In Flashduty On-call
Get an integration push URL in either of the two ways below. Choose the Standard Alert Event integration type in both, not Microsoft Sentinel.
Use a dedicated integration
- In the Flashduty console, go to Channels and open a channel
- Go to Settings → Integrations → Dedicated integrations and click Add an integration
- Select Standard Alert Event and click Save
- Open the generated integration card and copy the Push URL, in the form
https://api.flashcat.cloud/event/push/alert/standard?integration_key=<integration key>
Use a shared integration
- In the Flashduty console, go to Integration Center → Alert Events
- Select Standard Alert Event and enter an integration name
- Configure the default route and select a channel; you can add more rules under Routes after creation
- Click Save and copy the generated Push URL
Configure in Microsoft Sentinel
There are two parts: create a Logic App that starts with the Microsoft Sentinel incident trigger (called a playbook in Sentinel), then create automation rules that run it.
Create the Logic App
- Create a Logic App and choose Microsoft Sentinel incident as the workflow trigger. Only playbooks that start with an incident trigger can be selected by incident automation rules
- After the trigger, add the built-in HTTP action and fill in its fields as described in the next section
- Save the workflow
Create the automation rules
In Microsoft Sentinel, go to Configuration → Automation (in the Defender portal: Microsoft Sentinel → Configuration → Automation), click Create → Automation rule, and create the two rules below. Both use the Run playbook action with the Logic App from the previous step:
If the playbook appears grayed out in the list, Sentinel has no permission on its resource group: click Manage playbook permissions, select the resource group and click Apply (this needs the Owner role on the resource group).
HTTP action
Fields of the HTTP action:
Below is the JSON definition of this HTTP action; in the Logic App Code view it goes under
actions. A string that starts with @ and is a single expression is a Logic App expression evaluated from the Sentinel incident trigger output; the value is emitted as JSON, so a title containing quotes does not break the body:
Field mapping
Recovery and deduplication
- When the incident is closed (Status becomes
Closed), the Logic App sends an event withevent_statusset toOk, and Flashduty closes the alert with the same Alert Key. - Sentinel also fires When incident is updated when alerts, comments or tags are added. The update rule above runs only on status or severity changes; if you remove those conditions, every update is pushed, and repeated events with the same Alert Key merge into the original alert.
event_statusmust be one ofCritical,Warning,Info,Ok(capitalized); Flashduty rejects other values.- An incident that groups several Sentinel alerts is pushed as one Flashduty alert; the title and description come from the incident itself.
Troubleshooting
- Flashduty returns
InvalidParameter: check thatevent_statusis one of the four capitalized values and thattitle_ruleis not empty - The HTTP action returns a 4xx about authentication or routing: the push URL lacks
integration_key, or it is not the push URL of a Standard Alert Event integration - The automation rule does not run the Logic App: confirm the playbook starts with the Microsoft Sentinel incident trigger and that Sentinel has permission on its resource group
- The alert does not recover: confirm the update rule ran when the status became
Closed, and thatevent_statuswasOkin the Logic App run history