In Flashduty On-call
Get an integration push URL in either of the two ways below. Choose the Standard Alert Event integration type in both, not Microsoft Defender for Cloud.
Use a dedicated integration
- In the Flashduty console, go to Channels and open a channel
- Go to Settings → Integrations → Dedicated integrations and click Add an integration
- Select Standard Alert Event and click Save
- Open the generated integration card and copy the Push URL, in the form
https://api.flashcat.cloud/event/push/alert/standard?integration_key=<integration key>
Use a shared integration
- In the Flashduty console, go to Integration Center → Alert Events
- Select Standard Alert Event and enter an integration name
- Configure the default route and select a channel; you can add more rules under Routes after creation
- Click Save and copy the generated Push URL
Configure in Microsoft Defender for Cloud
You need the Security admin role or Owner on the resource group; creating and editing Logic Apps needs Logic App Contributor.
Create the Logic App
- In the Azure portal, create a Consumption Logic App. Workflow automation only triggers Consumption Logic Apps
- Choose When a Defender for Cloud Alert is created or triggered as the workflow trigger. Do not use the legacy When a response to a Microsoft Defender for Cloud alert is triggered; workflow automation does not run Logic Apps that use it
- After the trigger, add the built-in HTTP action and fill in its fields as described in the next section
- Save the workflow
Create the workflow automation
- In the Defender for Cloud sidebar, select Workflow automation and click Add workflow automation
- Enter a name and description
- In the trigger conditions, select security alerts and limit the severity if needed
- Under Actions, select the Logic App you created; click Refresh if it is not listed
- Save
HTTP action
Fields of the HTTP action:
Below is the JSON definition of this HTTP action; in the Logic App Code view it goes under
actions. A string that starts with @ and is a single expression is a Logic App expression evaluated from the alert trigger output; the value is emitted as JSON, so an alert name containing quotes does not break the body:
Field mapping
Recovery and deduplication
Defender for Cloud workflow automation runs the Logic App only when an alert is created or triggered and sends nothing when the alert is dismissed, so alerts from this integration do not recover automatically. Enable auto-resolve timeout on the channel that receives this integration, with a suggested window of 3 days or the time your team usually takes to handle alerts; you can also close alerts manually in Flashduty.
Troubleshooting
- Flashduty returns
InvalidParameter: check thatevent_statusis one of the capitalizedCritical,Warning,Info, and thattitle_ruleis not empty - The Logic App is missing from the workflow automation list: the list shows only Consumption Logic Apps that use a Defender for Cloud connector; click Refresh after creating it
- The Logic App does not run: confirm the trigger is When a Defender for Cloud Alert is created or triggered and that the workflow automation trigger conditions (severity) cover the alert