Skip to main content
Use a Custom notification hook in Sematext Cloud to send alert rule notifications to Flashduty On-call. Each alert rule (or each group of the rule when it uses Group by) maps to one Flashduty alert: the alert triggers when the rule fires and recovers automatically when Sematext sends the back-to-normal notification.

In Flashduty On-call


You can obtain an integration push URL in either of the following ways.

Use a dedicated integration

  1. In the Flashduty console, select Channel and open a channel
  2. Select Configuration → Integrations → Private integration, then click Add an integration
  3. Select Sematext, then click Save
  4. Open the generated integration card and copy the Push URL

Use a shared integration

  1. In the Flashduty console, select Integration Center → Alert Events
  2. Select Sematext and enter an integration name
  3. Configure the default route and select a channel; after creation, add more rules under Route if needed
  4. Click Save and copy the generated Push URL

Configure Sematext


1

Create a Custom notification hook

  1. Sign in to Sematext Cloud (US region apps.sematext.com or EU region apps.eu.sematext.com) and select Alerts → Notification Hooks in the left menu
  2. Click New Notification Hook, then click the Custom card
  3. Set Hook Name to Flashduty
  4. Paste the full Flashduty push URL into URL. The URL must include integration_key
  5. Set Send data as to Json and HTTP method to Post
  6. Click Add parameter and add each parameter in the table below. The left column is the parameter name and the right column is its value; Sematext replaces the $ variables when it sends the notification
When you are done, the request body in Preview should be:
  1. Click Send Test Notification and confirm that the request succeeds, then click Save Notification Hook
Do not add $applicationToken. Anyone who has the App token can read the data in that App, and Flashduty does not need it.
2

Use the hook in alert rules

  1. Open the alert rule you want to connect (Alerts → Alert Rules) and go to the Notifications tab of the edit page
  2. Turn on Alert me when the value goes back to non-alert level. It is off by default; without it Sematext never sends the back-to-normal notification and the Flashduty alert does not recover
  3. Select the Flashduty hook in the Additionally send to drop-down and save the rule. When Use account-default notification hooks for this alert is off, the drop-down is named Send to
To send every new alert rule to Flashduty, set the hook as an account-default hook.
3

Verify

  1. Make an alert rule fire. For example, create a Heartbeat alert for a host and stop the Sematext Agent on it, then confirm that Flashduty receives an active alert
  2. Resume data collection, wait for Sematext to send the back-to-normal notification, and confirm that the alert recovers
Sematext sends the back-to-normal notification only when the rule still receives data for that group and the value is back within the threshold. A Group by group that stops reporting data never gets one: for example, a log count rule grouped by host, where the host stops writing logs. Its Flashduty alert stays active until you close it. To detect a host that goes silent, use a Heartbeat alert.
The request sent by Send Test Notification does not belong to any alert rule. Flashduty returns success and does not create an alert.

Alert Key


Sematext adds the alert rule ID (ruleId) and rule name (alertName) to every alert notification. When the rule uses Group by, it also adds the group tag values that fired the alert (filters, for example {os.host=web-01}). You do not need to configure these fields in the hook. The Alert Key is computed from ruleId and all group tags in filters; the order of the tags does not matter. As a result:
  • Trigger and recovery notifications for the same alert rule and group go to the same alert
  • When an alert rule is grouped by a tag such as host, each group gets its own alert
  • Changes to the priority, description, time or rule name do not change the Alert Key
Requests that carry alertName but no ruleId are rejected.

Status and severity


The alert recovers when backToNormal is true; any other value is treated as a trigger. The severity comes from the alert rule priority ($priority): Matching ignores case.

Labels


Troubleshooting


  • Flashduty returns a parameter error: Make sure the URL is complete and includes integration_key, and that Send data as is set to Json
  • The alert does not recover: Make sure Alert me when the value goes back to non-alert level is on in the rule’s Notifications tab, that the hook has the backToNormal parameter with the value $backToNormal, and that the group is still sending data
  • Alerts for different hosts of the same rule are merged: Set Group by on a host tag (such as os.host) in the alert rule and set the aggregation to all separately
  • Every alert has the Warning severity: Check priority in the pushed content; see Status and severity above
For the meaning of each variable, see Sematext Custom Webhooks Parameters.