> ## Documentation Index
> Fetch the complete documentation index at: https://docs.flashduty.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Flowmon ADS alert integration

> Flowmon ADS sends detected network anomaly events as email reports; use a Flashduty email integration to turn each event into an alert.

When Flowmon ADS (Anomaly Detection System) detects a network anomaly event, it can send the event as an email report. The Flashduty [email integration](/en/on-call/integration/alert-integration/alert-sources/email) receives these emails, so no separate Flowmon ADS integration is needed: create an email integration in Flashduty and add its email address as a recipient of a Flowmon ADS email report. Each per-event email becomes one Flashduty alert.

<div className="hide">
  ## In Flashduty On-call

  ***

  Get the integration email address in either of the two ways below. **In both cases choose the Email integration type**, not Flowmon ADS.

  ### Use a dedicated integration

  1. In the Flashduty console, select **Channels** and open a channel
  2. Select **Settings** → **Integrations** → **Dedicated integrations** and click **Add an integration**
  3. Select **Email** and click **Save**
  4. Open the new integration card, copy the **email address**, then configure Flowmon ADS below

  ### Use a shared integration

  1. In the Flashduty console, select **Integration Center → Alert events**
  2. Select **Email**, enter an integration name and copy the **email address**
  3. Configure Flowmon ADS below
  4. Set a default route, select a channel and click **Save**
</div>

## Configure Flowmon ADS

***

1. In Flowmon ADS, open **Email notifications** under **Event Response** and create an email report. Each email report is bound to exactly one perspective
2. Click **Add new email** and add the Flashduty email integration address as a recipient
3. Choose the **email per event** report format. Each email describes a single event and, per the vendor documentation, is meant for automatic processing. The summary formats (Full, Compact, Extra compact) group many events for a period into one email, which would become a single alert in Flashduty
4. Set **Minimal priority to be reported** to the lowest event priority you want sent, and make the report active

Flowmon ADS decides when to send by priority: CRITICAL is sent right after the flow data is processed, while HIGH, MEDIUM, LOW and INFORMATION are sent as hourly, six-hour, daily and weekly summaries. To get events into Flashduty promptly, use this report only for the priorities that need prompt handling.

The body of a per-event email contains these fields:

| Field | Meaning |
| :- | :- |
| `ID` | Unique event identifier |
| `Category` | Code of the detection method |
| `Type` | Name of the detection method |
| `Perspective` | Perspective assigned to the report |
| `Severity` | Priority of the event |
| `Time` | Start time, in UTC or Flowmon appliance local time depending on the report settings |
| `Protocol` | Protocol related to the event, may be empty |
| `Source` | Source IP address |
| `Target IPs` | First 10 target IP addresses |
| `Ports involved` | Port numbers related to the event, may be empty |

## Push mode in Flashduty

***

Keep the email integration's default push mode, which creates a new alert for every email: the alert title is the email title and the description is the email body, which contains the fields above. Flowmon ADS sends one email per event and events don't need to be merged, so no rules are needed.

## Limitations

***

* **No recovery email**: Flowmon ADS events are one-time notifications and no recovery email is sent, so alerts do not close on their own. Turn on the [auto-resolve timeout](/en/on-call/channel/create-edit) in the channel that receives this integration; 24 hours is a reasonable start.
* **Severity**: in Flashduty these alerts show the Email integration type, and their severity is always Warning; the event priority is in the `Severity` field of the body. You can adjust it with [alert pipelines](/en/on-call/integration/alert-integration/alert-pipelines).
* **RT format**: the RT email format of Flowmon ADS groups events of the same type for one IP into a single email (the per-event format does not), so this page does not use it.
