alert_active when an alert is raised and alert_resolved when it is resolved. Flashduty correlates the two by the alert id: it creates an alert on trigger and recovers it on resolution.
In Flashduty On-call
You can obtain an integration push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, select Channel and open a channel
- Select Configuration → Integrations → Private integration, then click Add an integration
- Select Level, then click Save
- Open the generated integration card and copy the Push URL
Use a shared integration
- In the Flashduty console, select Integration Center → Alert Events
- Select Level and enter an integration name
- Configure the default route and select a channel; after creation, add more rules under Route if needed
- Click Save and copy the generated Push URL
Configure Level
1
Add a webhook
- Sign in to Level and go to Settings → Webhooks
- Create a webhook and paste the full Flashduty push URL, including
integration_key, as the URL - Select the events
alert_activeandalert_resolved. If onlyalert_activeis selected, alerts are never recovered automatically - The secret can be left empty. When a secret is set, Level adds an HMAC-SHA256 signature in the
X-Level-Signatureheader; Flashduty does not verify it and authenticates with theintegration_keyin the push URL
2
Save and verify
- Save the webhook
- Trigger a device alert in Level and confirm Flashduty receives an active alert
- After the alert is resolved in Level, confirm the matching Flashduty alert recovers
- The Webhooks page in Level shows the status code and response of each delivery, and Re-run request resends one
Alert Key
Flashduty uses
data.id (the Level alert ID) as the Alert Key, so alert_active and alert_resolved for the same alert share one Alert Key. Changes to the alert name, description, severity, or device hostname do not change it. Level’s event_id identifies an event and stays the same across retries and manual re-runs; Flashduty does not use it as the Alert Key. Requests without data.id are rejected.
Status and severity
The
device_created, device_updated, device_deleted, group_created, group_updated, and group_deleted events are not alerts; Flashduty returns success and creates nothing.
Severity comes from data.severity:
A recovery event keeps the alert’s existing severity.
Labels
The alert title is
hostname: alert name, and the description comes from data.description and data.payload.
Troubleshooting
- Flashduty returns a parameter error: check that the URL is complete and includes
integration_key, and that the request body is in Level’s webhook format - Alerts do not recover: check that the webhook has
alert_resolvedselected - The same event arrives more than once: Level retries failed deliveries automatically; repeated deliveries of the same alert merge into one Flashduty alert