alert-config.xml. Flashduty’s email integration receives these emails and extracts the Alert Key from the email title with a rule, so no separate QRadar integration is needed: create an email integration in Flashduty, add its email address as a recipient of the QRadar rule’s email response, then customize the email template and configure the push rule below.
In Flashduty On-call
Get the integration email address in either of the two ways below. In both cases choose the Email integration type, not IBM QRadar.
Use a dedicated integration
- In the Flashduty console, select Channels and open a channel
- Select Settings → Integrations → Dedicated integrations and click Add an integration
- Select Email and click Save
- Open the new integration card, copy the email address, then configure the push rule below
Use a shared integration
- In the Flashduty console, select Integration Center → Alert events
- Select Email, enter an integration name and copy the email address
- Configure the push rule below
- Set a default route, select a channel and click Save
Configure in QRadar
A rule’s email response uses the event or flow templates in
alert-config.xml. QRadar’s documentation describes how to edit them: Configuring event and flow custom email notifications. Below is the minimal change that makes the email fit a Flashduty rule.
1
Edit the email template
Log in to the QRadar Console over SSH as root, copy the If the files are not in that directory, look in
custom_alerts directory to a temporary directory, and edit alert-config.xml there:/opt/qradar/conf/templates/custom_alerts. Use this <template> (event template):- The title starts with
[QRadar], followed by the rule name and the source IP, and the push rule extracts the Alert Key from it. Several emails from the same rule and source IP merge into one Flashduty alert - Keep
<active>true</active>and leave<filename>empty. The${...}parameters come from the Common and Event parameters listed in QRadar’s documentation - If the rule also watches flows, add a second template in the same format with
<templatetype>flow</templatetype>and the same subject[QRadar] ${RuleName} from ${SourceIP}
2
Validate and deploy
File alert-config.xml was deployed successfully to staging!, log in to QRadar and go to Admin → Advanced → Deploy Full Configuration.3
Send email from the rule
In the response of each QRadar rule that should notify, enable the email notification, enter the address of the Flashduty email integration as the recipient, and make sure the email uses the template you added (a template with
<active> set to true appears as an option in QRadar).Configure the push rule in Flashduty
QRadar rule emails have no recovery email; one email corresponds to one rule firing. One trigger rule is therefore enough, and the Alert Key is extracted from the email title as “rule name + source IP”.
- Set Push mode to Trigger or close alert based on rules
- Add the rule below: the condition is Email title Match the given regex, and the Alert Key is extracted from the Email title
- Under Default rules, choose: if none of the above rules match, discard email
[QRadar] prefix (for example system notifications) do not create alerts.
Recovery and deduplication
- A QRadar rule response does not send another email when the condition clears, so Flashduty never closes these alerts on its own. Enable the auto-resolve timeout on the channel that receives this integration (24 hours suggested), or close alerts manually once handled.
- When the same rule fires again for the same source IP, the title and Alert Key are the same, so Flashduty updates the existing alert. To distinguish by destination IP or user, add the matching parameter (such as
${DestinationIP}or${UserName}) to<subject>. - Alerts show the integration type Email in Flashduty, and severity is Warning throughout. Adjust it with an alert processing pipeline.
- An email body over 128 KB is truncated and attachments are dropped; see the email integration.
Troubleshooting
- No alerts arrive: confirm Deploy Full Configuration was run, the rule’s email response uses the new template, and the QRadar mail server can deliver to the Flashduty email address
- Every alert is discarded: the email title does not start with
[QRadar], which means the rule is not using the new template; check the title of a received email - Too many alerts: keep only the rule name in
<subject>so that firings of the same rule merge