In Flashduty On-call
Get an integration push URL in either of the two ways below. Choose the AWS EventBridge integration type in both, not AWS Security Hub.
Use a dedicated integration
- In the Flashduty console, go to Channels and open a channel
- Go to Settings → Integrations → Dedicated integrations and click Add an integration
- Select AWS EventBridge and click Save
- Open the generated integration card and copy the Push URL, in the form
https://api.flashcat.cloud/event/push/alert/aws/eventbridge?integration_key=<integration key>
Use a shared integration
- In the Flashduty console, go to Integration Center → Alert Events
- Select AWS EventBridge and enter an integration name
- Configure the default route and select a channel; you can add more rules under Routes after creation
- Click Save and copy the generated Push URL
Configure in AWS
- Follow “Option 1: API destination” in the AWS EventBridge integration to create the Connection and API destination, using the Flashduty push URL as the endpoint. “Option 2: SNS topic” also works
- In the EventBridge console, create a rule and choose Rule with an event pattern for Rule type
- To build the pattern from a template, choose AWS services for Event source, Security Hub for AWS service and Security Hub Findings - Imported for Event type. Or choose Custom patterns (JSON editor) and paste the pattern below
- For Target types choose EventBridge API destination and select the API destination created above
detail.findings. For example, only findings produced by Amazon Inspector:
detail-type to the rule if you use them.
Field mapping
The
detail.findings array of a Security Hub Findings - Imported event holds a single finding. The mapping below is how Flashduty processes these AWS EventBridge events:
Recovery and deduplication
- Changing a finding’s workflow status to Resolved or Suppressed in Security Hub, or archiving the finding, produces a new Security Hub Findings - Imported event, and Flashduty closes the alert with the same Alert Key.
- When an event contains several findings, each finding becomes its own alert.
- If an event lacks
IdorProductArn, Flashduty returns HTTP 400.
Troubleshooting
- The API destination call fails: confirm the endpoint is the full push URL including
integration_keyand thatHTTP methodisPOST - Alerts do not recover: check whether the rule’s event pattern filters on
Workflow.StatusorRecordState, and whether the target has an Input transformer (the full event must be sent) - Findings from a Region are missing: an EventBridge rule only applies in its own Region; create a rule in every Region where Security Hub is enabled