In Flashduty On-call
You can obtain an integration push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, select Channel and open a channel
- Select Configuration → Integrations → Private integration, then click Add an integration
- Select Kentik, then click Save
- Open the generated integration card and copy the Push URL
Use a shared integration
- In the Flashduty console, select Integration Center → Alert Events
- Select Kentik and enter an integration name
- Configure the default route and select a channel; after creation, add more rules under Route if needed
- Click Save and copy the generated Push URL
Configure Kentik
Creating a notification channel requires the Administrator role in Kentik; Members can only view channels.
1
Create a Custom Webhook notification channel
- Log in to the Kentik Portal and go to Settings → Notification Channels
- Click Add Notification Channel and set Type to Webhook (listed as Custom Webhook). Do not choose the JSON type: Flashduty parses the output of the template below
- Fill in the fields as follows:
- Click Save
2
Use the channel in alert policies or Synthetics tests
- Alert policies: go to Settings → Alert Policies and edit a policy. For each threshold that should notify, open its Activate & Clear settings, select the channel under Notifications → Notification Channels, and save
- Synthetics tests: go to Synthetics → Tests and edit a test. On the Alerting and Notifications tab, select the channel under Notification Channels and save
3
Verify
- Let an alert policy or Synthetics test that uses the channel enter an alarm state, and confirm that Flashduty receives an active alert
- Wait for the condition to clear, or select the alert on the Kentik Alerting page and click Clear Alert, and confirm that the Flashduty alert recovers
Alert Key
Flashduty uses the Kentik alert ID (
AlarmID, shown as Alert ID in Kentik) as the Alert Key. Every state-change notification of one Kentik alert, from Active to Cleared, carries the same alert ID, so they merge into one alert, and the clear notification closes it.
- Alerts per key: an alert policy raises a separate alert for each key (one set of values of the policy dimensions) that matches the conditions. Each alert has its own ID, so each is a separate Flashduty alert that recovers on its own
- Synthetics alerts per agent: a Synthetics test raises a separate alert, with its own ID, for each test agent. A new failure after an alert clears gets a new alert ID and becomes a new Flashduty alert
- Changes to the description, severity, metric values, or times do not change the Alert Key. Events without
AlarmIDare rejected - When one notification carries several events, each event maps to its own alert. A notification with no events is accepted but creates no alert
Status and severity
The status comes from
IsActive:
The severity comes from the event importance (
Importance, 0 to 7). For alert policy alerts, Importance matches the severity of the threshold:
Labels
The alert title is the Kentik event description (
Description), such as Alarm for DDoS Protect Policy Active.
Troubleshooting
- Flashduty returns a parameter error: make sure the URL is complete and includes
integration_key, the channel type is Custom Webhook, and the template matches the one above AlarmID is required: the channel is used for mitigation or Insights notifications, or the template was changed. Use the channel only for alert policies and Synthetics tests- The alert does not recover: confirm that the alert is Cleared in Kentik. For policies with Acknowledgement Required on, the alert must be acknowledged in Kentik before it can clear (see Kentik threshold policy settings)
- One policy creates several alerts: the policy alerts on each set of dimension values separately; this is expected
- Test notifications: Send Test Notification on the Template & Preview tab sends mock data whose event description starts with
[TEST]; Flashduty accepts it and creates no alert. If you first load a real alert with Enter Alert ID, the test carries that alert’s real state, and Flashduty handles it as a real notification