In Flashduty On-call
You can obtain an integration push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, select Channel and open a channel
- Select Configuration → Integrations → Private integration, then click Add an integration
- Select Flowtriq, then click Save
- Open the generated integration card and copy the Push URL
Use a shared integration
- In the Flashduty console, select Integration Center → Alert Events
- Select Flowtriq and enter an integration name
- Configure the default route and select a channel; after creation, add more rules under Route if needed
- Click Save and copy the generated Push URL
Configure Flowtriq
1
Add a Webhook alert channel
- Sign in to the Flowtriq console and go to Alert Channels
- Add a channel of type Webhook (a trial account includes one free alert channel) and enter the full Flashduty push URL in URL (HTTPS, including
integration_key) - Leave Secret empty. When a secret is set, Flowtriq adds an HMAC-SHA256 signature in the
X-Flowtriq-Signatureheader; Flashduty authenticates the request by theintegration_keyin the URL and does not verify that signature
2
Save and test
- After saving the channel, click Test on it. Flowtriq sends a
testevent; Flashduty returns success and does not create an alert - If you use a Flowtriq escalation policy, add the Webhook channel to the relevant step. Without a policy, all channels fire as soon as an event occurs
3
Verify a real event
Trigger attack detection on a monitored node. Confirm that Flashduty receives an active alert, and that the alert recovers automatically when the attack ends.
Events and recovery
Flowtriq posts to the webhook on every incident event. The event type is in
event_type:
Other event types, including any Flowtriq adds later, create no alert; Flashduty returns success for them.
Alert Key
Flashduty builds the Alert Key from the incident identity:
incident.uuid when present, otherwise incident.id. Webhook deliveries currently carry the numeric incident.id and no uuid. The start and end events of one attack share one Alert Key, so the end event recovers the matching alert. An event with neither field is rejected. Changes to the title, severity, or peak traffic do not change the Alert Key.
Severity mapping
A recovery event keeps the last severity from the attack.
Labels
The alert description comes from Flowtriq’s AI summary (
ai_summary). The attack_start delivery carries no summary, so the description is empty at that point.
Troubleshooting
- Flowtriq shows a failed delivery: confirm the URL is complete, includes
integration_key, and uses HTTPS. Failed deliveries are listed in the notification log on the incident detail page in Flowtriq - The alert did not recover: confirm the Flowtriq channel sent an
attack_endevent. Recovery relies on the start and end events carrying the sameincident.id; if an alert stays open for a long time, close it manually in Flashduty - The test succeeded but no alert appeared:
testevents create no alert, which is expected