> ## Documentation Index
> Fetch the complete documentation index at: https://docs.flashduty.com/llms.txt
> Use this file to discover all available pages before exploring further.

# OPNsense alert integration

> OPNsense's Monit module sends service alerts by email; use a Flashduty email integration with rules to trigger and close OPNsense alerts.

OPNsense monitors services with the **Monit** module (**Services → Monit**) and sends alerts by email. The actions available in the module are sending email, restarting a service and stopping monitoring; there is no webhook. The Flashduty [email integration](/en/on-call/integration/alert-integration/alert-sources/email) receives these emails and uses rules on the email title to decide whether each one triggers or resolves an alert, so no separate OPNsense integration is needed: create an email integration in Flashduty, add its email address as the Monit alert recipient, and configure the push rules below.

<div className="hide">
  ## In Flashduty On-call

  ***

  Get the integration email address in either of the two ways below. **In both cases choose the Email integration type**, not OPNsense.

  ### Use a dedicated integration

  1. In the Flashduty console, select **Channels** and open a channel
  2. Select **Settings** → **Integrations** → **Dedicated integrations** and click **Add an integration**
  3. Select **Email** and click **Save**
  4. Open the new integration card, copy the **email address**, then configure the push rules below

  ### Use a shared integration

  1. In the Flashduty console, select **Integration Center → Alert events**
  2. Select **Email**, enter an integration name and copy the **email address**
  3. Configure the push rules below
  4. Set a default route, select a channel and click **Save**
</div>

## Configure OPNsense

***

1. **SMTP**: go to **Services → Monit → Settings**, enable Monit under **General Settings**, and enter the SMTP server address, port and credentials
2. **Recipient**: under **Alert Settings**, add an alert and set **Recipient** to the Flashduty email integration address
3. **Mail format**: in **Mail format** of that alert, enter the line below. The default subject has no host name and no fixed separator between service and event, so the rules could not extract a stable Alert Key from it; with this fixed format the rules can process every email

```
Subject: [$HOST] [$SERVICE] $EVENT
```

4. **Recovery notifications**: Monit sends a recovery email in the same format when a service recovers. Leave **Not on** off so that every event, including recovery, is emailed

## Configure push rules in Flashduty

***

In the title `[$HOST] [$SERVICE] $EVENT`, `$HOST` and `$SERVICE` are the same in the failure email and the recovery email; only `$EVENT` differs. The rules use the first two parts as the Alert Key, so a recovery email closes the matching alert.

1. Set **Push mode** to **Trigger or close alert based on rules**
2. Add the two rules below in this order. Each rule's condition is **Email title** **Match** the given regex, and the Alert Key is extracted from the **Email title**
3. Under **Default rules**, choose: if none of the above rules match, **discard email**

Rule 1: close the alert

```
Condition: Email title  Match  /^\[.+?\] \[.+?\] (Exists|.* (succeeded|recovery))$/
Regex: /^\[(.+?)\] \[(.+?)\] /
```

Rule 2: trigger an alert

```
Condition: Email title  Match  /^\[.+?\] \[.+?\] /
Regex: /^\[(.+?)\] \[(.+?)\] /
```

The close rule comes before the trigger rule. The Alert Key is the host name plus the service name, so repeated failures of the same service on the same host merge into one alert. The default rule discards mail that was not sent in the format above (for example from other alerts that have no **Mail format** set) so it does not create alerts that can never close on their own.

## Events in the email title

***

`$EVENT` is Monit's description of the event. Failures and recoveries come in pairs:

| Event type | Failure | Recovery |
| :- | :- | :- |
| status | `Status failed` | `Status succeeded` |
| connection | `Connection failed` | `Connection succeeded` |
| checksum | `Checksum failed` | `Checksum succeeded` |
| timeout | `Timeout` | `Timeout recovery` |
| nonexist | `Does not exist` | `Exists` |

## Limitations

***

* **Type and severity**: in Flashduty these alerts show the Email integration type, and their severity is always Warning. You can adjust it with [alert pipelines](/en/on-call/integration/alert-integration/alert-pipelines) based on the title.
* **Other events**: Monit events not in the table above are handled as trigger alerts. If an event type has no matching recovery email, turn on the [auto-resolve timeout](/en/on-call/channel/create-edit) in the channel that receives this integration; 24 hours is a reasonable start.
* **Title format**: if you change `Subject` in **Mail format**, update the regexes in the rules to match.
