> ## Documentation Index
> Fetch the complete documentation index at: https://docs.flashduty.com/llms.txt
> Use this file to discover all available pages before exploring further.

# ExtraHop alert integration

> Send ExtraHop Reveal(x) security and performance detections to Flashduty On-call through a detection notification rule's Custom Webhook.

Send ExtraHop Reveal(x) security and performance detections to Flashduty On-call through the Custom Webhook target of a detection notification rule. Flashduty uses the detection `id` as the Alert Key, so repeated updates of one detection merge into one alert.

ExtraHop's documentation does not describe a notification when a detection is closed or resolved, so Flashduty does not recover these alerts automatically. Turn on the channel's auto-resolve timeout (see [Detections and recovery](#detections-and-recovery)), or close alerts by hand once the detection is handled.

<div className="hide">
  ## In Flashduty On-call

  ***

  You can get the integration push URL in either of the following ways.

  ### Use a dedicated integration

  1. In the Flashduty console, select **Channel** and open a channel
  2. Select **Configuration** → **Integrations** → **Private integration**, then click **Add an integration**
  3. Select **ExtraHop** and click **Save**
  4. Open the new integration card and copy the **Push URL**

  ### Use a shared integration

  1. In the Flashduty console, select **Integration Center → Alert Events**
  2. Select **ExtraHop** and enter an integration name
  3. Configure the default route and select a channel. You can add more rules under **Routes** after creation
  4. Click **Save** and copy the generated **Push URL**
</div>

## Configure ExtraHop

***

You need NDR or NPM module access with full write privileges or higher. Webhooks are sent over TCP 443 (HTTPS), so ExtraHop must be able to reach the Flashduty push URL.

<Steps>
  <Step title="Create a notification rule">
    1. Log in to ExtraHop at `https://<extrahop-hostname-or-ip>`, click the **System Settings** icon, select **Notification Rules**, and click **Create**
    2. Select **Security Detection** for NDR modules or **Performance Detection** for NPM modules
    3. Enter a rule name and add conditions under **Criteria**, for example **Minimum Risk Score**, **Category**, or **Site**
  </Step>

  <Step title="Configure the Custom Webhook">
    1. Under **Target**, select **Custom Webhook**
    2. In **Payload URL**, paste the full push URL of the Flashduty integration, including `integration_key`. That parameter is the authentication, so the custom headers and Basic or Bearer authentication under **Show Advanced Connection Options** can stay empty
    3. Under **Notification Behavior**, select **Send for every detection update**, and under **Payload Options** select **Default payload**. The default payload carries `id`, `title`, `type`, `description`, `url`, `risk_score`, `src`, and `dst`, which Flashduty reads directly
    4. Click **Save**

    If you select **Send once per detection**, ExtraHop requires a custom payload. Add the detection ID to the suggested JSON so Flashduty can identify it (requests without `id` are rejected). `risk_score` and `site` are optional and feed the severity and labels:

    ```json theme={null}
    {
        "id": {{ id }},
        "title": "{{ title }}",
        "type": "{{ type }}",
        "url": "{{ url }}",
        "description": "{{ description }}",
        "risk_score": {{ risk_score }},
        "site": "{{ site }}",
        "categories_string": "{{ categories_string }}",
        "victim_primary": {{ victim_primary | safe }},
        "offender_primary": {{ offender_primary | safe }}
    }
    ```
  </Step>

  <Step title="Save and verify">
    1. Click **Test Connection**. ExtraHop sends a message titled **Test Notification** to the Payload URL. ExtraHop does not document the message body and Flashduty does not special-case it, so a test message without a detection `id` returns a parameter error. That only shows the URL is reachable and does not mean the setup is wrong
    2. Wait for a detection that matches the criteria and confirm that Flashduty receives the alert
  </Step>
</Steps>

## Alert Key

***

Flashduty uses `id` (ExtraHop defines it as "The unique identifier for the detection") as the Alert Key. Every update of one detection carries the same `id` and merges into one alert. Changes to the title, description, risk score, and time do not change the Alert Key. Requests without `id` are rejected.

## Detections and recovery

***

ExtraHop detection notifications cover creation and updates only. The documentation does not describe a notification when a detection is closed or resolved. Every notification Flashduty receives is a trigger, and none recovers an alert automatically.

Turn on the channel's [auto-resolve timeout](/en/on-call/channel/create-edit), 24 hours recommended, or close the alert by hand once the detection is handled.

## Severity

***

Severity comes from `risk_score`, using the same bands as the ExtraHop console colors:

| risk\_score | Flashduty severity |
| :- | :- |
| 80 and above (red) | Critical |
| 31-79 (orange) | Warning |
| 1-30 (yellow) | Info |
| Missing, 0, or non-numeric (performance detections have no risk score) | Warning |

## Labels

***

| Label | Source |
| :- | :- |
| `source` | Always `extrahop` |
| `detection_id` | `id` |
| `detection_type` | `type` |
| `detection_url` | `url` |
| `risk_score` | `risk_score` |
| `site` | `site` |
| `category` | `categories_string` |
| `src_host` / `src_ip` | `src.hostname` / `src.ipaddr` |
| `dst_host` / `dst_ip` | `dst.hostname` / `dst.ipaddr` |
| `offender` / `victim` | Name of `offender_primary` / `victim_primary`, or the IP when there is no name |

The alert title is `title`, falling back to `type` and then `ExtraHop detection <id>`. The description is the detection description followed by the link to the detection.

## Troubleshooting

***

* **Flashduty returns a parameter error**: check that the URL is complete and includes `integration_key`, and that the payload contains `id`
* **Alerts never close**: ExtraHop sends no recovery notification. Turn on the channel's auto-resolve timeout or close alerts by hand
* **Several notifications for one detection**: with **Send for every detection update**, ExtraHop sends a notification on each update and they merge into one Flashduty alert. Select **Send once per detection** if you do not want update notifications

For more on the fields, see the [ExtraHop detection notification rule documentation](https://docs.extrahop.com/current/detections-create-notification-rule/).
