RiverMuse (RightITnow ECM) Integration
RiverMuse — shipped today as RightITnow ECM — is an event-correlation console. Upstream monitoring tools send it events, ECM correlates those into alerts, and your teams triage the alerts. Connecting it gives Autoheal the same view your on-call engineers have: what is firing, how it correlates, and what raw signal sits underneath.
This integration is read-only. Autoheal fetches alerts, events and saved filters, and never acknowledges, assigns, annotates or closes anything in ECM.
Capabilities
Once connected, Autoheal can:
| Capability | Description |
|---|---|
| Search Alerts | Query alerts with an ad-hoc filter tree, or run one of your own saved filters by name. Returns the matching page plus the true total count |
| Get Alert | Fetch one or more alerts by ID, optionally following the rolled-up (nested) alerts beneath a lead alert |
| List Alert Events | Read the raw events ECM correlated into an alert, or sweep every event in a time window |
| List Alert Filters | Discover the paged alert filters saved in ECM — the per-team, per-site and per-severity views your operators already use |
| Test Connection | Verify the base URL and credentials, and report how many alerts the configured user can see |
Prerequisites
- A RiverMuse / RightITnow ECM instance (self-hosted). These docs are written against ECM 6.4
- An ECM user account with a REST API token
- That user's role must have the Alerts Console Tab permission and REST API permission
Setup
REST API access in ECM is a role permission, and it must be granted before a token can be generated.
- Log in to ECM as an administrator
- Go to the Configuration tab and open Roles (or Users, if you are granting per user)
- Select the role your Autoheal service account will use
- Enable REST API permission
- Confirm the same role has the Alerts Console Tab permission — that is what every read in this integration needs
- Save
We recommend a dedicated read-only service account (for example svc_autoheal) rather than a personal login, so the integration is not affected by password changes or someone leaving.
The token is generated per user, after the permission above is in place.
- Open the user's profile in ECM
- Generate the REST API token
- Copy it — this is the value Autoheal stores as the API Token
The token is used in place of a password with HTTP Basic authentication. ECM's own documentation shows credentials embedded in the URL; Autoheal always sends them in an Authorization header instead, so they never appear in a proxy or access log.
- Go to Integrations in Autoheal
- Click RiverMuse (RightITnow ECM)
- Enter a name (e.g., "Production ECM")
Enter the following:
- ECM Base URL: your instance's base URL, including the port if it is not the default — e.g.
https://ecm.company.com:8443. Do not add the/rightitnow/restapisuffix; Autoheal appends it - ECM Username: the user the token was generated for
- REST API Token: the token from step 2
- ECM Server Timezone (optional): see Timestamps and timezone below — get this one right
- Network Connector (optional): a Tailscale connector, if ECM is not reachable from the internet
Click Test Connection to verify, then Save. A successful test reports how many active alerts the configured user can see.
Required Permissions
The integration only needs read access:
| Permission | Why It's Needed |
|---|---|
| REST API | Allows the user to authenticate against the ECM REST API at all |
| Alerts Console Tab | Every read this integration performs — alerts, alert counts, events, saved filters |
Configuration Tab is deliberately not required. ECM's /responselimit endpoint would be the obvious way to test a connection, but it needs the Configuration Tab — a permission a least-privilege read-only account should not have. Autoheal tests the connection by counting alerts instead, so the account you create can stay narrow.
Timestamps and timezone
ECM stores and returns timestamps as wall-clock values with no UTC offset — 2026-08-31 01:00:00, with nothing to say which zone that is. Autoheal therefore needs to be told what clock your ECM server runs on.
Set ECM Server Timezone to the IANA name of that clock (for example Europe/London, America/New_York, Asia/Tokyo). It defaults to UTC.
With it set correctly:
- Time windows you ask for in UTC are converted to the server's wall clock before the query is sent
- Timestamps coming back are returned with the offset attached (
2026-08-31T01:00:00+01:00), so they are unambiguous while still matching what an operator sees in the ECM console
If this setting is wrong, every time-window query silently returns the wrong hour's data. If alert times look shifted, check this first.
Self-Hosted Notes
RiverMuse / RightITnow ECM is always self-hosted:
- Port and context path: include the port if it is non-default. If your ECM runs under a non-default Tomcat context path, paste the complete REST base ending in
/restapi(e.g.https://ecm.company.com/ecmprod/restapi) and Autoheal will use it as given - Self-signed certificates: if your ECM uses a self-signed TLS certificate, contact your Autoheal administrator to enable TLS verification bypass
- Firewall access: if ECM is not reachable from the internet, add a Tailscale connector under Private Access and select it in Network Connector
- Distributed workers: ECM restricts calls routed to distributed workers to read-only operations, which is all this integration performs
Filter fields are instance-specific
ECM filters are a nested boolean tree rather than a query string: a topOperator of AND or OR over nestedCriteria, where each leaf is a fieldName / fieldOperator / fieldValue triple. Confirmed operators are EQUALS, NOT_NULL, CONTAINS, GREATER_THAN and LESS_THAN.
Alongside built-in fields like SEVERITY, STATE, ENTITY_GROUP and TAG, ECM custom fields are addressable by their own name — so the fields available differ from one instance to the next, and the complete list lives in your own ECM online help rather than in the REST API documentation.
Because of that, the most reliable way in is your saved filters. Run the context-curation step after connecting: Autoheal will discover the saved alert filters, entity groups, connector sources and custom fields your instance actually uses, so agents write filters that work here rather than guessing.
Example Queries
Once connected, you can ask Autoheal:
What's firing in RiverMuse right now?
Run the NY-Infra-Critical saved filter and summarise what's alerting
Show me the critical and major open alerts for the EMEA-Payments entity group
Pull RiverMuse alert 30 and everything rolled up underneath it
What raw events came in behind alert 30 over the last six hours?
Has this entity alerted before? Check closed alerts too.
Troubleshooting
401 Unauthorized
- Verify the ECM username and REST API token are correct
- The token is generated per user, after REST API permission is granted to that user's role — a token generated before the permission was granted will not work
- Check for whitespace accidentally copied along with the token
- Verify the base URL points at the ECM instance and not a reverse proxy login page
403 Forbidden
- The user's role is missing the Alerts Console Tab permission, the REST API permission, or both
- This is a permissions change in ECM, not something that can be worked around from Autoheal
404 Not Found
- Verify the alert, filter or entity identifier exists
- Check the base URL: if your ECM uses a non-default context path, paste the complete REST base ending in
/restapi - ECM can also answer 404 when a filter matches nothing, so a 404 on a search is not necessarily a configuration problem
Empty results from a filter that should match
- The field name probably does not exist on this instance. Custom field names vary per deployment
- Run the saved-filter discovery (List Alert Filters) and use a saved filter by name instead
- Check whether the alert you expect is closed — searches include active alerts only unless closed alerts are explicitly requested
Alert times look shifted by several hours
- The ECM Server Timezone setting does not match your ECM server's actual clock
- Set it to the IANA name of that clock and re-run the query
Connection timeout
- Verify the ECM URL is reachable from the Autoheal network
- Check for firewall rules blocking access
- For an instance that is not internet-facing, use Private Access and select the connector in Network Connector
Responses are truncated
- Narrow the filter, or ask for a smaller page — the reported total count stays accurate regardless of truncation
- ECM also enforces its own per-response item limit from the authenticated user's preferences, so a page can come back smaller than requested