In Flashduty On-call
Get the push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, select Channels and open a channel
- Go to Settings → Integration Data → Dedicated Integrations and click Add an Integration
- Select Contrast Security and click Save
- Open the generated integration card and copy the Push URL
Use a shared integration
- In the Flashduty console, go to Integration Center → Alert Events
- Select Contrast Security and enter an integration name
- Configure the default route and choose a channel; you can add more rules under Routes after creation
- Click Save and copy the generated Push URL
In Contrast Security
1
Add a generic webhook
- Sign in to Contrast and go to Organization settings → Integrations
- Click Connect on the Generic webhook option
- Name the webhook and paste the full Flashduty push URL, including
integration_key, into the URL field - Choose the applications to send events for
2
Enter the Payload template
Paste the following single-line JSON into the Payload field:Contrast replaces each
$ variable with its value and sends the result as a POST. Do not add variables such as $Message or $VulnerabilityEvidence: they can contain double quotes or line breaks that break the JSON, and Flashduty then returns an invalid-parameter error.Click Add. Contrast disconnects a webhook after 5 consecutive attempts without a 2XX response; to reconnect, test and save it again.3
Verify
- Produce a new vulnerability in an application running the Contrast agent and confirm Flashduty shows an active alert
- In Contrast, change that vulnerability’s status to a closed status (for example Remediated or Fixed) and confirm the alert recovers
Events and Alert Key
Changes to severity, status, title, or application do not change the Alert Key. A
NEW_VULNERABILITY or VULNERABILITY_CHANGESTATUS_CLOSED event without trace_id, or a SERVER_OFFLINE event without server_id, is rejected. Unrecognized event types are handled like the last row.
Server-offline alerts and the events in the last row have no recovery event. Configure Auto-close after timeout (for example 24 hours) on the integration or channel, or close them manually.
Severity mapping
Mapped from
$Severity:
When a vulnerability is closed the alert recovers and keeps the severity carried by the closing event.
Labels
Troubleshooting
- Contrast reports the webhook as disconnected: Flashduty returned a non-2XX response. Check that the URL contains
integration_keyand that the Payload is the template above and valid JSON, then test and save again in Contrast - The alert does not recover: confirm the vulnerability moved to a closed status in Contrast. Other status changes (such as Confirmed or Suspicious) send no event
- An extra alert appears when saving or testing: the Contrast documentation does not show what a test request contains, so Flashduty does not special-case it and handles it as an ordinary event. A test request with unsubstituted or blank variables opens a separate alert for an unrecognized event type. Close it manually after verifying