Linking Better Stack as a source
Let AI connect your sources for you
Skip the manual setup — run this in your project and the wizard auto-detects your databases and APIs and connects them to PostHog.

This source is currently in alpha. The interface and available tables may change.
The Better Stack connector syncs incidents, incident comments, monitors, and more into the PostHog data warehouse, so you can analyze them alongside your product data.
Prerequisites
Credentials that can read the data you want to sync. PostHog only reads data, so read access is enough.
Adding a data source
- In PostHog, go to the Sources tab of the data pipeline section.
- Click + New source and click Link next to this source.
- Enter your credentials (see Configuration below) and click Next.
- Select the tables you want to sync, choose a sync method and frequency, then click Import.
Once the syncs are complete, you can start querying this data in PostHog.
Enter your Better Stack API token to automatically pull your uptime monitoring and incident data.
You can create an Uptime API token in your Better Stack dashboard under Integrations → API tokens. A team-scoped token syncs that team's data; a global token spans all teams.
You'll be asked for:
- API token
Sync modes
Each table can be synced in one of several modes, depending on what the source supports:
- Webhook (when available) – the source pushes changes to PostHog in real time. Fastest freshness, lowest ongoing cost, and the only mode that reliably captures updates and deletes.
- Incremental – only new or updated rows are synced on each run, using a cursor field (such as an
updated_attimestamp). Cheaper than a full refresh, but deletes aren't captured. - Append only – new rows are appended using a cursor field; existing rows are never updated. Ideal for immutable, append-only tables like event logs.
- Full refresh – the whole table is reloaded on every sync. Use it when a table has no reliable cursor or when you need deletions reflected.
See sync methods for a full explanation of how each mode works and how to choose between them.
Some Better Stack tables sync incrementally, so later runs only fetch new or updated rows. The rest are full refresh.
Configuration
| Option | Type | Required |
|---|---|---|
API token | password | Yes |
Supported tables
| Table | Description | Sync method | Incremental field | Primary key |
|---|---|---|---|---|
incidents | Downtime and alert incidents recorded by Better Stack, with their cause, acknowledgement, and resolution timeline. | Incremental, Full refresh | started_at | — |
incident_comments | Comments posted on an incident, including acknowledgement and resolution notes, with the incident they belong to. | Incremental, Full refresh | created_at | — |
monitors | Uptime monitors configured in Better Stack, with their check settings and current status. | Full refresh | — | — |
monitor_availability | Availability summary per monitor: uptime percentage and downtime totals over the monitor's lifetime. | Full refresh | — | — |
monitor_response_times | Response time measurements per monitor and checking region, covering the last 24 hours of each sync. | Incremental, Full refresh | at | — |
monitor_groups | Groups used to organize uptime monitors. | Full refresh | — | — |
heartbeats | Heartbeat (cron/background job) checks configured in Better Stack. | Full refresh | — | — |
heartbeat_availability | Availability summary per heartbeat: uptime percentage and downtime totals since the heartbeat was created. | Full refresh | — | — |
heartbeat_groups | Groups used to organize heartbeat checks. | Full refresh | — | — |
status_pages | Public status pages hosted on Better Stack. | Full refresh | — | — |
status_page_resources | The monitors and heartbeats each status page publishes, with the name and availability shown to visitors. | Full refresh | — | — |
on_calls | On-call calendars defining who is on call and when. | Full refresh | — | — |
on_call_events | Resolved on-call shifts per schedule: who was on call over which period, including one-off overrides. | Full refresh | — | — |
on_call_rotations | The rotation currently driving each on-call calendar: how long a turn lasts and who takes part. | Full refresh | — | — |
escalation_policies | Escalation policies describing how incidents are escalated to team members. | Full refresh | — | — |
severities | Severities used to route alerts, resolving the severity referenced on incidents. Better Stack's API names these urgencies. | Full refresh | — | — |
severity_groups | Groups used to organize severities. | Full refresh | — | — |
team_members | People in the Better Stack team, including pending invitations, resolving the user ids referenced by incidents and on-call schedules. | Full refresh | — | — |
roles | Roles available in the organization, both built-in and custom, resolving the role names carried on team members. | Full refresh | — | — |
Troubleshooting
- If the connection fails with an authorization error, the API token is wrong, expired, or has been revoked. Create a new one, then reconnect the source.
- If a table syncs no rows, the credential may not have access to that data. Check its permissions, then reconnect the source.
If your sync is failing or data looks wrong, see the Data warehouse troubleshooting guide. If that doesn't help, contact support – we're happy to help.