reportHTTP report module sends these events to Flashduty On-call.
BGPalerter sends each event once and never sends a recovery notification. Close every alert by hand, or turn on the channel’s auto-resolve timeout (see Events and recovery).
In Flashduty On-call
You can get the integration push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, select Channel and open a channel
- Select Configuration → Integrations → Private integration, then click Add an integration
- Select BGPalerter and click Save
- Open the new integration card and copy the Push URL
Use a shared integration
- In the Flashduty console, select Integration Center → Alert Events
- Select BGPalerter and enter an integration name
- Configure the default route and select a channel. You can add more rules under Routes after creation
- Click Save and copy the generated Push URL
Configure BGPalerter
BGPalerter has no fixed webhook format: the request body comes from the
reportHTTP template in config.yml. Flashduty parses only the JSON that the template below produces, so use it as is.
1
Edit config.yml
Add Notes:
reportHTTP under reports (uncomment the example block) and set hooks.default to the full push URL of the Flashduty integration, including integration_key:isTemplateJSON: truemakes BGPalerter send the body asContent-Type: application/json- Keep only the channels you need in
channels. For example, keephijackandvisibilityif those are the only events you care about - The
${...}tags are BGPalerter’s report context tags. A tag that an event type does not have renders as the textundefined, and Flashduty treats it as empty - The
descriptionof each prefix inprefixes.ymlis written into the template. Do not put double quotes in it, or BGPalerter cannot parse the JSON it generates - If you use user groups, set a push URL per group under
hooks
2
Restart BGPalerter
Restart BGPalerter to apply the configuration. A
sending report to: ... line in its log means it is posting to that URL.3
Verify
BGPalerter has no “send test notification” button. Running
bgpalerter -t (in Docker, append -t to the start command) replays fake BGP updates on the hijack channel. Those alerts look the same as real hijack alerts, so Flashduty creates ordinary Critical alerts. Close them by hand afterwards, and remove -t before production use.Events and recovery
Each channel in
channels is one kind of event:
BGPalerter sends no recovery notification, so Flashduty never closes these alerts automatically. Turn on the channel’s auto-resolve timeout (24 hours suggested). Hijack events usually need a human check, so you can also close them by hand once handled.
Alert Key
Flashduty computes the Alert Key from the routing facts of the event: the channel (
channel), the monitored prefix (prefix), the monitored AS (asn), the new origin AS (neworigin), and the prefix actually announced (newprefix). BGPalerter itself groups hijack events by origin AS and prefix.
- Repeated alerts from the same hijacker on the same prefix merge into one Flashduty alert
- A different hijacker or a different, more specific prefix opens a separate alert
- Events on the
pathchannel carry no prefix or AS, so the event summary (summary) is used instead, and events with the same summary merge - Content that changes between deliveries, such as the peer count and timestamps, is not part of the key
channel, or without any of prefix, AS, and summary, is rejected with an error.
Labels
The alert title is BGPalerter’s event summary, and the description is the prefix description.
Troubleshooting
- Flashduty receives no alerts: check that
hooks.defaultis the full HTTPS push URL withintegration_key. BGPalerter only writes a failed post to its own log and does not retry - BGPalerter logs a JSON parse error: check the prefix descriptions in
prefixes.ymlfor double quotes or line breaks - An alert never closes: BGPalerter sends no recovery notification. Turn on the channel’s auto-resolve timeout or close the alert by hand
- Requests return 400: the request has no
channel, usually because the template was changed. Restore the template above