In Flashduty On-call
You can get the push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, select Channels and open a channel
- Select Settings → Integrations → Dedicated integrations, then click Add an integration
- Select Rapid7 InsightIDR and click Save
- Open the generated integration card and copy the push URL
Use a shared integration
- In the Flashduty console, select Integration Center → Alert Events
- Select Rapid7 InsightIDR and enter an integration name
- Configure the default route and select a channel; you can add more rules under Routes after creation
- Click Save and copy the generated push URL
In Rapid7 InsightIDR
1
Add a Universal Webhook data exporter
- Sign in to InsightIDR, go to Data Connectors → SIEM → Data Collectors, and open the Data Exporters tab
- Click Add Data Exporter and choose Universal Webhook
- Select the collector to use and optionally enter a name
- Paste the full Flashduty push URL into URL. It must include
integration_key. HTTPS is recommended - Keep the pre-filled Secret. InsightIDR uses it to sign the request body (
X-Rapid7-Signatureheader). Flashduty does not verify the signature - Keep the default data export type, Investigations
- Click Save
2
Verify
When the exporter is saved or the collector starts, InsightIDR sends a test request (
X-Rapid7-Event: test). Flashduty creates an Info alert titled Rapid7 InsightIDR test notification. It does not recover on its own, so close it by hand after checking.After that, every investigation InsightIDR generates is pushed as one alert.Event types
Alert Key
Flashduty uses
investigationId, the fixed ID InsightIDR assigns to each investigation, as the Alert Key. Changes to the title, description, or time do not change it. A request without investigationId is rejected.
Status and severity
The InsightIDR payload carries no severity, so every investigation is treated as Warning. To separate levels, adjust them in the integration’s Alert processing by title or label.
Labels
User emails and AD distinguished names (
distinguishedName) are not written to labels.
About signatures
InsightIDR signs the request body with the Secret (
X-Rapid7-Signature). Flashduty does not verify it, so the integration_key in the push URL is the only credential; keep it private. You can also add custom headers on the exporter; Flashduty does not require them.
Troubleshooting
- Flashduty receives nothing: the collector is hosted by you. Confirm it can reach the internet and that the URL is complete and includes
integration_key - Parameter error: a missing
investigationIdmeans the request is not an investigation; an unsupported event meansX-Rapid7-Eventis neitheridr_investigation_creatednortest - Alerts never close: InsightIDR does not send investigation closures, so turn on auto-close
- The test alert stays open: the Info alert from the test request must be closed by hand