In Flashduty On-call
You can get the integration push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, go to Channels and open a channel
- Select Configuration → Integrations → Private integration, then click Add an integration
- Select IBM SevOne NPM and click Save
- Open the new integration card and copy the push URL
Use a shared integration
- In the Flashduty console, go to Integration Center → Alert Events
- Select IBM SevOne NPM and enter an integration name
- Configure the default route and select a channel. You can add more rules under Routes after creation
- Click Save and copy the generated push URL
Configure SevOne NPM
Create two Webhook Definitions: one sent when an alert triggers, one sent when it clears.
1
Create the trigger webhook
- Sign in to SevOne NMS, go to Events → Configuration → Webhook Definition Manager, and click add
- Set Definition Type to Policy and enter
Flashduty triggeras the Webhook Definition Name - Paste the complete Flashduty push URL into Destination URL
- Set Request Method to POST and Content Type to application/json
- Paste this template into Body:
- Click Test Definition to check that the request can be sent, then click Save
2
Create the clear webhook
Create a second definition the same way, named
Flashduty clear, with this Body (event is clear, plus closure_message):3
Assign the webhooks to policies
- Go to Events → Configuration → Policy Browser, select the policies to connect, and click Assign Webhooks
- Select
Flashduty trigger, check Trigger under Apply To, and save - Click Assign Webhooks again, select
Flashduty clear, check Clear under Apply To, and save
4
Verify the lifecycle
Let a policy trigger and confirm Flashduty shows an active alert. Then let it clear (the condition recovers, or acknowledge it manually under Events → Alerts) and confirm the alert recovers.
Payload
Each field is the substitution of one SevOne variable (see IBM’s Webhook Definition Manager):
SevOne outputs
n/a for a variable a policy type does not support (for example $pluginName on flow policies). Flashduty ignores n/a.
Alert Key
Flashduty uses
alert_id ($alertId, described by IBM as “The id of the triggered alert”) as the Alert Key. Repeated triggers and the clear of one SevOne alert carry the same alert_id, so they land on one Flashduty alert. Changing the policy name, severity or message does not change the Alert Key.
If alert_id is empty, n/a, or still the unsubstituted $alertId, Flashduty returns a parameter error.
Status and severity
$alertState is the policy severity. A clear event keeps the alert’s severity and sets the status to recovered.
FAQ
Does Test Definition create an alert in Flashduty?
Does Test Definition create an alert in Flashduty?
IBM documents only that Test Definition returns the status code, response header and body; it does not document the test body. If the test request carries a valid
alert_id and event, it creates or closes an alert like a real notification; without them Flashduty returns a parameter error. Close any alert created by a test manually.Can I configure only the trigger webhook?
Can I configure only the trigger webhook?
Alerts arrive, but Flashduty alerts do not recover automatically. Enable auto-close on timeout in the integration or channel, or add the clear webhook.
Does a policy that keeps triggering create several alerts?
Does a policy that keeps triggering create several alerts?
No. Every trigger of the same SevOne alert has the same
alert_id and merges into one Flashduty alert.Can trap alerts be connected?
Can trap alerts be connected?
The templates on this page are for the Policy type. Trap definitions use a different variable set and are out of scope for this integration.
Troubleshooting
- SevOne cannot deliver: check that Destination URL is the complete push URL; for a self-signed TLS certificate, check Allow insecure webhook connection, and use a certificate with a SAN rather than only a Common Name
- Flashduty returns a parameter error: check that Content Type is application/json,
eventistriggerorclear, andalert_idhas a value - Alert does not recover: check that the clear webhook is assigned to the same policy with Clear checked