In Flashduty On-call
You can get the integration push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, select Channel and open a channel
- Select Configuration → Integrations → Private integration, then click Add an integration
- Select CrowdStrike and click Save
- Open the new integration card and copy the Push URL
Use a shared integration
- In the Flashduty console, select Integration Center → Alert Events
- Select CrowdStrike and enter an integration name
- Configure the default route and select a channel. You can add more rules under Routes after creation
- Click Save and copy the generated Push URL
Configure CrowdStrike Falcon
The steps below need permission to create and release (publish) Fusion SOAR workflows in the Falcon console. The NG-SIEM Detection trigger needs the Next-Gen SIEM module; the EPP Detection trigger needs Falcon Insight/Prevent endpoint detection. The Falcon cloud must be able to reach the domain of the push URL.
1
Create the NG-SIEM detection workflow
- Sign in to the Falcon console, go to Fusion SOAR → Workflows (some tenants show this as NEXT-GEN SIEM → Automated workflows), and click Create workflow
- Set the trigger to Detection → NG-SIEM Detection
-
Add a Cloud HTTP Request action:
-
Method:
POST -
URL: the push URL you copied above (including
?integration_key=...) -
Headers: add
Content-Type: application/json -
Body (content type JSON):
-
Method:
- Save and Release the workflow — a workflow left as a draft never runs
detection_id must stay in the body.Fusion inserts ${...} values verbatim into the JSON string, and no JSON-escape function is documented. If a free-text field such as the detection name contains a double quote " or a backslash \, the body is no longer valid JSON and that push is rejected with 400. Only detection_id and severity are required; name is optional (when omitted the alert title is CrowdStrike detection), so if detection names may contain such characters, remove the name line from the body.2
(Optional) Create the EPP detection workflow
To also ingest endpoint protection (EPP) detections, repeat the previous step for a second workflow, this time with the trigger Detection → EPP Detection, and this body:
Alert Key
Flashduty uses the
detection_id field of the request body as the Alert Key. It maps to the Falcon Fusion trigger variable ${data['Trigger.Detection.DetectionID']} — CrowdStrike’s own Fusion workflow authoring reference calls this path “release-verified” (checked to exist at release time), and both the NG-SIEM and EPP detection triggers return it in the same composite-ID format for the same detection.
- Repeated deliveries for the same detection (for example, a severity escalation from High to Critical) land on the same alert
- Different detections (different
detection_id) never merge
detection_id, or whose severity is not one of Critical/High/Medium/Low/Informational.
Falcon Fusion has no “detection closed” trigger that carries the detection ID, so this integration is one-shot: Flashduty does not close an alert when the detection is closed in Falcon. Turn on auto-close for the channel (24 hours is a reasonable default for security detections). A repeat of the same detection inside that window refreshes the same alert.
Severity mapping
Alert content
- Title:
name(the detection name), falling back toCrowdStrike detectionwhen empty - Labels:
detection_id,product(NGSIEMorEPP),severity_raw(the rawseverityvalue); the NG-SIEM template also sendssource_url; the EPP template also sendsresource/host(hostname),process_sha256,ioc_value,ioc_type
Troubleshooting
- The workflow shows no error, but Flashduty never receives an alert: confirm the workflow was Released, not just saved as a draft — a draft workflow never runs
- The HTTP Action fails with a 400 in the logs: check that the body field names match the templates above exactly; the response names the missing or unsupported field (for example
detection_id is required) - The HTTP Action reports “unknown variable” or “property … contains unknown variable”: that variable path isn’t available for your detection type or trigger; use the Falcon console’s variable picker to find the field your trigger actually exposes and substitute it
- The alert never closes: this integration never receives a close event; turn on the channel’s auto-close as described under Alert Key