In Flashduty On-call
You can get the integration push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, select Channel and open a channel
- Select Configuration → Integrations → Private integration, then click Add an integration
- Select Imperva and click Save
- Open the new integration card and copy the Push URL
Use a shared integration
- In the Flashduty console, select Integration Center → Alert Events
- Select Imperva and enter an integration name
- Configure the default route and select a channel. You can add more rules under Routes after creation
- Click Save and copy the generated Push URL
Configure Imperva
1
Add a Webhook Connection
- Sign in to
my.imperva.comand select Account → Account Management in the top menu - In the sidebar select Webhook Connections, then click Add Webhook
- Enter a Name and paste the full Flashduty push URL (including
integration_key) into URL - Secret Token is optional. Imperva sends it in a custom HTTP header with every request; Flashduty does not check that header
- Click Test Webhook to confirm the URL is reachable, then save
2
Select the webhook in notification policies
Add or edit a notification policy and choose the new Webhook Connection in Recipients → Channel. Create a policy for each notification subtype in the “Events and recovery” table below (Website DDoS, Website Group DDoS, Individual IP Protection, Network Protection, Network Connectivity).
3
Verify
Click Test Webhook on the connection. Flashduty creates an Info alert titled like
Hello World Test - <webhook name>. The test has no recovery notification, so close it by hand.Events and recovery
- The Imperva payload has no severity field, so severity comes from the event type. DDoS start events mean Imperva is blocking or diverting the attack, so they map to Warning. A BGP connection down and an attack alert that needs manual confirmation map to Critical
- An end event (
...Stop,BgpUp,PerformanceRestored) resolves the alert for the same object MonitoringAttackStartCriticalandTrafficStartDiverthave no end notification, so each event opens its own alert. Turn on the channel’s auto-resolve timeout (24 hours suggested)- Other notification types (account, site, billing, subscription, policy changes, range status changes) create no alert; Flashduty acknowledges them and returns success
Alert Key
The Alert Key is computed from the event family, the Imperva account ID, and the object identity. Start and end events read the same fields:
The title, event time, account name in the payload, and the webhook ID do not take part. A request without
event_type, or without the object identity of its family, is rejected with an error that names the missing field.
Labels
The alert title comes from
event_title and the description from event_details.event_body.
Troubleshooting
- Test Webhook fails: Imperva requires the receiver to answer 200 or 201. Check that the push URL is complete, the
integration_keyis valid, and the integration type is Imperva - No alerts arrive: check that the notification policy’s Recipients use this Webhook Connection and that the event type is in the table above. Event types outside the table create no alert
- An alert never resolves: check that the notification subtype of the end event is also in a notification policy.
MonitoringAttackStartCriticalandTrafficStartDivertnever resolve automatically - A 400 response: the request lacks
event_typeor the object identity field; the response names the field