> ## Documentation Index
> Fetch the complete documentation index at: https://docs.flashduty.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Kentik alert integration

> Send Kentik alert policy and Synthetics alerts to Flashduty On-call through a Custom Webhook notification channel, and recover them automatically when the alert clears.

Use a Kentik Custom Webhook notification channel to send alerts to Flashduty On-call. Two kinds of alerts are supported: alerts raised by alert policies, and alerts raised by Synthetics tests. Each Kentik alert maps to one Flashduty alert: Kentik sends a trigger while the alert is Active, and a recovery when it becomes Cleared.

<div className="hide">
  ## In Flashduty On-call

  ***

  You can obtain an integration push URL in either of the following ways.

  ### Use a dedicated integration

  1. In the Flashduty console, select **Channel** and open a channel
  2. Select **Configuration** → **Integrations** → **Private integration**, then click **Add an integration**
  3. Select **Kentik**, then click **Save**
  4. Open the generated integration card and copy the **Push URL**

  ### Use a shared integration

  1. In the Flashduty console, select **Integration Center → Alert Events**
  2. Select **Kentik** and enter an integration name
  3. Configure the default route and select a channel; after creation, add more rules under **Route** if needed
  4. Click **Save** and copy the generated **Push URL**
</div>

## Configure Kentik

***

Creating a notification channel requires the Administrator role in Kentik; Members can only view channels.

<Steps>
  <Step title="Create a Custom Webhook notification channel">
    1. Log in to the Kentik Portal and go to **Settings** → **Notification Channels**
    2. Click **Add Notification Channel** and set **Type** to **Webhook** (listed as Custom Webhook). Do not choose the **JSON** type: Flashduty parses the output of the template below
    3. Fill in the fields as follows:

    | Field | Value |
    | :- | :- |
    | **Name** | A recognizable name, such as `Flashduty` |
    | **Status** | On |
    | **URL** | The full Flashduty integration push URL, including `integration_key` |
    | **Custom Headers** | Leave empty |
    | **Custom Template** | Click **Go to Notification Template Setup** and paste the template below into **TEMPLATE** on the **Template & Preview** tab, without renaming any field |
    | **Uglify JSON** | Keep the default |

    ```go-template theme={null}
    {
      "CompanyID": "{{ .CompanyID }}",
      "Events": [
        {{- range $index, $event := .Events -}}
        {{- join $index }}
        {
          "Type": {{ .Type | toJSON }},
          "AlarmID": "{{ with .Details.GetValue "AlarmID" }}{{ . }}{{ end }}",
          "IsActive": {{ .IsActive | toJSON }},
          "Importance": {{ .Importance | toJSON }},
          "Description": {{ .Description | toJSON }},
          "CurrentState": {{ .CurrentState | toJSON }},
          "PreviousState": {{ .PreviousState | toJSON }},
          "StartTime": {{ .StartTime | toJSON }},
          "EndTime": {{ .EndTime | toJSON }},
          "Details": {{ .Details.General.ToMap | toJSON }},
          "Dimensions": {{ (.Details.WithTag "dimension").ToMap | toJSON }},
          "Links": {{ (.Details.WithTag "url").ToMap | toJSON }}
        }
        {{- end }}
      ]
    }
    ```

    4. Click **Save**
  </Step>

  <Step title="Use the channel in alert policies or Synthetics tests">
    * **Alert policies**: go to **Settings** → **Alert Policies** and edit a policy. For each threshold that should notify, open its **Activate & Clear** settings, select the channel under **Notifications** → **Notification Channels**, and save
    * **Synthetics tests**: go to **Synthetics** → **Tests** and edit a test. On the **Alerting and Notifications** tab, select the channel under **Notification Channels** and save

    Do not use this channel for mitigation methods or Insights notifications: these notifications carry no alert ID, and Flashduty rejects them.
  </Step>

  <Step title="Verify">
    1. Let an alert policy or Synthetics test that uses the channel enter an alarm state, and confirm that Flashduty receives an active alert
    2. Wait for the condition to clear, or select the alert on the Kentik **Alerting** page and click **Clear Alert**, and confirm that the Flashduty alert recovers
  </Step>
</Steps>

## Alert Key

***

Flashduty uses the Kentik alert ID (`AlarmID`, shown as **Alert ID** in Kentik) as the Alert Key. Every state-change notification of one Kentik alert, from Active to Cleared, carries the same alert ID, so they merge into one alert, and the clear notification closes it.

* **Alerts per key**: an alert policy raises a separate alert for each key (one set of values of the policy dimensions) that matches the conditions. Each alert has its own ID, so each is a separate Flashduty alert that recovers on its own
* **Synthetics alerts per agent**: a Synthetics test raises a separate alert, with its own ID, for each test agent. A new failure after an alert clears gets a new alert ID and becomes a new Flashduty alert
* Changes to the description, severity, metric values, or times do not change the Alert Key. Events without `AlarmID` are rejected
* When one notification carries several events, each event maps to its own alert. A notification with no events is accepted but creates no alert

## Status and severity

***

The status comes from `IsActive`:

| Kentik `IsActive` | Status |
| :- | :- |
| `true` (alert Active) | Triggered |
| `false` (alert Cleared) | Recovered |

The severity comes from the event importance (`Importance`, 0 to 7). For alert policy alerts, `Importance` matches the severity of the threshold:

| Kentik severity | `Importance` | Flashduty severity |
| :- | :- | :- |
| Critical | 7 | Critical |
| Severe | 6 | Critical |
| Major | 5 | Warning |
| Warning | 4 | Warning |
| Minor | 3 | Info |
| Notice, Healthy, none | 2, 1, 0 | Info |
| Other or empty | - | Info |

## Labels

***

| Label | Source |
| :- | :- |
| `check` | Alert policy name (`AlarmPolicyName`); test name (`TestName`) for Synthetics alerts |
| `event_type` | Event type: `alarm` (alert policy) or `synthetic` (Synthetics) |
| `alarm_id` | Kentik alert ID, which is the Alert Key |
| `current_state` / `previous_state` | Current and previous state of the Kentik alert |
| `importance` | Raw Kentik importance value |
| `start_time` / `end_time` | Alert start and end time; `end_time` is `ongoing` while the alert is active |
| `company_id` | Kentik company ID |
| Others | Fields of `Details`, `Dimensions`, and `Links` in the template, such as `AlarmPolicyID`, `AlarmThresholdID`, `AlarmSeverity`, `TestID`, `IP_dst`, and `DashboardAlarmURL`. The labels above take precedence on name conflicts |

The alert title is the Kentik event description (`Description`), such as `Alarm for DDoS Protect Policy Active`.

## Troubleshooting

***

* **Flashduty returns a parameter error**: make sure the URL is complete and includes `integration_key`, the channel type is **Custom Webhook**, and the template matches the one above
* **`AlarmID is required`**: the channel is used for mitigation or Insights notifications, or the template was changed. Use the channel only for alert policies and Synthetics tests
* **The alert does not recover**: confirm that the alert is Cleared in Kentik. For policies with **Acknowledgement Required** on, the alert must be acknowledged in Kentik before it can clear (see [Kentik threshold policy settings](https://kb.kentik.com/v1/docs/threshold-policy-settings))
* **One policy creates several alerts**: the policy alerts on each set of dimension values separately; this is expected
* **Test notifications**: **Send Test Notification** on the **Template & Preview** tab sends mock data whose event description starts with `[TEST]`; Flashduty accepts it and creates no alert. If you first load a real alert with **Enter Alert ID**, the test carries that alert's real state, and Flashduty handles it as a real notification

For field details, see [Kentik notification channels](https://kb.kentik.com/docs/notification-channel) and the [Kentik Custom Webhook templating reference](https://github.com/kentik/custom-notification-templates/blob/main/docs/TEMPLATING_REFERENCE.md).
