In Flashduty On-call
You can obtain an integration push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, select Channel and open a channel
- Select Configuration → Integrations → Private integration, then click Add an integration
- Select CrowdSec, then click Save
- Open the generated integration card and copy the Push URL
Use a shared integration
- In the Flashduty console, select Integration Center → Alert Events
- Select CrowdSec and enter an integration name
- Configure the default route and select a channel; after creation, add more rules under Route if needed
- Click Save and copy the generated Push URL
Configure CrowdSec
Do the following on the machine that runs the CrowdSec Local API (LAPI). The HTTP notification plugin ships with CrowdSec, so nothing extra needs to be installed.
1
Configure the HTTP notification plugin
Edit
/etc/crowdsec/notifications/http.yaml (the same path inside the container for Docker deployments). Keep the default format and fill in url and method:format must stay {{.|toJson}}: Flashduty parses exactly the default JSON structure of the CrowdSec alert list. Replace url with the full Flashduty push URL. Flashduty identifies the integration by the integration_key in the URL, so keep this file as secret as a key.2
Enable the notification in a profile
Edit Only alerts that match the profile filters are pushed. After saving, reload CrowdSec with
/etc/crowdsec/profiles.yaml and add notifications to the profile that should notify:sudo systemctl reload crowdsec (restart the container for Docker deployments).3
Turn on the auto-resolve timeout
A CrowdSec alert is a one-shot event: after the ban expires, CrowdSec sends nothing more. In the channel that receives these alerts, turn on the auto-resolve timeout. We suggest a timeout equal to the ban duration (4 hours in the example above), counted from Incident trigger. Closing the incident also closes its alerts.
4
Verify
Run this on the CrowdSec machine:An Info alert titled
test alert appears in Flashduty. It does not recover on its own, so close it by hand or let the auto-resolve timeout close it. cscli notifications list shows whether the plugin is loaded.What is pushed
Each request carries a JSON array with one CrowdSec alert per element; with
group_wait or group_threshold, CrowdSec holds alerts until the next flush, so delivery can lag the detection by up to group_wait, and a request may hold several alerts. Flashduty creates one alert per array element. The event details (events) and the raw logs in meta are not sent to Flashduty.
Alert Key
Flashduty uses the
uuid that CrowdSec generates for each alert as the Alert Key. A retried request carries the same uuid and merges into the same alert; when the same source IP triggers again later, the new alert has a new uuid and creates a new Flashduty alert.
For older releases that send no uuid, Flashduty derives the Alert Key from the scenario, source scope, source value and start_at. The request is rejected when those fields are missing.
Severity
CrowdSec provides no severity, so every alert triggers at Warning, including alerts in simulation mode (
simulated). The test alert from cscli notifications test is Info and uses its own Alert Key, so it never merges with a real alert.
Labels
The alert title is
<scenario> from <source value> and the description is the CrowdSec message.
FAQ
No alert appears in Flashduty after a push?
No alert appears in Flashduty after a push?
Run
cscli notifications test http_default first to confirm the test alert arrives. If it does not, check that url contains integration_key and look for http plugin errors in the CrowdSec log (/var/log/crowdsec.log). If the test alert arrives but real ones do not, the profile filters usually do not match, or http_default is not listed in the profile.Do I need to configure a signature or an auth header?
Do I need to configure a signature or an auth header?
No. Flashduty identifies the integration by
integration_key only and does not check extra request headers.Why does an alert never close?
Why does an alert never close?
CrowdSec sends no recovery event. Turn on the auto-resolve timeout of the channel, or close the alert in Flashduty by hand.