Skip to main content
Use a Panther Custom Webhook alert destination to send alerts from rules, policies and other detections to Flashduty On-call. Each Panther alert maps to one Flashduty alert. Panther delivers an alert to a destination once and sends no status-change or resolve notification, so Flashduty alerts do not recover on their own. Turn on auto-close for the channel.

In Flashduty On-call


You can get the integration push URL in either of the following ways.

Use a dedicated integration

  1. Open the Flashduty console, choose Channels, and open a channel
  2. Choose Settings → Integrations → Dedicated integrations, then click Add an integration
  3. Choose Panther and click Save
  4. Open the generated integration card and copy the push URL

Use a shared integration

  1. Open the Flashduty console and choose Integration Center → Alert events
  2. Choose Panther and enter an integration name
  3. Configure the default route and pick a channel; you can add more rules under Routes after creation
  4. Click Save and copy the generated push URL

In Panther


1

Create the Custom Webhook destination

  1. Log in to the Panther Console and click Alert Destinations in the left sidebar
  2. Click Create New (or +Add your first Destination) and choose Custom Webhook
  3. Fill out the form:
    • Display Name: a name of your choice, for example Flashduty
    • Custom Webhook URL: paste the full Flashduty push URL
    • Severity Levels: the alert severities to send
    • Default Alert Types: the alert types to send
    • Log Types: all log types by default; narrow them if needed
  4. Click Add Destination
Panther sends an HTTP POST with a JSON body, expects a 2XX response, and retries up to 10 times on failure. The Flashduty push URL carries its own credential, so no custom HTTP header is needed.
2

Send a test alert

On the final page, click Send Test Alert. The Panther documentation does not show the body of the test request, so Flashduty handles it as an ordinary alert: it opens an alert under the request’s alertId. It is not linked to any real alert and no recovery follows, so close it manually once you see it.
3

Turn on auto-close

For the channel that receives Panther alerts, turn on auto-close. A duration of 24 hours is a reasonable start; adjust it to how fast your team handles these alerts.
4

Verify

Wait for a detection to match (or re-dispatch an alert from its details page in Panther) and confirm Flashduty receives the alert.

Alert Key


Flashduty uses the alertId field of the body as the Alert Key. Panther describes it as “Identifier of the alert in Panther Backend”. Manually re-sending the same Panther alert from its details page lands on the same Flashduty alert. Changes to the title, severity or description do not change the Alert Key. A request without alertId returns a parameter error.

Status and severity


The Panther Custom Webhook has no status field, so every delivery is a trigger event. Alert labels carry the detection name, detection ID (id), alert ID, alert type, raw severity, alert link and tags. alertContext is defined by the detection author and may hold raw log fields, so it is not copied into the alert; runbook is not copied either.

Troubleshooting


  • Panther shows a delivery failure: confirm the push URL is complete and includes integration_key; Panther retries up to 10 times when Flashduty returns a non-2XX response
  • No alert arrives: confirm the destination’s Severity Levels, Default Alert Types and Log Types cover the alert, and check the detection’s destination routing
  • An alert never closes: Panther sends no resolve notification, so turn on auto-close for the channel
  • A test alert appears: it comes from Send Test Alert and is handled as an ordinary alert; close it manually
For more details, see the Panther documentation Custom Webhook Destination.