Skip to main content
Send ExtraHop Reveal(x) security and performance detections to Flashduty On-call through the Custom Webhook target of a detection notification rule. Flashduty uses the detection id as the Alert Key, so repeated updates of one detection merge into one alert. ExtraHop’s documentation does not describe a notification when a detection is closed or resolved, so Flashduty does not recover these alerts automatically. Turn on the channel’s auto-resolve timeout (see Detections and recovery), or close alerts by hand once the detection is handled.

In Flashduty On-call


You can get the integration push URL in either of the following ways.

Use a dedicated integration

  1. In the Flashduty console, select Channel and open a channel
  2. Select Configuration → Integrations → Private integration, then click Add an integration
  3. Select ExtraHop and click Save
  4. Open the new integration card and copy the Push URL

Use a shared integration

  1. In the Flashduty console, select Integration Center → Alert Events
  2. Select ExtraHop and enter an integration name
  3. Configure the default route and select a channel. You can add more rules under Routes after creation
  4. Click Save and copy the generated Push URL

Configure ExtraHop


You need NDR or NPM module access with full write privileges or higher. Webhooks are sent over TCP 443 (HTTPS), so ExtraHop must be able to reach the Flashduty push URL.
1

Create a notification rule

  1. Log in to ExtraHop at https://<extrahop-hostname-or-ip>, click the System Settings icon, select Notification Rules, and click Create
  2. Select Security Detection for NDR modules or Performance Detection for NPM modules
  3. Enter a rule name and add conditions under Criteria, for example Minimum Risk Score, Category, or Site
2

Configure the Custom Webhook

  1. Under Target, select Custom Webhook
  2. In Payload URL, paste the full push URL of the Flashduty integration, including integration_key. That parameter is the authentication, so the custom headers and Basic or Bearer authentication under Show Advanced Connection Options can stay empty
  3. Under Notification Behavior, select Send for every detection update, and under Payload Options select Default payload. The default payload carries id, title, type, description, url, risk_score, src, and dst, which Flashduty reads directly
  4. Click Save
If you select Send once per detection, ExtraHop requires a custom payload. Add the detection ID to the suggested JSON so Flashduty can identify it (requests without id are rejected). risk_score and site are optional and feed the severity and labels:
3

Save and verify

  1. Click Test Connection. ExtraHop sends a message titled Test Notification to the Payload URL. ExtraHop does not document the message body and Flashduty does not special-case it, so a test message without a detection id returns a parameter error. That only shows the URL is reachable and does not mean the setup is wrong
  2. Wait for a detection that matches the criteria and confirm that Flashduty receives the alert

Alert Key


Flashduty uses id (ExtraHop defines it as “The unique identifier for the detection”) as the Alert Key. Every update of one detection carries the same id and merges into one alert. Changes to the title, description, risk score, and time do not change the Alert Key. Requests without id are rejected.

Detections and recovery


ExtraHop detection notifications cover creation and updates only. The documentation does not describe a notification when a detection is closed or resolved. Every notification Flashduty receives is a trigger, and none recovers an alert automatically. Turn on the channel’s auto-resolve timeout, 24 hours recommended, or close the alert by hand once the detection is handled.

Severity


Severity comes from risk_score, using the same bands as the ExtraHop console colors:

Labels


The alert title is title, falling back to type and then ExtraHop detection <id>. The description is the detection description followed by the link to the detection.

Troubleshooting


  • Flashduty returns a parameter error: check that the URL is complete and includes integration_key, and that the payload contains id
  • Alerts never close: ExtraHop sends no recovery notification. Turn on the channel’s auto-resolve timeout or close alerts by hand
  • Several notifications for one detection: with Send for every detection update, ExtraHop sends a notification on each update and they merge into one Flashduty alert. Select Send once per detection if you do not want update notifications
For more on the fields, see the ExtraHop detection notification rule documentation.