Skip to main content
This integration receives the HTTPS subscription of an Amazon SNS topic. The trigger and recovery of a CloudWatch alarm update the same Flashduty alert. Cost Anomaly Detection, Amazon Managed Service for Prometheus (AMP) alert manager and AWS Budgets notifications on the same topic are recognized too.

In Flashduty


You can obtain an integration push URL through either of these two methods:

Using Private Integration

Choose this method when you don’t need to route alert events to different channels. It’s simpler.

Using Shared Integration

Choose this method when you need to route alerts to different channels based on the alert event’s payload information.

Configure in AWS


  1. Log in to the AWS console and open Simple Notification Service
  2. On the Topics page, click Create topic, select Standard for Type, enter Flashduty as the name, and click Create topic
  3. On the Subscriptions page, click Create subscription
  4. Select Flashduty for Topic ARN, HTTPS for Protocol, and enter the integration push URL as Endpoint
  5. Click Create subscription
drawing
  1. Return to the Subscriptions page. The status Confirmed means Flashduty has confirmed the subscription
  2. Open the CloudWatch console, go to All alarms, and create or edit an alarm
  3. In the Notification step, select the SNS topic Flashduty for all three states: In alarm, OK and Insufficient data. Without OK, the alert does not recover automatically
drawing
  1. Return to the integration list. A latest event time means events are arriving
The subscription works with Raw message delivery on or off. With raw delivery off, SNS includes the Subject, which becomes the alert title of plain-text messages, so we recommend keeping it off.

Other AWS services that publish to SNS


Send the notifications of these services to the same Flashduty topic. No other setup is needed.

Cost Anomaly Detection

In Billing and Cost Management → Cost Anomaly Detection → Alert subscriptions, create a subscription, set Alerting frequency to Individual alerts, and select the SNS topic Flashduty as the recipient. The topic access policy must allow costalerts.amazonaws.com to publish. Each anomaly (anomalyId) maps to one alert, and later notifications for the same anomaly merge into it. Cost Anomaly Detection sends no notification when an anomaly ends, so close the alert manually.

Amazon Managed Service for Prometheus

Add an sns_configs receiver that points to the Flashduty topic in the workspace alert manager configuration. Use the default_template from the AWS guide Configure alert manager to send messages to Amazon SNS as JSON so that messages are sent as JSON:
  • Each alert gets its fingerprint as the Alert Key. firing triggers and resolved recovers
  • A severity label of critical, warning or info maps to Critical, Warning or Info; any other value maps to Warning
  • Labels and annotations become Flashduty labels. The title is the summary annotation, or alertname when it is absent
Without this template, the alert manager sends plain text, which Flashduty handles as described in “Other messages” below and cannot recover automatically. The template does not escape double quotes in label values, so a message containing them is also handled as plain text.

AWS Budgets

In the budget Alert settings, choose Amazon SNS Alerts and enter the ARN of the Flashduty topic. The topic access policy must allow budgets.amazonaws.com to publish. Budgets notifications are plain text and are handled as described in “Other messages” below.

Other messages

Each unrecognized message (plain text or other JSON) creates one Warning alert. The Alert Key is the SNS MessageId, so an SNS retry of the same message does not create a second alert. The title is the SNS Subject, or the first line of the message when there is no subject. These alerts do not recover automatically.

Alert Key


ALARM, INSUFFICIENT_DATA and OK of a CloudWatch alarm share one Alert Key; changes to the alarm name, threshold, reason or description do not split the alert. A CloudWatch alarm message without AlarmArn is rejected.

Status and severity


CloudWatch alarms have no severity. ALARM and INSUFFICIENT_DATA map to Warning by default, and OK recovers the alert.To set a severity, add flashduty_severity: critical to the alarm’s Alarm description (critical, warning or info, case-insensitive, with : or =). For example:

Labels


  • Single-metric alarms: trigger_metric_name, trigger_namespace, trigger_dimensions_<dimension name> and more. When the dimensions include InstanceId, it is written to resource
  • Metric math and anomaly detection alarms: each query writes trigger_expression_<query ID>, trigger_metric_<query ID> (namespace/metric name) and trigger_dimensions_<dimension name>. metric and check come from the query that returns data
  • Composite alarms: alarm_rule and triggering_children (ARNs of the child alarms that triggered)
  • All alarms: alarm_arn, aws_account_id, region, new_state_value, old_state_value

Troubleshooting


  • Subscription stays in Pending confirmation: Make sure the endpoint is the full push URL including integration_key, then run Request confirmation on the subscription in the SNS console
  • Flashduty returns a SubscribeURL error: Flashduty only visits subscription confirmation URLs on sns.<region>.amazonaws.com, sns.<region>.amazonaws.com.cn and sns.<region>.amazonaws.eu. Make sure the subscription request comes from Amazon SNS
  • Alert does not recover: Make sure the OK state of the CloudWatch alarm also notifies the Flashduty topic
  • Handling events in EventBridge: For GuardDuty, Security Hub, AWS Health and similar events, use the AWS EventBridge integration