> ## Documentation Index
> Fetch the complete documentation index at: https://docs.flashduty.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Lacework FortiCNAPP alert integration

> Send cloud security alerts from FortiCNAPP (formerly Lacework) to Flashduty On-call through a custom webhook alert channel.

Use a Lacework FortiCNAPP custom webhook alert channel to send compliance change, anomaly and other alerts to Flashduty On-call. Each FortiCNAPP event maps to one Flashduty alert. FortiCNAPP posts once when it generates an alert, and its documentation describes no close or status-change notification, so Flashduty alerts do not recover on their own. Turn on auto-close for the channel.

<div className="hide">
  ## In Flashduty On-call

  ***

  You can get the integration push URL in either of the following ways.

  ### Use a dedicated integration

  1. Open the Flashduty console, choose **Channels**, and open a channel
  2. Choose **Settings** → **Integrations** → **Dedicated integrations**, then click **Add an integration**
  3. Choose **Lacework FortiCNAPP** and click **Save**
  4. Open the generated integration card and copy the **push URL**

  ### Use a shared integration

  1. Open the Flashduty console and choose **Integration Center → Alert events**
  2. Choose **Lacework FortiCNAPP** and enter an integration name
  3. Configure the default route and pick a channel; you can add more rules under **Routes** after creation
  4. Click **Save** and copy the generated **push URL**
</div>

## In FortiCNAPP

***

<Steps>
  <Step title="Create the webhook alert channel">
    1. Log in to the FortiCNAPP console as a user with administrative privileges
    2. Go to **Settings > Notifications > Channels** and click **+ Add new**
    3. Select **Webhook** and click **Next**
    4. Enter a channel name, for example `Flashduty`
    5. In **Webhook URL**, paste the full Flashduty push URL (it must be `https`; keep `integration_key` in the query string)
    6. Click **Save**

    FortiCNAPP sends an HTTP `POST` with a fixed JSON body, so no template is needed.
  </Step>

  <Step title="Create an alert rule">
    In **Settings > Notifications > Alert rules**, click **+ Add New**, select the channel from the previous step, and choose the alert severities, resource groups and alert categories you need. Only alerts that match an alert rule are sent to Flashduty.
  </Step>

  <Step title="Turn on auto-close">
    For the channel that receives FortiCNAPP alerts, turn on [auto-close](/en/on-call/channel/create-edit). A duration of 24 hours, counted from **Incident trigger**, is a reasonable start; adjust it to how fast your team handles these alerts.
  </Step>

  <Step title="Verify">
    Run **Test Integration** on the channel in the channel list (where available), or wait for an alert rule to match, and confirm that Flashduty receives the alert. The FortiCNAPP documentation does not show the body of the test request, so Flashduty handles it as an ordinary alert. It is not linked to any real alert and no recovery follows, so close it manually once you see it.
  </Step>
</Steps>

## Alert Key

***

Flashduty builds the Alert Key from `lacework_account` and `event_id` in the request body. The FortiCNAPP documentation describes `event_id` as "The FortiCNAPP ID for the event". Repeated deliveries of one event (for example one notification per resource when the channel groups issues by resources) land on the same Flashduty alert, and each event opens its own alert.

Changes to the title, severity, description or time do not change the Alert Key. A request without `event_id` opens an alert of its own. A request with none of `event_id`, `event_title` and `event_description` is rejected with a parameter error.

## Status and severity

***

The FortiCNAPP webhook has no status field, so every request is a trigger event. `event_severity` ranges from 1 to 5, with 1 the highest.

| FortiCNAPP `event_severity` | Meaning | Flashduty severity |
| :- | :- | :- |
| `1`, `2` | Critical, High | Critical |
| `3` | Medium | Warning |
| `4`, `5` | Low, Info | Info |
| Empty or other | | Warning |

The alert title is `event_title` and the description is `event_description`. Alert labels include the Lacework account (`lacework_account`), event source (`event_source`), event type (`event_type`), event ID, raw severity, recommendation ID (`rec_id`, compliance events only), event time and event link.

## Troubleshooting

***

* **No alert arrives**: check that an alert rule uses the channel and that its severities, resource groups and alert categories cover the alert; a disabled channel delivers nothing
* **The channel cannot be saved**: the webhook URL must be `https` and include the full `integration_key` query parameter
* **The alert never closes**: FortiCNAPP sends no close notification; turn on auto-close for the channel
* **A test alert arrives**: it comes from **Test Integration**; handle it as an ordinary alert and close it manually

For more information, see the Fortinet documentation [Custom webhook alert channel](https://docs.fortinet.com/document/forticnapp/latest/administration-guide/465696/custom-webhook-alert-channel).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.