In Flashduty On-call
You can get the integration push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, select Channel and open a channel
- Select Configuration → Integrations → Private integration, then click Add an integration
- Select LogicMonitor and click Save
- Open the new integration card and copy the Push URL
Use a shared integration
- In the Flashduty console, select Integration Center → Alert Events
- Select LogicMonitor and enter an integration name
- Configure the default route and select a channel. You can add more rules under Routes after creation
- Click Save and copy the generated Push URL
Configure LogicMonitor
The steps below need a LogicMonitor user who can manage Integrations, Escalation Chains, and Alert Rules.
1
Create the Custom HTTP Delivery integration
Go to Settings → Integrations, click Add Integration, select Custom HTTP Delivery under Workflow Integration, and fill in the form as follows:Do not rename the fields, and keep
Body template:
alert_id and alert_status. Leave Use Custom Headers and Include an ID provided in HTTP response when updating alert status off.2
Test and save
Click Test Alert Delivery and make sure LogicMonitor reports success. The test request carries
alert_status test; Flashduty returns success and creates no alert. Then click Save.3
Create an escalation chain
LogicMonitor sends alerts only to escalation chains referenced by an alert rule. Go to Settings → Escalation Chains, create a chain, add a Recipient in Stage 1, select the
Flashduty integration created above, and save.4
Configure the alert rule
Go to Settings → Alert Rules, create a rule or edit an existing one, and set it as follows:
LogicMonitor evaluates alert rules in ascending priority order, and an alert matches only the first rule that fits. Make sure the alerts you want to push do not match another rule first.
5
Verify the lifecycle
Make a datapoint cross its alert threshold (for example, temporarily lower the threshold of a DataSource datapoint) and confirm that Flashduty receives an active alert. Restore the threshold, wait for the alert to clear, and confirm that the original alert closes. LogicMonitor evaluates thresholds on each datapoint’s polling interval, so the alert and the clear usually arrive within one or two polling intervals.
Alert Key
Flashduty uses
alert_id (##ALERTID##, for example LMD12345) as the Alert Key. The LogicMonitor docs state that all alerts on one resource (or website), LogicModule, instance, and datapoint combination share the same alert ID, so the raise, severity change, and clear notifications land on one Flashduty alert. A new alert after a clear opens a new Flashduty alert.
Changes to the severity, value, threshold, or alert message do not change the Alert Key. Do not replace ##ALERTID## with ##INTERNALID## in the template: ##INTERNALID## changes when the severity changes, so the clear notification would not close the original alert.
Flashduty rejects requests without alert_id or alert_status, or where either field is still the unreplaced ##ALERTID## or ##ALERTSTATUS##.
Alert lifecycle
Flashduty handles each notification by its
alert_status field (##ALERTSTATUS##):
If you select Acknowledged in the integration, LogicMonitor sends an
ack notification when an alert is acknowledged. An acknowledgement neither opens nor closes a Flashduty alert, and ignored notifications return success.
Severity
The severity comes from the
level field (##LEVEL##), case-insensitive:
The clear notification carries the level of the alert that cleared, and the recovery event keeps that severity.
Alert content
- Title:
<DataSource> <datapoint> on <resource>, where the resource is the host name, or the website name for website alerts. Without a DataSource and datapoint, the title is the resource name; with none of them, it isLogicMonitor alert <alert_id> - Description: the alert message rendered by
##MESSAGE##, as configured in the LogicModule - Labels:
check(DataSource and datapoint),resource,host,website,alert_id,alert_status,alert_type,level(original level),datasource,instance,datapoint,value,threshold,group,alert_url(link to the LogicMonitor alert details page)
##DATAPOINT## as-is; Flashduty treats it as empty.
Troubleshooting
- Test Alert Delivery fails: make sure URL is the full push URL including the
integration_keyparameter, and that HTTP Method isHTTP Post - Flashduty says the body is not valid JSON: make sure Alert Data uses Raw with the JSON format, and that every
##TOKEN##in the template is inside double quotes - No alert is sent: make sure the alert matches an alert rule that references the escalation chain, and that the chain’s stage contains the integration. The alert’s History shows the notifications sent
- The alert does not recover: make sure Send notification when alerts clear is on for the alert rule, Cleared is selected in the integration’s Alert Statuses, and
alert_idin the template is##ALERTID## - The same issue is notified repeatedly: set the alert rule’s Escalation Interval to
0 - A cleared alert reopens: with Escalated/De-escalated selected, adding a note to a cleared alert in LogicMonitor also sends an
updatenotification, and Flashduty reopens the alert. Avoid adding notes to cleared alerts, or close the alert manually in Flashduty