CLOSED or SUPPRESSED. No separate Inspector integration is needed: create an AWS EventBridge integration in Flashduty, then create an EventBridge rule that forwards Inspector events to it.
In Flashduty On-call
Get an integration push URL in either of the two ways below. Choose the AWS EventBridge integration type in both, not Amazon Inspector.
Use a dedicated integration
- In the Flashduty console, go to Channels and open a channel
- Go to Settings → Integrations → Dedicated integrations and click Add an integration
- Select AWS EventBridge and click Save
- Open the generated integration card and copy the Push URL, in the form
https://api.flashcat.cloud/event/push/alert/aws/eventbridge?integration_key=<integration key>
Use a shared integration
- In the Flashduty console, go to Integration Center → Alert Events
- Select AWS EventBridge and enter an integration name
- Configure the default route and select a channel; you can add more rules under Routes after creation
- Click Save and copy the generated Push URL
Configure in AWS
Inspector emits events to the default event bus of each Region where it is enabled, so create the rule in every such Region.
- Follow “Option 1: API destination” in the AWS EventBridge integration to create the Connection and API destination, using the Flashduty push URL as the endpoint. “Option 2: SNS topic” also works
- In the EventBridge console, select Rules → Create rule and choose Rule with an event pattern for Rule type
- In Event pattern, choose Custom patterns (JSON editor) and paste the pattern below
- For Target types choose EventBridge API destination and select the API destination created above
Inspector2 Scan, Inspector2 Coverage, Inspector2 AutoEnable) are not findings and should not be forwarded to Flashduty; the detail-type above already excludes them.
Field mapping
The mapping below is how Flashduty processes these AWS EventBridge events:
Recovery and deduplication
- Inspector sends another event for the same
findingArnwhen a vulnerability is fixed or a finding changes state. WhenstatusisCLOSED(fixed) orSUPPRESSED, Flashduty closes the alert. - If the account is an Inspector delegated administrator, findings of member accounts are also delivered to it; use the label
aws_account_idto tell the source account. - If an event lacks
detail.findingArn, Flashduty returns HTTP 400. - The
detailof code vulnerability findings contains file paths and detector names, which end up in the alert through thedetaillabel.
Troubleshooting
- The API destination call fails: confirm the endpoint is the full push URL including
integration_keyand thatHTTP methodisPOST - Alerts do not recover: check whether the rule’s event pattern filters on
status, and whether the target has an Input transformer (the full event must be sent) - Findings from a Region are missing: Inspector only emits events to the event bus of its own Region; create a rule in every Region where Inspector is enabled