New, Update, and Clear notifications keep updating and finally recover that alert.
In Flashduty On-call
You can get the integration push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, select Channel and open a channel
- Select Configuration → Integrations → Private integration, then click Add an integration
- Select FortiSIEM and click Save
- Open the new integration card and copy the Push URL
Use a shared integration
- In the Flashduty console, select Integration Center → Alert Events
- Select FortiSIEM and enter an integration name
- Configure the default route and select a channel; you can add more rules under Routes after creation
- Click Save and copy the generated Push URL
In FortiSIEM
1
Fill in Incident HTTP Notification
- Sign in to FortiSIEM as an administrator and go to ADMIN → Settings → Analytics → Incident Notification
- In the Incident HTTP Notification section, enter the complete Flashduty Push URL (including the
integration_keyparameter) in HTTP(S) Server URL - If the form requires a User Name and Password, enter any placeholder values. Flashduty authenticates with the
integration_keyin the push URL and does not check them - Click Save
2
Understand what is sent
Incident HTTP Notification is a global FortiSIEM notification channel: per the official documentation, it sends when a rule triggers an incident. To sync only some incidents, filter by labels such as
rule_type, severity, or organization with Flashduty Routes or alert processing rules.3
Verify the lifecycle
Let a rule trigger a real incident and confirm Flashduty receives an active alert. Then clear the incident in FortiSIEM (or wait for it to clear automatically) and confirm the Flashduty alert recovers. The form’s Test button is documented only as a connection check, and its request body is not published. If it sends a request to the push URL, that request may be handled as an ordinary incident or rejected as invalid, so go by what the console shows.
Alert Key
Flashduty uses the
incidentId attribute of the incident element as the Alert Key. The FortiSIEM documentation defines it as “Unique ID of the incident in FortiSIEM”, and describes status as “New, Update or Clear”; one incidentId is expected across the notifications of one incident. The XML schema comes from the FortiSIEM 6.7.0 Integration API guide; check the first real delivery on your 7.x version against the field list below. Changes to the rule name, severity, repeat count, time, or incident details do not change the Alert Key.
Flashduty rejects a request without incidentId (HTTP 400), because later updates and recovery could not be matched reliably.
Status and severity
The
status attribute:
The
severity attribute accepts HIGH, MEDIUM, LOW, or the matching 0-10 score:
Labels
deviceDetails, which carries user names and emails, is not written to labels.
Troubleshooting
- FortiSIEM reports a failed push: confirm HTTP(S) Server URL starts with
https://, includes the fullintegration_key, and that the FortiSIEM network can reachapi.flashcat.cloud - Flashduty returns an invalid-parameter error: confirm the body is FortiSIEM incident XML (root element
incident) with anincidentIdattribute - The alert does not recover: confirm the incident was cleared in FortiSIEM, and check that the notification Flashduty received has
statusset toClear - Too many incidents arrive: Incident HTTP Notification applies to every rule, so filter with Flashduty routes or alert processing rules
- The test succeeds but real alerts do not arrive: check that a rule actually triggered an incident and that Incident HTTP Notification is configured in FortiSIEM