source set to aws.health and detail-type set to AWS Health Event. The Flashduty AWS EventBridge integration handles these events explicitly, so no separate AWS Health integration is needed: create an AWS EventBridge integration in Flashduty and use its push URL as the target of an EventBridge rule.
In Flashduty On-call
Get an integration push URL in either of the two ways below. Choose the AWS EventBridge integration type in both, not AWS Health.
Use a dedicated integration
- In the Flashduty console, go to Channels and open a channel
- Go to Settings → Integrations → Dedicated integrations and click Add an integration
- Select AWS EventBridge and click Save
- Open the generated integration card and copy the Push URL
Use a shared integration
- In the Flashduty console, go to Integration Center → Alert Events
- Select AWS EventBridge and enter an integration name
- Configure the default route and select a channel; you can add more rules under Routes after creation
- Click Save and copy the generated Push URL
Configure in AWS
AWS Health events are forwarded by an EventBridge rule whose target is an API destination that points to the Flashduty push URL (an SNS topic target also works). The steps for both target types are in the AWS EventBridge integration; for AWS Health you only need the event pattern below.
- Create a rule in EventBridge with this event pattern:
- To narrow the scope, add filters under
detail. For example, onlyissueevents for Amazon EC2:
- Choose the API destination that points to the Flashduty push URL as the rule target and save the rule
- While creating the rule, you can pick the AWS Health sample events in the Test event pattern panel of the EventBridge console to confirm the pattern matches
Regions and backup rules
- Create a rule in every Region you want to receive events from. Global events (for example IAM-related events) are delivered to US East (N. Virginia),
us-east-1 - In the standard AWS partition, events are also sent to the backup Region US West (Oregon). If you create rules in both the primary and the backup Region, the same event arrives twice; both copies have the same
eventArnand affected account, so Flashduty merges them into one alert through the same Alert Key - To keep only the primary Region’s events, add the filter
"backupEvent": ["false"](detail.backupEvent) to the backup Region rule
Field mapping
Severity
EventBridge events carry no common severity field, so every AWS Health event triggers as Warning. To differentiate, rewrite the severity by the
event_type_category label in Alert processing, for example issue to Critical and scheduledChange kept at Warning or lowered to Info.
Recovery and deduplication
- AWS Health sends an update with
statusCodeset toclosedwhen the event ends, and Flashduty recovers the alert with the same Alert Key - Scheduled changes (
scheduledChange) are sent with statusupcomingbefore they start, so Flashduty triggers alerts ahead of time. If you only care about ongoing incidents, restricteventTypeCategorytoissuein the event pattern - Events with
detail-typeset toAWS Health Abuse Eventhave no dedicated handling: each event becomes its own alert keyed by the eventid, with no recovery. Matching onlyAWS Health Eventin the pattern avoids them - Events without
detail.eventArnare rejected (HTTP 400)
Troubleshooting
- The rule does not fire: check the event pattern; public events can take up to an hour after the rule is created; make sure rules exist in the event’s Region and in
us-east-1for global events - The alert does not recover: confirm the event pattern does not filter out the
closedstatus and that the target has no Input transformer (the full event must be sent) - Two alerts for one event: confirm both events have the same
detail.eventArnand affected account; ifdetail-typewas rewritten the event cannot be merged as a Health event - The API destination call fails: confirm the endpoint is the full push URL and
HTTP methodisPOST