Skip to main content
Use a Lacework FortiCNAPP custom webhook alert channel to send compliance change, anomaly and other alerts to Flashduty On-call. Each FortiCNAPP event maps to one Flashduty alert. FortiCNAPP posts once when it generates an alert, and its documentation describes no close or status-change notification, so Flashduty alerts do not recover on their own. Turn on auto-close for the channel.

In Flashduty On-call


You can get the integration push URL in either of the following ways.

Use a dedicated integration

  1. Open the Flashduty console, choose Channels, and open a channel
  2. Choose Settings → Integrations → Dedicated integrations, then click Add an integration
  3. Choose Lacework FortiCNAPP and click Save
  4. Open the generated integration card and copy the push URL

Use a shared integration

  1. Open the Flashduty console and choose Integration Center → Alert events
  2. Choose Lacework FortiCNAPP and enter an integration name
  3. Configure the default route and pick a channel; you can add more rules under Routes after creation
  4. Click Save and copy the generated push URL

In FortiCNAPP


1

Create the webhook alert channel

  1. Log in to the FortiCNAPP console as a user with administrative privileges
  2. Go to Settings > Notifications > Channels and click + Add new
  3. Select Webhook and click Next
  4. Enter a channel name, for example Flashduty
  5. In Webhook URL, paste the full Flashduty push URL (it must be https; keep integration_key in the query string)
  6. Click Save
FortiCNAPP sends an HTTP POST with a fixed JSON body, so no template is needed.
2

Create an alert rule

In Settings > Notifications > Alert rules, click + Add New, select the channel from the previous step, and choose the alert severities, resource groups and alert categories you need. Only alerts that match an alert rule are sent to Flashduty.
3

Turn on auto-close

For the channel that receives FortiCNAPP alerts, turn on auto-close. A duration of 24 hours, counted from Incident trigger, is a reasonable start; adjust it to how fast your team handles these alerts.
4

Verify

Run Test Integration on the channel in the channel list (where available), or wait for an alert rule to match, and confirm that Flashduty receives the alert. The FortiCNAPP documentation does not show the body of the test request, so Flashduty handles it as an ordinary alert. It is not linked to any real alert and no recovery follows, so close it manually once you see it.

Alert Key


Flashduty builds the Alert Key from lacework_account and event_id in the request body. The FortiCNAPP documentation describes event_id as “The FortiCNAPP ID for the event”. Repeated deliveries of one event (for example one notification per resource when the channel groups issues by resources) land on the same Flashduty alert, and each event opens its own alert. Changes to the title, severity, description or time do not change the Alert Key. A request without event_id opens an alert of its own. A request with none of event_id, event_title and event_description is rejected with a parameter error.

Status and severity


The FortiCNAPP webhook has no status field, so every request is a trigger event. event_severity ranges from 1 to 5, with 1 the highest. The alert title is event_title and the description is event_description. Alert labels include the Lacework account (lacework_account), event source (event_source), event type (event_type), event ID, raw severity, recommendation ID (rec_id, compliance events only), event time and event link.

Troubleshooting


  • No alert arrives: check that an alert rule uses the channel and that its severities, resource groups and alert categories cover the alert; a disabled channel delivers nothing
  • The channel cannot be saved: the webhook URL must be https and include the full integration_key query parameter
  • The alert never closes: FortiCNAPP sends no close notification; turn on auto-close for the channel
  • A test alert arrives: it comes from Test Integration; handle it as an ordinary alert and close it manually
For more information, see the Fortinet documentation Custom webhook alert channel.