In Flashduty On-call
You can obtain an integration push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, select Channel and open a channel
- Select Settings → Integrations → Dedicated integrations, then click Add an integration
- Select LimaCharlie and click Save
- Open the generated integration card and copy the Push URL
Use a shared integration
- In the Flashduty console, go to Integration Center → Alert events
- Select LimaCharlie and enter an integration name
- Configure the default route and choose a channel. You can add more rules under Routes after the integration is created
- Click Save and copy the generated Push URL
Configure LimaCharlie
1
Add a webhook output
- Sign in to LimaCharlie, select the organization, and go to Outputs
- Click Add Output. Set Stream to Detections and Destination to Webhook (one request per detection; do not choose Webhook Bulk)
- Set Name to
flashduty - Paste the complete Flashduty Push URL, including the
integration_keyparameter, into DESTINATION HOST - Enter any string as SECRET KEY. LimaCharlie uses it to compute the
lc-signaturerequest header. Flashduty does not verify that header
2
Make sure D&R rules produce detections
The webhook output forwards detections only. Confirm that the organization has enabled D&R rules that generate them, either your own rules or a managed ruleset. To forward only some detections, set a category or tag filter on the output.
3
Verify connectivity
The stream of an output can only be chosen when the output is created and cannot be changed afterwards. To check that the URL is reachable first, create a separate test output: set Stream to Audit Logs, Destination to Webhook, and DESTINATION HOST to the same Push URL. Then make a management change in the organization (for example, disable and re-enable a D&R rule) to trigger an audit event. Flashduty returns 200 for requests that are not detections and creates no alert, so this step only proves the URL is reachable. Delete the test output when you are done.For an end-to-end check, let a D&R rule match once and confirm the alert arrives in Flashduty.
Alert Key
Flashduty uses the detection’s
detect_id as the Alert Key. The LimaCharlie documentation defines it as the unique detection identifier. A resent detection keeps its detect_id and merges into the same alert, and different detections become separate alerts.
cat (the detection name), priority, and timestamps are not part of the Alert Key. A request that has cat but no detect_id is rejected with a parameter error.
Severity
LimaCharlie provides only an optional integer
priority (0 to 10) with no defined levels. The Flashduty mapping is:
Field mapping
The matched event (
detect) and the extracted IOCs (detect_data) are not copied into labels.
Alerts do not recover
A detection is a one-shot event and LimaCharlie sends no recovery. In the channel that receives this integration, turn on the auto-resolve timeout. 24 hours is a reasonable start; adjust it to how quickly your team handles detections.
Troubleshooting
LimaCharlie reports a failed or temporarily disabled output
LimaCharlie reports a failed or temporarily disabled output
LimaCharlie disables a failing output for a while and re-enables it automatically. Editing the output configuration re-enables it immediately. Check that DESTINATION HOST is the complete Push URL, and look at the
outputs/<output name> entry under Errors in LimaCharlie Platform Logs for details.No alerts arrive
No alerts arrive
Confirm that the output stream is Detections and that you chose Webhook, not Webhook Bulk. Requests from the Audit Logs, Events, and Deployments streams are accepted by Flashduty but create no alert.
Flashduty returns a parameter error
Flashduty returns a parameter error
The body must be JSON with a non-empty
detect_id. If you reshape the body with custom_transform, keep the cat and detect_id fields.