Event types reference
Device: device/online, device/offline, device/alert, device/write, device/write/ack
device/alert carries a code: THRESHOLD_VIOLATION (a reading entered Alert — severity Error when Synacl evaluates it in the cloud), THRESHOLD_CLEARED (back inside the limit — Info) and THRESHOLD_WATCH (a reading entered Watch, the early warning inside the limit — Warning). None of these breaks quiet hours; only Critical does. See Normal, Watch and Alert.
Gateway: gateway/online, gateway/offline, gateway/restart(/failed), gateway/reset-config(/failed)
Firmware: firmware/update/requested (you started an update), firmware/update/started, firmware/update/complete, firmware/update/failed (reported by the gateway)
Connectivity / protocol faults: link/weak, modbus/timeout, gpio/fault, i2c/fault, spi/fault, uart/fault, can/fault, mbus/fault, http/poll-error, snmp/poll-error
Quota: quota/rate-limited, quota/suspended, quota/restored, quota/banned (one device), quota/tenant-rate-limited (your whole account is over its message rate and messages are being dropped), quota/tenant-burst (many devices broke their interval at the same moment, which usually means one duplicate gateway or simulator — per-device suspension pauses while this is open)
Webhook ingest: ingest/auth-failed, ingest/invalid-payload, ingest/unknown-tag — raised when an HTTPS push is rejected, or accepted with a key matching no tag. Throttled to one per kind, per device, per minute. See webhook data ingest.
Automation & system: rule/fired, action/triggered, action/failed, egress/failed, bug/reward, system/message, system/announcement
Events about a device or gateway carry its name as it was when the event happened, so the history still reads after a rename or delete.
See fault events for troubleshooting the protocol faults.