Skip to main content
BGPalerter is NTT’s open-source BGP monitor. It detects hijacked prefixes, new sub-prefixes, lost visibility, AS path anomalies, and RPKI-invalid announcements. Its reportHTTP report module sends these events to Flashduty On-call. BGPalerter sends each event once and never sends a recovery notification. Close every alert by hand, or turn on the channel’s auto-resolve timeout (see Events and recovery).

In Flashduty On-call


You can get the integration push URL in either of the following ways.

Use a dedicated integration

  1. In the Flashduty console, select Channel and open a channel
  2. Select Configuration → Integrations → Private integration, then click Add an integration
  3. Select BGPalerter and click Save
  4. Open the new integration card and copy the Push URL

Use a shared integration

  1. In the Flashduty console, select Integration Center → Alert Events
  2. Select BGPalerter and enter an integration name
  3. Configure the default route and select a channel. You can add more rules under Routes after creation
  4. Click Save and copy the generated Push URL

Configure BGPalerter


BGPalerter has no fixed webhook format: the request body comes from the reportHTTP template in config.yml. Flashduty parses only the JSON that the template below produces, so use it as is.
1

Edit config.yml

Add reportHTTP under reports (uncomment the example block) and set hooks.default to the full push URL of the Flashduty integration, including integration_key:
Notes:
  • isTemplateJSON: true makes BGPalerter send the body as Content-Type: application/json
  • Keep only the channels you need in channels. For example, keep hijack and visibility if those are the only events you care about
  • The ${...} tags are BGPalerter’s report context tags. A tag that an event type does not have renders as the text undefined, and Flashduty treats it as empty
  • The description of each prefix in prefixes.yml is written into the template. Do not put double quotes in it, or BGPalerter cannot parse the JSON it generates
  • If you use user groups, set a push URL per group under hooks
2

Restart BGPalerter

Restart BGPalerter to apply the configuration. A sending report to: ... line in its log means it is posting to that URL.
3

Verify

BGPalerter has no “send test notification” button. Running bgpalerter -t (in Docker, append -t to the start command) replays fake BGP updates on the hijack channel. Those alerts look the same as real hijack alerts, so Flashduty creates ordinary Critical alerts. Close them by hand afterwards, and remove -t before production use.

Events and recovery


Each channel in channels is one kind of event: BGPalerter sends no recovery notification, so Flashduty never closes these alerts automatically. Turn on the channel’s auto-resolve timeout (24 hours suggested). Hijack events usually need a human check, so you can also close them by hand once handled.

Alert Key


Flashduty computes the Alert Key from the routing facts of the event: the channel (channel), the monitored prefix (prefix), the monitored AS (asn), the new origin AS (neworigin), and the prefix actually announced (newprefix). BGPalerter itself groups hijack events by origin AS and prefix.
  • Repeated alerts from the same hijacker on the same prefix merge into one Flashduty alert
  • A different hijacker or a different, more specific prefix opens a separate alert
  • Events on the path channel carry no prefix or AS, so the event summary (summary) is used instead, and events with the same summary merge
  • Content that changes between deliveries, such as the peer count and timestamps, is not part of the key
A request without channel, or without any of prefix, AS, and summary, is rejected with an error.

Labels


The alert title is BGPalerter’s event summary, and the description is the prefix description.

Troubleshooting


  • Flashduty receives no alerts: check that hooks.default is the full HTTPS push URL with integration_key. BGPalerter only writes a failed post to its own log and does not retry
  • BGPalerter logs a JSON parse error: check the prefix descriptions in prefixes.yml for double quotes or line breaks
  • An alert never closes: BGPalerter sends no recovery notification. Turn on the channel’s auto-resolve timeout or close the alert by hand
  • Requests return 400: the request has no channel, usually because the template was changed. Restore the template above
For more options, see the BGPalerter documentation.