStats.criticalEvents}`);\n}\n\nif (performanceStats.avgResponseTime > 2000) {\n report.alerts.push(`High system response time: ${performanceStats.avgResponseTime}ms`);\n report.recommendations.push('Consider performance optimization');\n}\n\nreturn { json: report };"
},
"name": "Generate Daily Report",
"type": "n8n-nodes-base.code",
"typeVersion": 2,
"position": [680, 350]
},
{
"parameters": {
"jsCode": "// Format HTML report\nconst report = $json;\n\nconst html = `\n<!DOCTYPE html>\n<html>\n<head>\n <title>Daily System Report - ${report.date}</title>\n <style>\n body { font-family: Arial, sans-serif; margin: 20px; }\n .header { background-color: #f0f0f0; padding: 20px; border-radius: 5px; }\n .section { margin: 20px 0; }\n .metric { display: inline-block; margin: 10px; padding: 10px; background-color: #f9f9f9; border: 1px solid #ddd; border-radius: 3px; }\n .alert { background-color: #ffe6e6; border: 1px solid #ff0000; padding: 10px; margin: 10px 0; border-radius: 3px; }\n .recommendation { background-color: #e6ffe6; border: 1px solid #00ff00; padding: 10px; margin: 10px 0; border-radius: 3px; }\n </style>\n</head>\n<body>\n <div class=\"header\">\n <h1>Daily System Report</h1>\n <p><strong>Date:</strong> ${report.date}</p>\n <p><strong>Period:</strong> ${report.period}</p>\n </div>\n\n <div class=\"section\">\n <h2>Summary</h2>\n <div class=\"metric\"><strong>Total Users:</strong> ${report.summary.totalUsers}</div>\n <div class=\"metric\"><strong>Active Users:</strong> ${report.summary.activeUsers}</div>\n <div class=\"metric\"><strong>New Users:</strong> ${report.summary.newUsers}</div>\n <div class=\"metric\"><strong>Total Computers:</strong> ${report.summary.totalComputers}</div>\n <div class=\"metric\"><strong>Online Computers:</strong> ${report.summary.onlineComputers}</div>\n <div class=\"metric\"><strong>Security Events:</strong> ${report.summary.securityEvents}</div>\n <div class=\"metric\"><strong>Critical Events:</strong> ${report.summary.criticalEvents}</div>\n <div class=\"metric\"><strong>System Uptime:</strong> ${report.summary.systemUptime}%</div>\n <div class=\"metric\"><strong>Avg Response Time:</strong> ${report.summary.avgResponseTime}ms</div>\n </div>\n\n ${report.alerts.length > 0 ? `\n <div class=\"section\">\n <h2>Alerts</h2>\n ${report.alerts.map(alert => `<div class=\"alert\">${alert}</div>`).join('')}\n </div>\n ` : ''}\n\n ${report.recommendations.length > 0 ? `\n <div class=\"section\">\n <h2>Recommendations</h2>\n ${report.recommendations.map(rec => `<div class=\"recommendation\">${rec}</div>`).join('')}\n </div>\n ` : ''}\n\n <div class=\"section\">\n <p><em>Report generated automatically by Sysadmin Anywhere</em></p>\n </div>\n</body>\n</html>\n`;\n\nreturn { json: { html: html, report: report } };"
},
"name": "Format HTML Report",
"type": "n8n-nodes-base.code",
"typeVersion": 2,
"position": [900, 350]
},
{
"parameters": {
"subject": "Daily System Report - {{ $json.report.date }}",
"html": "={{ $json.html }}",
"options": {
"priority": "normal"
}
},
"name": "Send Daily Report",
"type": "n8n-nodes-base.emailSend",
"typeVersion": 2,
"position": [1120, 350]
},
{
"parameters": {
"channel": "#daily-reports",
"text": "📊 Daily System Report for {{ $json.report.date }}:\n\n👥 Users: {{ $json.report.summary.totalUsers }} ({{ $json.report.summary.activeUsers }} active, {{ $json.report.summary.newUsers }} new)\n💻 Computers: {{ $json.report.summary.totalComputers }} ({{ $json.report.summary.onlineComputers }} online)\n🔒 Security Events: {{ $json.report.summary.securityEvents }} ({{ $json.report.summary.criticalEvents }} critical)\n⚡ System Uptime: {{ $json.report.summary.systemUptime }}%\n📈 Avg Response Time: {{ $json.report.summary.avgResponseTime }}ms\n\n{{ $json.report.alerts.length > 0 ? '🚨 Alerts: ' + $json.report.alerts.length : '✅ No alerts' }}",
"otherOptions": {
"linkNames": true
}
},
"name": "Send Slack Summary",
"type": "n8n-nodes-base.slack",
"typeVersion": 2,
"position": [1120, 450]
},
{
"parameters": {
"url": "http://incident:8080/api/reports/daily",
"method": "POST",
"body": "={{ $json.report }}"
},
"name": "Archive Report",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [1340, 400]
}
],
"connections": {
"Morning Schedule": {
"main": [
[
{
"node": "Get User Statistics",
"type": "main",
"index": 0
},
{
"node": "Get Computer Statistics",
"type": "main",
"index": 0
},
{
"node": "Get Security Statistics",
"type": "main",
"index": 0
},
{
"node": "Get Performance Statistics",
"type": "main",
"index": 0
}
]
]
},
"Get User Statistics": {
"main": [
[
{
"node": "Generate Daily Report",
"type": "main",
"index": 0
}
]
]
},
"Get Computer Statistics": {
"main": [
[
{
"node": "Generate Daily Report",
"type": "main",
"index": 1
}
]
]
},
"Get Security Statistics": {
"main": [
[
{
"node": "Generate Daily Report",
"type": "main",
"index": 2
}
]
]
},
"Get Performance Statistics": {
"main": [
[
{
"node": "Generate Daily Report",
"type": "main",
"index": 3
}
]
]
},
"Generate Daily Report": {
"main": [
[
{
"node": "Format HTML Report",
"type": "main",
"index": 0
}
]
]
},
"Format HTML Report": {
"main": [
[
{
"node": "Send Daily Report",
"type": "main",
"index": 0
},
{
"node": "Send Slack Summary",
"type": "main",
"index": 0
},
{
"node": "Archive Report",
"type": "main",
"index": 0
}
]
]
}
}
}

Monitoring load and automatic resource optimization.

{
"name": "Auto Scaling and Optimization",
"nodes": [
{
"parameters": {
"cronExpression": "*/15 * * * *"
},
"name": "Schedule Trigger",
"type": "n8n-nodes-base.cron",
"typeVersion": 1,
"position": [240, 300]
},
{
"parameters": {
"url": "http://sysadminanywhere:8080/api/metrics/load",
"method": "GET"
},
"name": "Get System Load",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [460, 300]
},
{
"parameters": {
"url": "http://inventory:8080/api/metrics/performance",
"method": "GET"
},
"name": "Get Performance Metrics",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [460, 400]
},
{
"parameters": {
"jsCode": "// Analyze load and determine actions\nconst systemLoad = $input.item(0).json;\nconst performance = $input.item(1).json;\n\nconst actions = [];\n\n// Check CPU load\nif (systemLoad.cpuUsage > 85) {\n actions.push({\n type: 'scale_up',\n reason: 'High CPU usage',\n value: systemLoad.cpuUsage,\n severity: systemLoad.cpuUsage > 95 ? 'critical' : 'high'\n });\n}\n\n// Check memory\nif (systemLoad.memoryUsage > 90) {\n actions.push({\n type: 'scale_memory',\n reason: 'High memory usage',\n value: systemLoad.memoryUsage,\n severity: systemLoad.memoryUsage > 95 ? 'critical' : 'high'\n });\n}\n\n// Check disk space\nif (systemLoad.diskUsage > 85) {\n actions.push({\n type: 'cleanup_disk',\n reason: 'High disk usage',\n value: systemLoad.diskUsage,\n severity: systemLoad.diskUsage > 95 ? 'critical' : 'high'\n });\n}\n\n// Check database performance\nif (performance.dbResponseTime > 5000) {\n actions.push({\n type: 'optimize_db',\n reason: 'Slow database response',\n value: performance.dbResponseTime,\n severity: performance.dbResponseTime > 10000 ? 'critical' : 'high'\n });\n}\n\n// Check active sessions\nif (systemLoad.activeSessions > systemLoad.maxSessions * 0.8) {\n actions.push({\n type: 'scale_sessions',\n reason: 'High session count',\n value: systemLoad.activeSessions,\n severity: 'medium'\n });\n}\n\n// If load is low, consider scaling down\nif (systemLoad.cpuUsage < 20 && systemLoad.memoryUsage < 30 && systemLoad.activeSessions < systemLoad.maxSessions * 0.3) {\n actions.push({\n type: 'scale_down',\n reason: 'Low system load',\n value: systemLoad.cpuUsage,\n severity: 'info'\n });\n}\n\nreturn actions.map(action => ({ json: action }));"
},
"name": "Analyze Load and Actions",
"type": "n8n-nodes-base.code",
"typeVersion": 2,
"position": [680, 350]
},
{
"parameters": {
"values": {
"string": [
{
"name": "type",
"value": "scale_up"
}
]
}
},
"name": "Filter Scale Up",
"type": "n8n-nodes-base.filter",
"typeVersion": 1,
"position": [900, 200]
},
{
"parameters": {
"values": {
"string": [
{
"name": "type",
"value": "scale_memory"
}
]
}
},
"name": "Filter Scale Memory",
"type": "n8n-nodes-base.filter",
"typeVersion": 1,
"position": [900, 300]
},
{
"parameters": {
"values": {
"string": [
{
"name": "type",
"value": "cleanup_disk"
}
]
}
},
"name": "Filter Cleanup Disk",
"type": "n8n-nodes-base.filter",
"typeVersion": 1,
"position": [900, 400]
},
{
"parameters": {
"values": {
"string": [
{
"name": "type",
"value": "optimize_db"
}
]
}
},
"name": "Filter Optimize DB",
"type": "n8n-nodes-base.filter",
"typeVersion": 1,
"position": [900, 500]
},
{
"parameters": {
"url": "http://sysadminanywhere:8080/api/scale/up",
"method": "POST",
"body": {
"reason": "{{ $json.reason }}",
"currentLoad": "{{ $json.value }}",
"severity": "{{ $json.severity }}"
}
},
"name": "Scale Up Resources",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [1120, 200]
},
{
"parameters": {
"url": "http://sysadminanywhere:8080/api/scale/memory",
"method": "POST",
"body": {
"reason": "{{ $json.reason }}",
"currentUsage": "{{ $json.value }}",
n "severity": "{{ $json.severity }}"
}
},
"name": "Scale Memory",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [1120, 300]
},
{
"parameters": {
"url": "http://sysadminanywhere:8080/api/cleanup/disk",
"method": "POST",
"body": {
"reason": "{{ $json.reason }}",
"usage": "{{ $json.value }}",
"severity": "{{ $json.severity }}"
}
},
"name": "Cleanup Disk Space",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [1120, 400]
},
{
"parameters": {
"url": "http://sysadminanywhere:8080/api/optimize/database",
"method": "POST",
"body": {
"reason": "{{ $json.reason }}",
"responseTime": "{{ $json.value }}",
"severity": "{{ $json.severity }}"
}
},
"name": "Optimize Database",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [1120, 500]
},
{
"parameters": {
"toEmail": "[email protected]",
"subject": "🔧 Auto Scaling: {{ $json.type }} - {{ $json.reason }}",
"text": "Automatic scaling action performed:\n\nAction: {{ $json.type }}\nReason: {{ $json.reason }}\nValue: {{ $json.value }}\nSeverity: {{ $json.severity }}\nTimestamp: {{ new Date().toISOString() }}\n\nThis action was performed automatically by the system monitoring.",
"options": {
"priority": "{{ $json.severity === 'critical' ? 'high' : 'normal' }}"
}
},
"name": "Send Scaling Notification",
"type": "n8n-nodes-base.emailSend",
"typeVersion": 2,
"position": [1340, 350]
},
{
"parameters": {
"channel": "#ops-alerts",
"text": "🔧 Auto scaling: {{ $json.type }} due to {{ $json.reason }} ({{ $json.value }})",
"otherOptions": {
"linkNames": true
}
},
"name": "Send Slack Notification",
"type": "n8n-nodes-base.slack",
"typeVersion": 2,
"position": [1340, 450]
},
{
"parameters": {
"url": "http://incident:8080/api/audit-log",
"method": "POST",
"body": {
"action": "AUTO_SCALING",
"actionType": "{{ $json.type }}",
"reason": "{{ $json.reason }}",
n "value": "{{ $json.value }}",
"severity": "{{ $json.severity }}",
"timestamp": "{{ new Date().toISOString() }}"
}
},
"name": "Log Scaling Action",
"type": "n8n-nodes-base.httpRequest",
"typeVersion": 3,
"position": [1340, 550]
}
],
"connections": {
"Schedule Trigger": {
"main": [
[
{
"node": "Get System Load",
"type": "main",
"index": 0
},
{
"node": "Get Performance Metrics",
"type": "main",
"index": 0
}
]
]
},
"Get System Load": {
"main": [
[
{
"node": "Analyze Load and Actions",
"type": "main",
"index": 0
}
]
]
},
"Get Performance Metrics": {
"main": [
[
{
"node": "Analyze Load and Actions",
"type": "main",
"index": 1
}
]
]
},
"Analyze Load and Actions": {
"main": [
[
{
"node": "Filter Scale Up",
"type": "main",
"index": 0
},
{
"node": "Filter Scale Memory",
"type": "main",
"index": 0
},
{
"node": "Filter Cleanup Disk",
"type": "main",
"index": 0
},
{
"node": "Filter Optimize DB",
"type": "main",
"index": 0
}
]
]
},
"Filter Scale Up": {
"main": [
[
{
"node": "Scale Up Resources",
"type": "main",
"index": 0
}
]
]
},
"Filter Scale Memory": {
"main": [
[
{
"node": "Scale Memory",
"type": "main",
"index": 0
}
]
]
},
"Filter Cleanup Disk": {
"main": [
[
{
"node": "Cleanup Disk Space",
"type": "main",
"index": 0
}
]
]
},
"Filter Optimize DB": {
"main": [
[
{
"node": "Optimize Database",
"type": "main",
"index": 0
}
]
]
},
"Scale Up Resources": {
"main": [
[
{
"node": "Send Scaling Notification",
"type": "main",
"index": 0
},
{
"node": "Send Slack Notification",
"type": "main",
"index": 0
},
{
"node": "Log Scaling Action",
"type": "main",
"index": 0
}
]
]
},
"Scale Memory": {
"main": [
[
{
"node": "Send Scaling Notification",
"type": "main",
"index": 0
},
{
"node": "Send Slack Notification",
"type": "main",
"index": 0
},
{
"node": "Log Scaling Action",
"type": "main",
"index": 0
}
]
]
},
"Cleanup Disk Space": {
"main": [
[
{
"node": "Send Scaling Notification",
"type": "main",
"index": 0
},
{
"node": "Send Slack Notification",
"type": "main",
"index": 0
},
{
"node": "Log Scaling Action",
"type": "main",
"index": 0
}
]
]
},
"Optimize Database": {
"main": [
[
{
"node": "Send Scaling Notification",
"type": "main",
"index": 0
},
{
"node": "Send Slack Notification",
"type": "main",
"index": 0
},
{
"node": "Log Scaling Action",
"type": "main",
"index": 0
}
]
]
}
}
}
{
"name": "SMTP Server",
"type": "smtp",
"data": {
"host": "smtp.company.com",
"port": 587,
"secure": false,
"user": "[email protected]",
"password": "your-password"
}
}
{
"name": "Slack Bot",
"type": "slackApi",
"data": {
"botToken": "xoxb-your-bot-token"
}
}
{
"name": "Sysadmin Anywhere API",
"type": "httpBasicAuth",
"data": {
"username": "api-user",
"password": "api-password"
}
}
  1. Test Run: Use “Execute Workflow” for testing
  2. Mock Data: Create test webhook calls
  3. Check Logs: Review execution history
  4. Validation: Ensure all notification channels work
  1. Execution time: Monitor workflow execution time
  2. Error rate: Track error count
  3. Resource usage: Check resource consumption
  4. Success rate: Track successful executions

These workflows provide comprehensive automation for Sysadmin Anywhere. Adapt them to your specific requirements and infrastructure.