In Flashduty On-call
You can get the integration push URL in either of two ways.
Use a dedicated integration
- In the Flashduty console, select Channel and open a channel
- Select Configuration → Integrations → Private integration, then click Add an integration
- Select Sublime Security and click Save
- Open the integration card and copy the push URL
Use a shared integration
- In the Flashduty console, go to Integration Center → Alert Events
- Select Sublime Security and enter an integration name
- Configure the default route and choose a channel; you can add more rules under Routes after creation
- Click Save and copy the generated push URL
In Sublime Security
1
Create a webhook Action
- In the Sublime dashboard, go to Manage → Actions in the left navigation, click New Action, and select Webhook
- Enter a name and paste the full Flashduty push URL, including
integration_key, as the endpoint URL - Click Save. Sublime then opens the Attach to Rules dialog, where you can select existing rules and click Attach selected rules
2
Choose the message group scope
The webhook Scope has three options: Flagged Messages (when a flagged message is received in a message group), All Messages (all messages in a message group), and First Message Only (the first message received in a message group). Pushes for the same message group share one Alert Key and merge into one alert.
3
Attach it to rules
Add the Action to the detection rules or automations you want to be notified about. On a new account the rules from Sublime’s feed are inactive, so activate at least one rule before the webhook can fire. Sublime’s documentation does not describe a test button for webhooks, so after a message is flagged, confirm that an alert appears in Flashduty.
Events and recovery
Sublime sends no resolve notification. Enable auto-close on timeout for the channel, with 7 days suggested, or close alerts by hand once the message is handled.
Alert Key
The Alert Key is
data.message.canonical_id, or data.message.id when it is absent. Sublime documents canonical_id as the identifier of the message group a message belongs to, shared when the same message is delivered to several mailboxes. Changes to identifiers, classification, rule names or severity do not change the Alert Key. A push with neither field is rejected, and the error names the field.
Severity
Flashduty uses the highest severity among
flagged_rules:
Labels
The push carries no subject or body; use
message_id to look the message up in Sublime. Flashduty does not store the user email in actor.
Signature header
Sublime sends an
X-Sublime-Signature header on every delivery, in the format t=<Unix timestamp>,v0=<HMAC signature>. The Flashduty push URL authenticates with integration_key and does not verify this header, so no extra setup is needed.
Troubleshooting
- No alerts arrive: confirm the Action is attached to a rule and check the Action’s message group scope
- Flashduty returns a parameter error: the push has neither
data.message.canonical_idnordata.message.id, which happens for a manual trigger with no message selected - Alerts never close: Sublime sends no recovery, so enable auto-close on timeout for the channel