In Flashduty On-call
Get the integration email address in either of the two ways below. In both cases choose the Email integration type, not OPNsense.
Use a dedicated integration
- In the Flashduty console, select Channels and open a channel
- Select Settings → Integrations → Dedicated integrations and click Add an integration
- Select Email and click Save
- Open the new integration card, copy the email address, then configure the push rules below
Use a shared integration
- In the Flashduty console, select Integration Center → Alert events
- Select Email, enter an integration name and copy the email address
- Configure the push rules below
- Set a default route, select a channel and click Save
Configure OPNsense
- SMTP: go to Services → Monit → Settings, enable Monit under General Settings, and enter the SMTP server address, port and credentials
- Recipient: under Alert Settings, add an alert and set Recipient to the Flashduty email integration address
- Mail format: in Mail format of that alert, enter the line below. The default subject has no host name and no fixed separator between service and event, so the rules could not extract a stable Alert Key from it; with this fixed format the rules can process every email
- Recovery notifications: Monit sends a recovery email in the same format when a service recovers. Leave Not on off so that every event, including recovery, is emailed
Configure push rules in Flashduty
In the title
[$HOST] [$SERVICE] $EVENT, $HOST and $SERVICE are the same in the failure email and the recovery email; only $EVENT differs. The rules use the first two parts as the Alert Key, so a recovery email closes the matching alert.
- Set Push mode to Trigger or close alert based on rules
- Add the two rules below in this order. Each rule’s condition is Email title Match the given regex, and the Alert Key is extracted from the Email title
- Under Default rules, choose: if none of the above rules match, discard email
Events in the email title
$EVENT is Monit’s description of the event. Failures and recoveries come in pairs:
Limitations
- Type and severity: in Flashduty these alerts show the Email integration type, and their severity is always Warning. You can adjust it with alert pipelines based on the title.
- Other events: Monit events not in the table above are handled as trigger alerts. If an event type has no matching recovery email, turn on the auto-resolve timeout in the channel that receives this integration; 24 hours is a reasonable start.
- Title format: if you change
Subjectin Mail format, update the regexes in the rules to match.