> ## Documentation Index
> Fetch the complete documentation index at: https://docs.flashduty.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Panther alert integration

> Send Panther detection alerts to Flashduty On-call through a Panther Custom Webhook alert destination.

Use a Panther Custom Webhook alert destination to send alerts from rules, policies and other detections to Flashduty On-call. Each Panther alert maps to one Flashduty alert. Panther delivers an alert to a destination once and sends no status-change or resolve notification, so Flashduty alerts do not recover on their own. Turn on auto-close for the channel.

<div className="hide">
  ## In Flashduty On-call

  ***

  You can get the integration push URL in either of the following ways.

  ### Use a dedicated integration

  1. Open the Flashduty console, choose **Channels**, and open a channel
  2. Choose **Settings** → **Integrations** → **Dedicated integrations**, then click **Add an integration**
  3. Choose **Panther** and click **Save**
  4. Open the generated integration card and copy the **push URL**

  ### Use a shared integration

  1. Open the Flashduty console and choose **Integration Center → Alert events**
  2. Choose **Panther** and enter an integration name
  3. Configure the default route and pick a channel; you can add more rules under **Routes** after creation
  4. Click **Save** and copy the generated **push URL**
</div>

## In Panther

***

<Steps>
  <Step title="Create the Custom Webhook destination">
    1. Log in to the Panther Console and click **Alert Destinations** in the left sidebar
    2. Click **Create New** (or **+Add your first Destination**) and choose **Custom Webhook**
    3. Fill out the form:
       * **Display Name**: a name of your choice, for example `Flashduty`
       * **Custom Webhook URL**: paste the full Flashduty push URL
       * **Severity Levels**: the alert severities to send
       * **Default Alert Types**: the alert types to send
       * **Log Types**: all log types by default; narrow them if needed
    4. Click **Add Destination**

    Panther sends an HTTP `POST` with a JSON body, expects a `2XX` response, and retries up to 10 times on failure. The Flashduty push URL carries its own credential, so no custom HTTP header is needed.
  </Step>

  <Step title="Send a test alert">
    On the final page, click **Send Test Alert**. The Panther documentation does not show the body of the test request, so Flashduty handles it as an ordinary alert: it opens an alert under the request's `alertId`. It is not linked to any real alert and no recovery follows, so close it manually once you see it.
  </Step>

  <Step title="Turn on auto-close">
    For the channel that receives Panther alerts, turn on [auto-close](/en/on-call/channel/create-edit). A duration of 24 hours is a reasonable start; adjust it to how fast your team handles these alerts.
  </Step>

  <Step title="Verify">
    Wait for a detection to match (or re-dispatch an alert from its details page in Panther) and confirm Flashduty receives the alert.
  </Step>
</Steps>

## Alert Key

***

Flashduty uses the `alertId` field of the body as the Alert Key. Panther describes it as "Identifier of the alert in Panther Backend". Manually re-sending the same Panther alert from its details page lands on the same Flashduty alert.

Changes to the title, severity or description do not change the Alert Key. A request without `alertId` returns a parameter error.

## Status and severity

***

The Panther Custom Webhook has no status field, so every delivery is a trigger event.

| Panther `severity` | Flashduty severity |
| :- | :- |
| `CRITICAL`, `HIGH` | Critical |
| `MEDIUM` | Warning |
| `LOW`, `INFO` | Info |
| Empty or other | Warning |

Alert labels carry the detection name, detection ID (`id`), alert ID, alert type, raw severity, alert link and `tags`. `alertContext` is defined by the detection author and may hold raw log fields, so it is not copied into the alert; `runbook` is not copied either.

## Troubleshooting

***

* **Panther shows a delivery failure**: confirm the push URL is complete and includes `integration_key`; Panther retries up to 10 times when Flashduty returns a non-`2XX` response
* **No alert arrives**: confirm the destination's **Severity Levels**, **Default Alert Types** and **Log Types** cover the alert, and check the detection's destination routing
* **An alert never closes**: Panther sends no resolve notification, so turn on auto-close for the channel
* **A test alert appears**: it comes from **Send Test Alert** and is handled as an ordinary alert; close it manually

For more details, see the Panther documentation [Custom Webhook Destination](https://docs.panther.com/alerts/destinations/custom_webhook).
