> ## Documentation Index
> Fetch the complete documentation index at: https://docs.flashduty.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Logpoint alert integration

> Send triggered Logpoint (Guardsix) alert rules to Flashduty On-call through the HTTP Notification.

Use the HTTP Notification of a Logpoint (Guardsix) alert rule to send rule triggers to Flashduty On-call. Each alert rule maps to one Flashduty alert.

Logpoint sends a notification only when the rule triggers and sends nothing when it clears, so alerts do not recover automatically. Turn on the auto-resolve timeout in the channel; see [Alerts do not recover](#alerts-do-not-recover).

<div className="hide">
  ## In Flashduty On-call

  ***

  Create either a dedicated or shared **Logpoint** alert integration and copy its complete Push URL.
</div>

## Configure Logpoint

***

The Logpoint HTTP Notification has no fixed payload; the body comes from the Jinja template you enter. Flashduty parses only the template below.

<Steps>
  <Step title="Open the notification settings of the alert rule">
    In Logpoint, go to **Settings** → **Knowledge Base** → **Alert Rules**, find the rule, and click the **Setup Notification** icon in its Actions column. To set several rules at once, select them and choose **Setup Notifications of Selected Alert Rules** from the **MORE** dropdown.
  </Step>

  <Step title="Configure the HTTP Notification">
    1. Click **HTTP Notification** and select **Notify via HTTP**
    2. Set **Notification Trigger** to **Automatic** (sends on every rule trigger)
    3. Set **Protocol** to **HTTPS**, enter the host of the Push URL in **Base URL**, and set **Request Type** to **POST**
    4. In **Query String**, enter the part of the Push URL after `?` (it contains `integration_key`)
    5. Paste the template below into **Body**
    6. Set the **Threshold** and click **Finish**

    ```json theme={null}
    {
      "alertrule_id": "{{alertrule_id}}",
      "alert_name": "{{alert_name}}",
      "risk_level": "{{risk_level}}",
      "incident_id": "{{incident_id}}",
      "attack_category": "{{attack_category}}",
      "attack_tag": "{{attack_tag}}",
      "logpoint_name": "{{logpoint_name}}",
      "log_source": "{{log_source}}",
      "user_id": "{{user_id}}",
      "rows_count": "{{rows_count}}",
      "search_link": "{{search_link}}",
      "detection_timestamp": "{{detection_timestamp}}"
    }
    ```

    <Warning>
      Keep `alertrule_id`; Flashduty rejects a request without it. Logpoint substitutes placeholder text as-is, so a double quote in a rule name or another value breaks the JSON. Remove that field or avoid double quotes in rule names.
    </Warning>
  </Step>

  <Step title="Verify">
    Trigger the alert rule (or wait for it to match) and confirm Flashduty receives one alert titled with the rule name. The Logpoint HTTP Notification has no test button.
  </Step>
</Steps>

## Alert Key

***

Flashduty uses `alertrule_id` (`{{alertrule_id}}`) as the Alert Key. The Logpoint documentation defines it as the ID of the alert. When the same rule triggers again it merges into the alert that is still open. `incident_id` changes on every trigger, so it is kept only as a label. Changes to the rule name, risk level or number of matching logs do not change the Alert Key.

## Status and severity

***

Flashduty maps severity from `risk_level` (`{{risk_level}}`):

| `risk_level` | Flashduty severity |
| :- | :- |
| `critical`, `high` | Critical |
| `medium` | Warning |
| `low` | Info |
| Empty or any other value | Warning |

The Logpoint documentation does not list every `risk_level` value; its examples use `medium` and `high`, and `critical` and `low` are inferred from the risk options in the rule editor.

## Alerts do not recover

***

Logpoint sends no recovery notification. In the channel that receives this integration, turn on the [auto-resolve timeout](/en/on-call/channel/create-edit). 24 hours is a reasonable start; adjust it to how quickly your team handles alerts.

## Troubleshooting

***

* **Logpoint sends no request**: confirm Notification Trigger is **Automatic** and the rule is enabled and actually matching
* **Flashduty returns a parameter error**: confirm the Body is valid JSON and keeps `alertrule_id`; double quotes in a log source or rule name break the JSON
* **The alert title is `Logpoint alert <id>`**: `alert_name` is empty or was not rendered; check the placeholder spelling in the template
* **The alert never closes**: this is expected; turn on the auto-resolve timeout

See [Logpoint Reserved Jinja Placeholders](https://archive-docs.guardsix.com/docs/alerts-and-incident/en/release-7.8.0/Logpoint%20Reserved%20Jinja%20Placeholders.html) and [Alert Notifications](https://archive-docs.guardsix.com/docs/alerts-and-incident/en/release-7.8.0/Alert/Setting%20Up%20Alert%20Notifications.html) for more placeholders.
