> ## Documentation Index
> Fetch the complete documentation index at: https://docs.flashduty.com/llms.txt
> Use this file to discover all available pages before exploring further.

# OpenObserve alert integration

> Send OpenObserve alerts to Flashduty On-call through a webhook template on an alert destination.

An OpenObserve webhook destination has no fixed request body: the body is the template you save. This integration defines one JSON template. Paste it into OpenObserve, and when an alert fires OpenObserve fills the variables in and posts the result to Flashduty. Each OpenObserve alert, identified by organization, stream type, stream, and alert name, maps to one Flashduty alert.

<div className="hide">
  ## In Flashduty On-call

  ***

  You can obtain an integration push URL in either of the following ways.

  ### Use a dedicated integration

  1. In the Flashduty console, select **Channel** and open a channel
  2. Select **Configuration** → **Integrations** → **Private integration**, then click **Add an integration**
  3. Select **OpenObserve**, then click **Save**
  4. Open the generated integration card and copy the **Push URL**

  ### Use a shared integration

  1. In the Flashduty console, select **Integration Center → Alert Events**
  2. Select **OpenObserve** and enter an integration name
  3. Configure the default route and select a channel; after creation, add more rules under **Route** if needed
  4. Click **Save** and copy the generated **Push URL**
</div>

## Configure OpenObserve

***

You need permission to manage alert templates and destinations.

<Steps>
  <Step title="Create a template">
    1. In OpenObserve, open the **Destination Templates** tab on the **Reliability** (alerts) page and create a template of the webhook type
    2. Paste this JSON as the template body and save:

    ```json theme={null}
    {
      "org_name": "{org_name}",
      "stream_type": "{stream_type}",
      "stream_name": "{stream_name}",
      "alert_name": "{alert_name}",
      "alert_type": "{alert_type}",
      "alert_level": "{alert_level}",
      "alert_status": "{alert_status}",
      "episode_id": "{episode_id}",
      "alert_count": "{alert_count}",
      "alert_agg_value": "{alert_agg_value}",
      "alert_operator": "{alert_operator}",
      "alert_threshold": "{alert_threshold}",
      "alert_period": "{alert_period}",
      "alert_url": "{alert_url}",
      "alert_description": "{alert_description}"
    }
    ```

    The template must contain `org_name`, `stream_name`, and `alert_name`; Flashduty rejects a request that lacks any of them. You can remove the other fields.
  </Step>

  <Step title="Create a destination">
    1. Open the **Notification Destinations** tab on the same page and create a destination
    2. Set **Template** to the template from the previous step
    3. Set **URL** to the full Flashduty push URL, including `integration_key`
    4. Set **Method** to `POST`
    5. **Headers** can stay empty: Flashduty authenticates with the `integration_key` in the URL and does not depend on `Content-Type`
  </Step>

  <Step title="Use the destination in an alert">
    1. Create or edit an OpenObserve alert and select the destination
    2. From OpenObserve 1.1, you can enable recovery notifications on the alert (`notify_on_recovery`); when the alert recovers, OpenObserve posts one more request with `alert_status` set to `resolved`. Earlier versions, and alerts without this option, send no recovery notification
    3. Save the alert, wait for its condition to be met, and confirm Flashduty receives an active alert
  </Step>
</Steps>

## Alert Key

***

Flashduty computes the Alert Key from `org_name`, `stream_type`, `stream_name`, and `alert_name`, so the trigger, repeated triggers, and recovery of one OpenObserve alert share an Alert Key. Changes to the level, result count, threshold, trigger time, or `episode_id` do not change it; an empty `stream_type` counts as an empty value. A request without `org_name`, `stream_name`, or `alert_name` is rejected.

Renaming an OpenObserve alert, stream, or organization produces a new Alert Key.

## Status and severity

***

| `alert_level` | Flashduty severity |
| :- | :- |
| `critical` | Critical |
| `warning`, `no_data`, empty, or any other value | Warning |

An `alert_status` of `resolved` recovers the alert; any other value triggers it. Before OpenObserve 1.1, `{alert_status}`, `{alert_level}`, and `{episode_id}` are not substituted and arrive as the literal template text. Flashduty treats them as empty, so the alert triggers as Warning.

## Recovery

***

Flashduty receives a recovery request, and closes the alert automatically, only with OpenObserve 1.1 or later and recovery notifications enabled on the alert. Otherwise every firing is an independent one-shot notification with no recovery request. For these alerts, set **auto-close after timeout** on the Flashduty integration or channel with a suitable duration, or the alert stays active.

## Labels

***

| Label | Source |
| :- | :- |
| `org` | `org_name` |
| `stream` / `stream_type` | Stream name and type |
| `check` | Alert name |
| `alert_type` | `realtime` or `scheduled` |
| `alert_level` / `alert_status` | Level and status |
| `episode_id` | ID of one firing episode (OpenObserve 1.1 and later) |
| `alert_count` / `alert_agg_value` | Query result count and aggregate value |
| `alert_operator` / `alert_threshold` / `alert_period` | Condition operator, threshold, and query time window |
| `url` | Link to the alert in OpenObserve |

The template does not contain `{rows}`, so Flashduty does not receive the log rows the query returned.

## Troubleshooting

***

* **Flashduty returns an invalid-parameter error**: Check that the URL is complete and includes `integration_key`, that the template contains `org_name`, `stream_name`, and `alert_name`, and that the template is valid JSON
* **The alert does not recover**: Check that OpenObserve is 1.1 or later and that the alert has recovery notifications enabled; otherwise configure auto-close after timeout
* **The request fails when the alert name contains quotes or line breaks**: OpenObserve fills variable values into the template as plain text, so a double quote or line break in the alert name can make the JSON invalid. Avoid these characters in alert names
* **The destination has no test button**: OpenObserve's webhook destination has no test send. You can fire the alert once from the alert list with **⋮ → Trigger**: that delivery has an empty `alert_level` and `episode_id`, so Flashduty opens a Warning alert with no recovery request; close it manually or rely on auto-close

For more variables, see [OpenObserve alert templates](https://openobserve.ai/docs/user-guide/management/templates/).
