In Flashduty On-call
You can obtain an integration push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, select Channel and open a channel
- Select Configuration → Integrations → Private integration, then click Add an integration
- Select OpenObserve, then click Save
- Open the generated integration card and copy the Push URL
Use a shared integration
- In the Flashduty console, select Integration Center → Alert Events
- Select OpenObserve and enter an integration name
- Configure the default route and select a channel; after creation, add more rules under Route if needed
- Click Save and copy the generated Push URL
Configure OpenObserve
You need permission to manage alert templates and destinations.
1
Create a template
- In OpenObserve, open the Destination Templates tab on the Reliability (alerts) page and create a template of the webhook type
- Paste this JSON as the template body and save:
org_name, stream_name, and alert_name; Flashduty rejects a request that lacks any of them. You can remove the other fields.2
Create a destination
- Open the Notification Destinations tab on the same page and create a destination
- Set Template to the template from the previous step
- Set URL to the full Flashduty push URL, including
integration_key - Set Method to
POST - Headers can stay empty: Flashduty authenticates with the
integration_keyin the URL and does not depend onContent-Type
3
Use the destination in an alert
- Create or edit an OpenObserve alert and select the destination
- From OpenObserve 1.1, you can enable recovery notifications on the alert (
notify_on_recovery); when the alert recovers, OpenObserve posts one more request withalert_statusset toresolved. Earlier versions, and alerts without this option, send no recovery notification - Save the alert, wait for its condition to be met, and confirm Flashduty receives an active alert
Alert Key
Flashduty computes the Alert Key from
org_name, stream_type, stream_name, and alert_name, so the trigger, repeated triggers, and recovery of one OpenObserve alert share an Alert Key. Changes to the level, result count, threshold, trigger time, or episode_id do not change it; an empty stream_type counts as an empty value. A request without org_name, stream_name, or alert_name is rejected.
Renaming an OpenObserve alert, stream, or organization produces a new Alert Key.
Status and severity
An
alert_status of resolved recovers the alert; any other value triggers it. Before OpenObserve 1.1, {alert_status}, {alert_level}, and {episode_id} are not substituted and arrive as the literal template text. Flashduty treats them as empty, so the alert triggers as Warning.
Recovery
Flashduty receives a recovery request, and closes the alert automatically, only with OpenObserve 1.1 or later and recovery notifications enabled on the alert. Otherwise every firing is an independent one-shot notification with no recovery request. For these alerts, set auto-close after timeout on the Flashduty integration or channel with a suitable duration, or the alert stays active.
Labels
The template does not contain
{rows}, so Flashduty does not receive the log rows the query returned.
Troubleshooting
- Flashduty returns an invalid-parameter error: Check that the URL is complete and includes
integration_key, that the template containsorg_name,stream_name, andalert_name, and that the template is valid JSON - The alert does not recover: Check that OpenObserve is 1.1 or later and that the alert has recovery notifications enabled; otherwise configure auto-close after timeout
- The request fails when the alert name contains quotes or line breaks: OpenObserve fills variable values into the template as plain text, so a double quote or line break in the alert name can make the JSON invalid. Avoid these characters in alert names
- The destination has no test button: OpenObserve’s webhook destination has no test send. You can fire the alert once from the alert list with ⋮ → Trigger: that delivery has an empty
alert_levelandepisode_id, so Flashduty opens a Warning alert with no recovery request; close it manually or rely on auto-close