- Failing policy: Fleet posts once when a policy changes from passing (or no result) to failing on a host.
- New vulnerability: Fleet posts when it detects a new CVE on a host, checked hourly by default.
In Flashduty On-call
Get the integration push URL in either of the following ways.
Dedicated integration
- In the Flashduty console, go to Channels and open a channel
- Go to Settings → Integrations → Dedicated integration and click Add an integration
- Select Fleet and click Save
- Open the integration card and copy the push URL
Shared integration
- In the Flashduty console, go to Integration Center → Alert events
- Select Fleet and enter a name
- Set the default route and pick a channel; you can add more rules under Routes later
- Click Save and copy the push URL
In Fleet
Enable the webhooks under Manage automations in the Fleet admin UI, or set them through GitOps or the configuration file, as shown below. Use the full Flashduty push URL, including
integration_key, as destination_url for both webhooks.
1
Failing policy webhook
policy_ids: the policies that trigger the webhookhost_batch_size: the maximum number of hosts in one request. The default0puts every failing host in a single request. Set it to 200 or less, because Flashduty processes at most 200 hosts per request
2
Vulnerability webhook
3
Do not enable the host status or activity webhooks
Fleet’s host status and activity webhooks carry no per-object identifier. Flashduty rejects them with a parameter error, so do not point them at this URL.
4
Verify
The Fleet documentation describes no test button for these webhooks. Make a selected policy fail on a host (passing to failing). Fleet checks policy webhooks once a day by default, which you can change with
webhook_settings.interval. Then confirm the alert appears in Flashduty.Hosts run policies at the interval set by FLEET_OSQUERY_POLICY_UPDATE_INTERVAL (default 1 hour), so the first alert can take that long to appear.Events and recovery
One delivery can carry many hosts. Flashduty handles them in host ID order and processes at most 200 hosts per delivery; the rest are ignored, so use
host_batch_size to control the batch size.
Fleet does not notify Flashduty when a host is fixed. Turn on auto-close for the integration’s channel, with a suggested window of 24 hours to 7 days depending on how long you take to handle failing policies. When the same policy fails again on the same host (for example after the policy is reset in Fleet), it merges into the same alert.
Alert Key
- Failing policy: computed from the policy ID (
policy.id) and the host ID (hosts[].id) - Vulnerability: computed from the CVE ID and the host ID
Severity
The policy
critical option requires a Fleet Premium license; free Fleet rejects it with option critical requires a premium license. On free Fleet, every policy alert therefore arrives as Warning.
Labels
The policy query, author details, and software installation paths in the payload are not stored as labels.
Troubleshooting
- Flashduty returns a parameter error: the message names the missing field. If it says only failing policy and vulnerability webhooks are supported, check whether a host status or activity webhook points at this URL
- No alert arrives: the policy webhook fires only when a policy changes from passing to failing; a host that keeps failing is not sent again. Hosts run policies every
FLEET_OSQUERY_POLICY_UPDATE_INTERVAL(default 1 hour), and Fleet posts only after a result changes - Alerts never close: Fleet sends no recovery, so turn on auto-close