Skip to main content
SmartEvent automatic reactions offer Mail, SNMP Trap, Block Source, Block Event Activity and External Script. There is no webhook. The Flashduty Email integration can receive SmartEvent mail, so no separate Check Point integration is needed: create an Email integration in Flashduty and use its address as the recipient of the SmartEvent Mail reaction.

In Flashduty On-call


You can get the integration email address in either of two ways. Choose the Email integration type in both cases, not Check Point.

Dedicated integration

  1. In the Flashduty console, go to Channels and open a channel
  2. Go to Settings → Integrations → Dedicated integrations and click Add an integration
  3. Select Email and click Save
  4. Open the generated card and copy the Email address

Shared integration

  1. In the Flashduty console, go to Integration Center → Alert Events
  2. Select Email, enter an integration name and copy the Email address
  3. Configure the default route, choose a channel and click Save

Confirm the push mode in Flashduty


SmartEvent sends one mail per event and no recovery mail, and the subject carries the event number (see Mail subject format), so every mail is an independent event. Set the Email integration’s push mode to the one that always triggers a new alert (the create page may preselect a different mode, so check it): each mail creates a new alert whose title is the mail subject and whose description is the mail body. No trigger or close rules are needed.

In Check Point SmartConsole


Paths follow the Check Point R81.10 administration guide.
  1. In SmartConsole, click the Logs & Monitor view in the left navigation panel, click +, then under External Apps click SmartEvent Settings & Policy
  2. Go to General Settings → Objects → Automatic Reactions and click Add → Mail
  3. Fill in Name and the sender address in From
  4. In To, enter the address of the Flashduty Email integration (separate multiple addresses with semicolons)
  5. In Outgoing mail server (SMTP), enter the IP address or FQDN of an SMTP server that can deliver mail to Flashduty
  6. Keep the default Subject, [EventNumber] - [Severity] - [Name], so the subject carries the event number, severity and event name
  7. Save, reference the automatic reaction in the event definitions you want notifications for, and install the policy

Mail subject format


The default Subject of the Mail reaction is [EventNumber] - [Severity] - [Name]: event number, severity and event name. Flashduty uses the mail subject as the alert title.

Limitations


  • No recovery: SmartEvent sends no recovery mail. Enable auto-resolve timeout on the channel that receives this integration (24 hours suggested), or close alerts manually in Flashduty.
  • No deduplication: the subject contains the event number, so each event creates its own alert.
  • Severity: alerts from the Email integration always have Warning severity. Use an alert processing pipeline to adjust it from the severity text in the subject.
  • Integration type: alerts show Email as the integration type in Flashduty.