Skip to main content
Use a Sublime Security webhook Action to send messages flagged by detection rules to Flashduty On-call. One message (one message group) maps to one alert, and the alert title is the name of the highest-severity rule that flagged it. Sublime pushes only when a message is flagged and sends no resolve notification, so Flashduty alerts do not recover automatically.

In Flashduty On-call


You can get the integration push URL in either of two ways.

Use a dedicated integration

  1. In the Flashduty console, select Channel and open a channel
  2. Select Configuration → Integrations → Private integration, then click Add an integration
  3. Select Sublime Security and click Save
  4. Open the integration card and copy the push URL

Use a shared integration

  1. In the Flashduty console, go to Integration Center → Alert Events
  2. Select Sublime Security and enter an integration name
  3. Configure the default route and choose a channel; you can add more rules under Routes after creation
  4. Click Save and copy the generated push URL

In Sublime Security


1

Create a webhook Action

  1. In the Sublime dashboard, go to Manage → Actions in the left navigation, click New Action, and select Webhook
  2. Enter a name and paste the full Flashduty push URL, including integration_key, as the endpoint URL
  3. Click Save. Sublime then opens the Attach to Rules dialog, where you can select existing rules and click Attach selected rules
Sublime requires the receiver to return a 2xx response within 10 seconds, which Flashduty does.
2

Choose the message group scope

The webhook Scope has three options: Flagged Messages (when a flagged message is received in a message group), All Messages (all messages in a message group), and First Message Only (the first message received in a message group). Pushes for the same message group share one Alert Key and merge into one alert.
3

Attach it to rules

Add the Action to the detection rules or automations you want to be notified about. On a new account the rules from Sublime’s feed are inactive, so activate at least one rule before the webhook can fire. Sublime’s documentation does not describe a test button for webhooks, so after a message is flagged, confirm that an alert appears in Flashduty.

Events and recovery


Sublime sends no resolve notification. Enable auto-close on timeout for the channel, with 7 days suggested, or close alerts by hand once the message is handled.

Alert Key


The Alert Key is data.message.canonical_id, or data.message.id when it is absent. Sublime documents canonical_id as the identifier of the message group a message belongs to, shared when the same message is delivered to several mailboxes. Changes to identifiers, classification, rule names or severity do not change the Alert Key. A push with neither field is rejected, and the error names the field.

Severity


Flashduty uses the highest severity among flagged_rules:

Labels


The push carries no subject or body; use message_id to look the message up in Sublime. Flashduty does not store the user email in actor.

Signature header


Sublime sends an X-Sublime-Signature header on every delivery, in the format t=<Unix timestamp>,v0=<HMAC signature>. The Flashduty push URL authenticates with integration_key and does not verify this header, so no extra setup is needed.

Troubleshooting


  • No alerts arrive: confirm the Action is attached to a rule and check the Action’s message group scope
  • Flashduty returns a parameter error: the push has neither data.message.canonical_id nor data.message.id, which happens for a manual trigger with no message selected
  • Alerts never close: Sublime sends no recovery, so enable auto-close on timeout for the channel
For field details, see the Sublime webhook documentation.