id as the Alert Key, so repeated updates of one detection merge into one alert.
ExtraHop’s documentation does not describe a notification when a detection is closed or resolved, so Flashduty does not recover these alerts automatically. Turn on the channel’s auto-resolve timeout (see Detections and recovery), or close alerts by hand once the detection is handled.
In Flashduty On-call
You can get the integration push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, select Channel and open a channel
- Select Configuration → Integrations → Private integration, then click Add an integration
- Select ExtraHop and click Save
- Open the new integration card and copy the Push URL
Use a shared integration
- In the Flashduty console, select Integration Center → Alert Events
- Select ExtraHop and enter an integration name
- Configure the default route and select a channel. You can add more rules under Routes after creation
- Click Save and copy the generated Push URL
Configure ExtraHop
You need NDR or NPM module access with full write privileges or higher. Webhooks are sent over TCP 443 (HTTPS), so ExtraHop must be able to reach the Flashduty push URL.
1
Create a notification rule
- Log in to ExtraHop at
https://<extrahop-hostname-or-ip>, click the System Settings icon, select Notification Rules, and click Create - Select Security Detection for NDR modules or Performance Detection for NPM modules
- Enter a rule name and add conditions under Criteria, for example Minimum Risk Score, Category, or Site
2
Configure the Custom Webhook
- Under Target, select Custom Webhook
- In Payload URL, paste the full push URL of the Flashduty integration, including
integration_key. That parameter is the authentication, so the custom headers and Basic or Bearer authentication under Show Advanced Connection Options can stay empty - Under Notification Behavior, select Send for every detection update, and under Payload Options select Default payload. The default payload carries
id,title,type,description,url,risk_score,src, anddst, which Flashduty reads directly - Click Save
id are rejected). risk_score and site are optional and feed the severity and labels:3
Save and verify
- Click Test Connection. ExtraHop sends a message titled Test Notification to the Payload URL. ExtraHop does not document the message body and Flashduty does not special-case it, so a test message without a detection
idreturns a parameter error. That only shows the URL is reachable and does not mean the setup is wrong - Wait for a detection that matches the criteria and confirm that Flashduty receives the alert
Alert Key
Flashduty uses
id (ExtraHop defines it as “The unique identifier for the detection”) as the Alert Key. Every update of one detection carries the same id and merges into one alert. Changes to the title, description, risk score, and time do not change the Alert Key. Requests without id are rejected.
Detections and recovery
ExtraHop detection notifications cover creation and updates only. The documentation does not describe a notification when a detection is closed or resolved. Every notification Flashduty receives is a trigger, and none recovers an alert automatically. Turn on the channel’s auto-resolve timeout, 24 hours recommended, or close the alert by hand once the detection is handled.
Severity
Severity comes from
risk_score, using the same bands as the ExtraHop console colors:
Labels
The alert title is
title, falling back to type and then ExtraHop detection <id>. The description is the detection description followed by the link to the detection.
Troubleshooting
- Flashduty returns a parameter error: check that the URL is complete and includes
integration_key, and that the payload containsid - Alerts never close: ExtraHop sends no recovery notification. Turn on the channel’s auto-resolve timeout or close alerts by hand
- Several notifications for one detection: with Send for every detection update, ExtraHop sends a notification on each update and they merge into one Flashduty alert. Select Send once per detection if you do not want update notifications