Skip to main content
This integration receives Amazon EventBridge events, either pushed directly by an API destination or relayed by an SNS topic. CloudWatch alarm, GuardDuty, Security Hub, AWS Health, Amazon Inspector, AWS Config and DevOps Guru events merge per alarm or finding and recover automatically when the source recovers. Every other event creates one alert.

In Flashduty


You can obtain an integration push URL through either of these two methods:

Using Private Integration

Choose this simpler option when you don’t need to route alert events to different channels.

Using Shared Integration

Choose this option when you need to route alerts to different channels based on the alert event payload.

Configure in AWS EventBridge


Use either of the following delivery methods.

Option 1: API destination

Step 1: Create Connection in API destinations

  1. Log in to your AWS Console, search for Amazon EventBridge product, and enter the corresponding product console
  2. Select Integration=>API destinations from the left navigation bar
  3. Click Connections, then click Create connection
drawing
  1. In the Connection details section, enter Flashduty for Connection name
  2. In the Authorization section, select Other for Destination type
  3. Select API Key for Authorization type
  4. Enter Flashduty for API key name, and enter the integration_key from the integration push URL for Value
  5. Click Create to save
drawing

Step 2: Create API destination

  1. Return to the API destinations interface and click Create API destination
drawing
  1. Fill in the information in the API destination detail editing interface, enter Flashduty for Name
  2. Enter the integration push URL for API destination endpoint
  3. Select POST for HTTP method
  4. Select Use an existing connection for Connection type and choose the Flashduty Connection added in Step 1
  5. Click Create to save
drawing

Step 3: Use the API destination created in Step 2 in EventBridge Rules

  1. Log in to your AWS Console, search for Amazon EventBridge product, and enter the corresponding product console
  2. Select Buses=>Rules from the left navigation bar, create or edit existing rules
  3. Other configurations are omitted here
  4. For Target types, select EventBridge API destination as the target type
  5. Under API destination, select Use an existing API destination and choose the Flashduty API destination created in Step 2 from the dropdown
  6. Click Next, configure as needed, and save
drawing

Option 2: SNS topic

  1. Create an SNS topic and an HTTPS subscription as described in the AWS CloudWatch integration, using the push URL of this integration as the endpoint, and wait until the subscription status is Confirmed
  2. In the EventBridge rule, set Target types to AWS service, and choose SNS topic and that topic as the target
  3. Do not configure an input transformer on the target; send the full event
Flashduty only visits subscription confirmation URLs on sns.<region>.amazonaws.com, sns.<region>.amazonaws.com.cn and sns.<region>.amazonaws.eu.

Event rule


Use an event pattern in the rule, for example:
Do not filter out recovery states in the rule, or alerts cannot recover automatically. For example, matching only "state": {"value": ["ALARM"]}, "newEvaluationResult": {"complianceType": ["NON_COMPLIANT"]}, Security Hub "findings": {"Workflow": {"Status": ["NEW"]}} or Inspector "status": ["ACTIVE"] drops the recovery events.
AWS Health sends events to the Region where they occur; events of global services arrive in us-east-1. Create the rule in every Region you care about.

Alert Key and recovery


  • Later events of the same source (repeated GuardDuty findings, Security Hub updates, AWS Health progress) merge into the original alert
  • When one Security Hub event carries several findings, each finding creates its own alert
  • An event missing the Alert Key field listed above is rejected (HTTP 400)
  • GuardDuty sends no event when a finding is archived, so close the alert manually

Severity


EventBridge events have no common severity field, so every event triggers as Warning, as it always has. The source’s own severity is kept in a label, and an alert pipeline can rewrite the severity based on it: For CloudWatch alarms, set the severity with flashduty_severity: critical (critical, warning or info) in the Alarm description, the same way as in the AWS CloudWatch integration.

Title and labels


  • The alert title is source::detail-type, for example aws.guardduty::GuardDuty Finding
  • Every event carries the labels source, region, account, check (detail-type), detail (the event detail as JSON) and resources
  • The summary label is a readable summary: the finding or alarm title for sources with dedicated handling; for other events, in order, CloudTrail eventSource eventName, RDS SourceIdentifier Message, ECS group stoppedReason, or EC2 instance-id state
  • Sources with dedicated handling also add source fields such as finding_id, finding_arn, event_arn, config_rule_name and insight_id; resource is the affected resource (DevOps Guru insights have none)

Troubleshooting


  • API destination invocations fail: Make sure the endpoint is the full push URL including integration_key and HTTP method is POST
  • SNS subscription stays in Pending confirmation: Make sure the subscription points to this integration’s push URL, then run Request confirmation in the SNS console
  • Alert does not recover: Check whether the rule’s event pattern filters out recovery states, and whether the target has an input transformer
  • One finding creates several alerts: Make sure the event comes from a source in the table above and its detail-type is not rewritten