> ## Documentation Index
> Fetch the complete documentation index at: https://docs.flashduty.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Censys alert integration

> Send new risks found by Censys ASM to Flashduty On-call through a webhook.

Use the Webhook Connection of Censys Attack Surface Management (ASM) to send newly found risks on your attack surface to Flashduty On-call. Each risk instance (one risk type on one asset) maps to one Flashduty alert. The Censys webhook only sends a notification when a risk is found and sends nothing when the risk closes, so alerts do not recover automatically.

<div className="hide">
  ## In Flashduty On-call

  ***

  You can obtain an integration push URL in either of the following ways.

  ### Use a dedicated integration

  1. In the Flashduty console, select **Channel** and open a channel
  2. Select **Configuration** → **Integrations** → **Private integration**, then click **Add an integration**
  3. Select **Censys** and click **Save**
  4. Open the generated integration card and copy the **Push URL**

  ### Use a shared integration

  1. In the Flashduty console, select **Integration Center → Alert events**
  2. Select **Censys** and enter an integration name
  3. Configure the default route and select a channel; you can add more rules under **Route** after the integration is created
  4. Click **Save** and copy the generated **Push URL**
</div>

## In Censys ASM

***

Webhook Connection is available only at the Advanced and Enterprise access levels of Censys ASM. If your firewall or gateway restricts source IPs, allow the Censys egress addresses `52.5.142.59`, `34.226.132.221`, and `52.54.43.157`.

<Steps>
  <Step title="Add a Webhook Connection">
    1. Sign in to the Censys ASM console and click **Integrations**
    2. Find **Webhook Connection** and click **Set Up**
    3. On the Authentication page, paste the full Flashduty push URL into **Webhook URL**; the URL must include `integration_key`
    4. Choose **Authentication type** from the options Censys offers. Flashduty authenticates with the `integration_key` in the URL and does not check other credentials
    5. Click **Connect**, then **Next Step**
  </Step>

  <Step title="Choose the risk severities to send">
    1. On the Default Set Up page, review the defaults (the fields on that page cannot be edited) and click **Next Step**
    2. On the Filters page, select the risk severities to send
    3. Click **Submit**, then **Close**
  </Step>

  <Step title="Turn on auto-close">
    Censys sends no notification when a risk closes. Turn on [auto-close](/en/on-call/channel/create-edit) in the channel that receives these alerts, with a suggested duration of 7 days, or close an alert manually once the risk is fixed.
  </Step>

  <Step title="Verify">
    The Censys webhook documentation describes no test button. When ASM finds a new risk on your attack surface it sends an event; confirm the matching alert appears in Flashduty.
  </Step>
</Steps>

## Alert Key

***

Flashduty computes the Alert Key from `event.data.risk_id` (the risk type ID) and `event.data.impacted_asset` (the affected asset, such as `Host: 1.1.1.1`). Censys defines a risk instance as one risk type on one asset, but does not state that `risk_id` and `impacted_asset` stay unchanged across deliveries. The same risk type on the same asset gets the same Alert Key, so repeated deliveries merge into one alert; the same risk type on different assets, or different risk types on one asset, produce separate alerts.

Changes to the risk name, description, severity, first and last seen times, or the event ID do not change the Alert Key. An event without `risk_id` or `impacted_asset` is rejected. An event whose `event.type` is not `risk_instance_opened` creates no alert; Flashduty acknowledges it and returns success.

## Status and severity

***

Every event is a trigger. Flashduty sets the severity from `risk_severity`:

| Censys severity | Flashduty severity |
| :- | :- |
| `critical`, `high` | Critical |
| `medium` | Warning |
| `low`, `info` | Info |
| Empty or other | Warning |

## Labels

***

| Label | Source |
| :- | :- |
| `event` | Event type, such as `risk_instance_opened` |
| `workspace_id` | Censys workspace ID |
| `risk_id` / `risk_event_id` | Risk type ID and risk event ID |
| `check` / `risk_name` | Risk type name, such as `eol-openssl-software` |
| `risk_severity` | Original Censys risk severity |
| `resource` | Affected asset |
| `categories` | Risk categories |
| `first_seen_at` / `last_seen_at` | When the risk was first and last seen |
| `url` | Link to the asset's risk page in the Censys console |

The alert title is the risk description (`risk_description`, or the risk name when empty) followed by the affected asset.

## Troubleshooting

***

* **Webhook Connection is missing**: check that the Censys ASM access level is Advanced or Enterprise
* **The integration does not work**: Censys requires the receiver to accept the top-level `event` field; the Flashduty push URL needs no extra handling
* **Flashduty returns an invalid-parameter error**: check that the URL is complete and includes `integration_key`
* **Alerts never close**: Censys sends no risk-closed notification; turn on the channel's auto-close

For field details, see [Censys Webhooks for ASM](https://docs.censys.com/docs/asm-webhook).
