In Flashduty On-call
You can obtain an integration push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, select Channel and open a channel
- Select Configuration → Integrations → Private integration, then click Add an integration
- Select Censys and click Save
- Open the generated integration card and copy the Push URL
Use a shared integration
- In the Flashduty console, select Integration Center → Alert events
- Select Censys and enter an integration name
- Configure the default route and select a channel; you can add more rules under Route after the integration is created
- Click Save and copy the generated Push URL
In Censys ASM
Webhook Connection is available only at the Advanced and Enterprise access levels of Censys ASM. If your firewall or gateway restricts source IPs, allow the Censys egress addresses
52.5.142.59, 34.226.132.221, and 52.54.43.157.
1
Add a Webhook Connection
- Sign in to the Censys ASM console and click Integrations
- Find Webhook Connection and click Set Up
- On the Authentication page, paste the full Flashduty push URL into Webhook URL; the URL must include
integration_key - Choose Authentication type from the options Censys offers. Flashduty authenticates with the
integration_keyin the URL and does not check other credentials - Click Connect, then Next Step
2
Choose the risk severities to send
- On the Default Set Up page, review the defaults (the fields on that page cannot be edited) and click Next Step
- On the Filters page, select the risk severities to send
- Click Submit, then Close
3
Turn on auto-close
Censys sends no notification when a risk closes. Turn on auto-close in the channel that receives these alerts, with a suggested duration of 7 days, or close an alert manually once the risk is fixed.
4
Verify
The Censys webhook documentation describes no test button. When ASM finds a new risk on your attack surface it sends an event; confirm the matching alert appears in Flashduty.
Alert Key
Flashduty computes the Alert Key from
event.data.risk_id (the risk type ID) and event.data.impacted_asset (the affected asset, such as Host: 1.1.1.1). Censys defines a risk instance as one risk type on one asset, but does not state that risk_id and impacted_asset stay unchanged across deliveries. The same risk type on the same asset gets the same Alert Key, so repeated deliveries merge into one alert; the same risk type on different assets, or different risk types on one asset, produce separate alerts.
Changes to the risk name, description, severity, first and last seen times, or the event ID do not change the Alert Key. An event without risk_id or impacted_asset is rejected. An event whose event.type is not risk_instance_opened creates no alert; Flashduty acknowledges it and returns success.
Status and severity
Every event is a trigger. Flashduty sets the severity from
risk_severity:
Labels
The alert title is the risk description (
risk_description, or the risk name when empty) followed by the affected asset.
Troubleshooting
- Webhook Connection is missing: check that the Censys ASM access level is Advanced or Enterprise
- The integration does not work: Censys requires the receiver to accept the top-level
eventfield; the Flashduty push URL needs no extra handling - Flashduty returns an invalid-parameter error: check that the URL is complete and includes
integration_key - Alerts never close: Censys sends no risk-closed notification; turn on the channel’s auto-close