engage (triggered) and, once the condition clears, release. Flashduty links the two messages with one Alert Key: engage creates the alert and release recovers it. Flow alerts are sent once and never released.
In Flashduty On-call
Create either a dedicated or shared ntopng alert integration and copy its complete Push URL.
Dedicated integration
- In the Flashduty console, select Channels and open a channel
- Go to Settings → Integrations → Dedicated integrations and click Add an integration
- Select ntopng and click Save
- Open the integration card and copy the Push URL
Shared integration
- In the Flashduty console, go to Integration center → Alert events
- Select ntopng and enter an integration name
- Configure the default route and choose a channel; you can add more rules under Routes after creation
- Click Save and copy the generated Push URL
In ntopng
1
Create a Webhook endpoint
- Log in to ntopng as an administrator
- Go to Notifications → Endpoints and click +
- Choose the Webhook endpoint type and name it
Flashduty - Paste the complete Flashduty Push URL, including
integration_key, into the webhook URL - Leave Shared Secret, Username, and Password empty. Flashduty authenticates with the
integration_keyin the Push URL and does not check them. If you set a Shared Secret, it is included in every request but never stored in a Flashduty alert
2
Create a recipient
- Go to Notifications → Recipients and click +
- Select the
Flashdutyendpoint you just created and name the recipient - Change Notifications Type to Alerts. The default is Active Scan Reports, which sends no alerts, so Flashduty receives nothing
- Set the minimum severity, alert categories, entity types, and host pools as needed; only alerts that match are sent
- Click Check to send a test request, then click Add to save the recipient
3
Verify the lifecycle
Trigger a host alert (for example, let a host breach one of ntopng’s threshold checks) and confirm Flashduty shows an active alert. After the condition clears and ntopng releases the alert, confirm the Flashduty alert recovers.
Alert Key
The
engage and release messages for one alert carry the same interface ID (ifid), entity type (entity_id), entity value (entity_val), alert type (alert_id), and subtype (subtype). Flashduty builds the Alert Key from these five fields. ntopng itself tells engaged alerts apart by entity value, alert type, and subtype. The score (score), timestamps, host name, and check period change between messages and are not part of the Alert Key.
A flow alert has action set to store and each one becomes its own alert. When ntopng resends the same flow after its conditions change, the Alert Key stays the same: it is built from the interface, alert type, VLAN, client and server IP and port, protocol, and the flow’s first-seen time.
If an engage or release message lacks alert_id, entity_id, or entity_val, Flashduty returns a parameter error that names the field.
Severity
ntopng derives severity from
score; Flashduty maps it as follows. A missing or non-numeric score is treated as Info.
Recovery and testing
release: closes the alert with the same Alert Key and keeps the severity it had before the release.store(flow alerts) and any alert without a release message: does not recover on its own. Turn on auto-close in the integration or channel, with a suggested duration of 24 hours.- Check button: ntopng sends a request with
version0.2and an emptyalertslist. Flashduty returns success and opens one Info alert titledntopng test notificationunder its own Alert Key. It never merges with a real alert and does not recover on its own, so close it manually.
Troubleshooting
- ntopng reports a delivery failure: confirm the webhook URL is complete, includes
integration_key, and that the ntopng server can reachapi.flashcat.cloud. ntopng retries a failed delivery 3 times - Flashduty returns a parameter error: check that the body is JSON and that every
engageandreleasealert hasalert_id,entity_id, andentity_val - An alert does not recover: flow alerts have no release message; for other alerts ntopng must release them first, so check on the ntopng Alerts page whether the alert is still engaged
- No alerts arrive: check the recipient’s minimum severity, alert category, and entity filters, and that alert generation is enabled in ntopng