finding.created opens the alert, and finding.status.changed with the status changing to resolved recovers the same alert.
In Flashduty On-call
You can get the integration push URL in either of the following ways.
Use a dedicated integration
- Open the Flashduty console, choose Channels, and open a channel
- Choose Settings → Integrations → Dedicated integrations, then click Add an integration
- Choose Blumira and click Save
- Open the generated integration card and copy the push URL
Use a shared integration
- Open the Flashduty console and choose Integration Center → Alert events
- Choose Blumira and enter an integration name
- Configure the default route and pick a channel; you can add more rules under Routes after creation
- Click Save and copy the generated push URL
In Blumira
1
Create the webhook
- In the Blumira console, go to Settings → Webhooks (MSP users: MSP Portal → Webhooks)
- Click Add Webhook
- Paste the full Flashduty push URL into Endpoint URL (Blumira accepts only public HTTPS endpoints, which the Flashduty push URL is)
- Optional: add a description
2
Set event filters
Under Event filters, add at least these two event types:
finding.created: a new finding is createdfinding.status.changed: a finding’s status changes; a change toresolvedrecovers the alert
operational, risk, suspect, threat, system) or priority (P1, P2, P3). Without filters Blumira sends every event; Flashduty acknowledges finding.owners.changed, finding.comment.added, case.* and other events with a success response and creates no alert.3
Save and send a test
- Click Create webhook, copy and store the HMAC signing secret (it is shown only once), then click Done
- In the Webhooks table, click the ellipsis at the end of the row and choose Send Test
webhook.test) opens a standalone Info alert titled Blumira test notification in Flashduty. It is not tied to any real finding and no recovery follows, so close it manually once you see it.4
Verify the lifecycle
Wait for a real Blumira finding and confirm Flashduty receives the active alert. Then mark that finding resolved in Blumira and confirm the original alert recovers.
About signatures
Blumira signs each delivery in the
X-Blumira-Signature header (format t=<timestamp>,v1=<HMAC-SHA256>). Flashduty does not verify this signature and does not need the signing secret. The integration_key in the push URL is the only credential, so keep it private.
Alert Key
Flashduty uses
data.finding_id as the Alert Key. The finding.created and finding.status.changed examples in Blumira’s documentation carry the same finding_id, so the trigger, status updates, and recovery land on one alert.
Changes to the title, priority, status, or time do not change the Alert Key. A request without data.finding_id is rejected with a parameter error.
Status and severity
Flashduty treats only
resolved as recovery. Blumira’s documentation shows no other closing status; if a finding closes with another status, the alert stays active, so turn on the channel’s auto-resolve timeout as a fallback.
Alert labels include the finding ID, short ID, type, category, priority, source country, and link. Owner and actor names and emails are not written to the alert.
Troubleshooting
- Blumira reports failed deliveries or auto-disabled the webhook: check that the push URL is complete and includes
integration_key. Blumira disables a webhook after sustained failures; fix the cause and re-enable it under Edit - No alerts arrive: confirm the webhook is enabled and the event filters include
finding.created - Alerts do not recover: confirm the filters include
finding.status.changedand the finding’s new status isresolved - A test alert appeared: it is the standalone Info alert from Send Test; close it manually