Skip to main content
An IBM QRadar rule can run an email response, and the subject and body of that email can be customized with a template in alert-config.xml. Flashduty’s email integration receives these emails and extracts the Alert Key from the email title with a rule, so no separate QRadar integration is needed: create an email integration in Flashduty, add its email address as a recipient of the QRadar rule’s email response, then customize the email template and configure the push rule below.

In Flashduty On-call


Get the integration email address in either of the two ways below. In both cases choose the Email integration type, not IBM QRadar.

Use a dedicated integration

  1. In the Flashduty console, select Channels and open a channel
  2. Select Settings → Integrations → Dedicated integrations and click Add an integration
  3. Select Email and click Save
  4. Open the new integration card, copy the email address, then configure the push rule below

Use a shared integration

  1. In the Flashduty console, select Integration Center → Alert events
  2. Select Email, enter an integration name and copy the email address
  3. Configure the push rule below
  4. Set a default route, select a channel and click Save

Configure in QRadar


A rule’s email response uses the event or flow templates in alert-config.xml. QRadar’s documentation describes how to edit them: Configuring event and flow custom email notifications. Below is the minimal change that makes the email fit a Flashduty rule.
1

Edit the email template

Log in to the QRadar Console over SSH as root, copy the custom_alerts directory to a temporary directory, and edit alert-config.xml there:
If the files are not in that directory, look in /opt/qradar/conf/templates/custom_alerts. Use this <template> (event template):
  • The title starts with [QRadar], followed by the rule name and the source IP, and the push rule extracts the Alert Key from it. Several emails from the same rule and source IP merge into one Flashduty alert
  • Keep <active>true</active> and leave <filename> empty. The ${...} parameters come from the Common and Event parameters listed in QRadar’s documentation
  • If the rule also watches flows, add a second template in the same format with <templatetype>flow</templatetype> and the same subject [QRadar] ${RuleName} from ${SourceIP}
2

Validate and deploy

After you see File alert-config.xml was deployed successfully to staging!, log in to QRadar and go to Admin → Advanced → Deploy Full Configuration.
3

Send email from the rule

In the response of each QRadar rule that should notify, enable the email notification, enter the address of the Flashduty email integration as the recipient, and make sure the email uses the template you added (a template with <active> set to true appears as an option in QRadar).

Configure the push rule in Flashduty


QRadar rule emails have no recovery email; one email corresponds to one rule firing. One trigger rule is therefore enough, and the Alert Key is extracted from the email title as “rule name + source IP”.
  1. Set Push mode to Trigger or close alert based on rules
  2. Add the rule below: the condition is Email title Match the given regex, and the Alert Key is extracted from the Email title
  3. Under Default rules, choose: if none of the above rules match, discard email
Rule 1: trigger an alert
The default rule discards mail so that emails without the [QRadar] prefix (for example system notifications) do not create alerts.

Recovery and deduplication


  • A QRadar rule response does not send another email when the condition clears, so Flashduty never closes these alerts on its own. Enable the auto-resolve timeout on the channel that receives this integration (24 hours suggested), or close alerts manually once handled.
  • When the same rule fires again for the same source IP, the title and Alert Key are the same, so Flashduty updates the existing alert. To distinguish by destination IP or user, add the matching parameter (such as ${DestinationIP} or ${UserName}) to <subject>.
  • Alerts show the integration type Email in Flashduty, and severity is Warning throughout. Adjust it with an alert processing pipeline.
  • An email body over 128 KB is truncated and attachments are dropped; see the email integration.

Troubleshooting


  • No alerts arrive: confirm Deploy Full Configuration was run, the rule’s email response uses the new template, and the QRadar mail server can deliver to the Flashduty email address
  • Every alert is discarded: the email title does not start with [QRadar] , which means the rule is not using the new template; check the title of a received email
  • Too many alerts: keep only the rule name in <subject> so that firings of the same rule merge