In Flashduty On-call
You can obtain an integration push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, select Channel and open a channel
- Select Configuration → Integrations → Private integration, then click Add an integration
- Select Sematext, then click Save
- Open the generated integration card and copy the Push URL
Use a shared integration
- In the Flashduty console, select Integration Center → Alert Events
- Select Sematext and enter an integration name
- Configure the default route and select a channel; after creation, add more rules under Route if needed
- Click Save and copy the generated Push URL
Configure Sematext
1
Create a Custom notification hook
- Sign in to Sematext Cloud (US region
apps.sematext.comor EU regionapps.eu.sematext.com) and select Alerts → Notification Hooks in the left menu - Click New Notification Hook, then click the Custom card
- Set Hook Name to
Flashduty - Paste the full Flashduty push URL into URL. The URL must include
integration_key - Set Send data as to Json and HTTP method to Post
- Click Add parameter and add each parameter in the table below. The left column is the parameter name and the right column is its value; Sematext replaces the
$variables when it sends the notification
When you are done, the request body in Preview should be:
- Click Send Test Notification and confirm that the request succeeds, then click Save Notification Hook
2
Use the hook in alert rules
- Open the alert rule you want to connect (Alerts → Alert Rules) and go to the Notifications tab of the edit page
- Turn on Alert me when the value goes back to non-alert level. It is off by default; without it Sematext never sends the back-to-normal notification and the Flashduty alert does not recover
- Select the
Flashdutyhook in the Additionally send to drop-down and save the rule. When Use account-default notification hooks for this alert is off, the drop-down is named Send to
3
Verify
- Make an alert rule fire. For example, create a Heartbeat alert for a host and stop the Sematext Agent on it, then confirm that Flashduty receives an active alert
- Resume data collection, wait for Sematext to send the back-to-normal notification, and confirm that the alert recovers
The request sent by Send Test Notification does not belong to any alert rule. Flashduty returns success and does not create an alert.
Alert Key
Sematext adds the alert rule ID (
ruleId) and rule name (alertName) to every alert notification. When the rule uses Group by, it also adds the group tag values that fired the alert (filters, for example {os.host=web-01}). You do not need to configure these fields in the hook.
The Alert Key is computed from ruleId and all group tags in filters; the order of the tags does not matter. As a result:
- Trigger and recovery notifications for the same alert rule and group go to the same alert
- When an alert rule is grouped by a tag such as host, each group gets its own alert
- Changes to the priority, description, time or rule name do not change the Alert Key
alertName but no ruleId are rejected.
Status and severity
The alert recovers when
backToNormal is true; any other value is treated as a trigger. The severity comes from the alert rule priority ($priority):
Matching ignores case.
Labels
Troubleshooting
- Flashduty returns a parameter error: Make sure the URL is complete and includes
integration_key, and that Send data as is set to Json - The alert does not recover: Make sure Alert me when the value goes back to non-alert level is on in the rule’s Notifications tab, that the hook has the
backToNormalparameter with the value$backToNormal, and that the group is still sending data - Alerts for different hosts of the same rule are merged: Set Group by on a host tag (such as
os.host) in the alert rule and set the aggregation to all separately - Every alert has the Warning severity: Check
priorityin the pushed content; see Status and severity above