> ## Documentation Index
> Fetch the complete documentation index at: https://docs.flashduty.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Sublime Security alert integration

> Send email messages flagged by Sublime Security to Flashduty On-call through a webhook Action, one alert per message group.

Use a Sublime Security webhook Action to send messages flagged by detection rules to Flashduty On-call. One message (one message group) maps to one alert, and the alert title is the name of the highest-severity rule that flagged it.

Sublime pushes only when a message is flagged and sends no resolve notification, so Flashduty alerts do not recover automatically.

<div className="hide">
  ## In Flashduty On-call

  ***

  You can get the integration push URL in either of two ways.

  ### Use a dedicated integration

  1. In the Flashduty console, select **Channel** and open a channel
  2. Select **Configuration** → **Integrations** → **Private integration**, then click **Add an integration**
  3. Select **Sublime Security** and click **Save**
  4. Open the integration card and copy the **push URL**

  ### Use a shared integration

  1. In the Flashduty console, go to **Integration Center → Alert Events**
  2. Select **Sublime Security** and enter an integration name
  3. Configure the default route and choose a channel; you can add more rules under **Routes** after creation
  4. Click **Save** and copy the generated **push URL**
</div>

## In Sublime Security

***

<Steps>
  <Step title="Create a webhook Action">
    1. In the Sublime dashboard, go to **Manage** → **Actions** in the left navigation, click **New Action**, and select **Webhook**
    2. Enter a name and paste the full Flashduty push URL, including `integration_key`, as the endpoint URL
    3. Click **Save**. Sublime then opens the **Attach to Rules** dialog, where you can select existing rules and click **Attach selected rules**

    Sublime requires the receiver to return a 2xx response within 10 seconds, which Flashduty does.
  </Step>

  <Step title="Choose the message group scope">
    The webhook **Scope** has three options: **Flagged Messages** (when a flagged message is received in a message group), **All Messages** (all messages in a message group), and **First Message Only** (the first message received in a message group). Pushes for the same message group share one Alert Key and merge into one alert.
  </Step>

  <Step title="Attach it to rules">
    Add the Action to the detection rules or automations you want to be notified about. On a new account the rules from Sublime's feed are inactive, so activate at least one rule before the webhook can fire. Sublime's documentation does not describe a test button for webhooks, so after a message is flagged, confirm that an alert appears in Flashduty.
  </Step>
</Steps>

## Events and recovery

***

| Sublime `type` | Meaning | Effect in Flashduty |
| :- | :- | :- |
| `message.flagged` | A rule flagged the message | Triggers an alert |
| `group` | Another message in the group fired a webhook scoped to the whole group | Triggers or updates the alert for that message group |
| `manual` | A user triggered the Action in Sublime | Triggers an alert when message info is present; rejected when the message identifier is missing |

Sublime sends no resolve notification. Enable [auto-close on timeout](/en/on-call/channel/create-edit) for the channel, with 7 days suggested, or close alerts by hand once the message is handled.

## Alert Key

***

The Alert Key is `data.message.canonical_id`, or `data.message.id` when it is absent. Sublime documents `canonical_id` as the identifier of the message group a message belongs to, shared when the same message is delivered to several mailboxes. Changes to identifiers, classification, rule names or severity do not change the Alert Key. A push with neither field is rejected, and the error names the field.

## Severity

***

Flashduty uses the highest severity among `flagged_rules`:

| Sublime rule severity | Flashduty severity |
| :- | :- |
| `critical`, `high` | Critical |
| `medium` | Warning |
| `low`, `informational` | Info |
| No rules or an unknown value | Warning |

## Labels

***

| Label | Source |
| :- | :- |
| `source` | Always `sublime` |
| `check` | Name of the highest-severity rule |
| `trigger_event` | The push `type` |
| `canonical_id` / `message_id` | Message group and message identifiers |
| `message_source_id` / `mailbox_id` | Message source and mailbox identifiers |
| `classification` | Message classification, for example `malicious` |
| `rule_severity` | Highest rule severity |
| `flagged_rules` | Flagged rule names, highest severity first |
| `rule_tags` | Rule tags, deduplicated and sorted |
| `triggered_actions` | Names of the Actions that fired |

The push carries no subject or body; use `message_id` to look the message up in Sublime. Flashduty does not store the user email in `actor`.

## Signature header

***

Sublime sends an `X-Sublime-Signature` header on every delivery, in the format `t=<Unix timestamp>,v0=<HMAC signature>`. The Flashduty push URL authenticates with `integration_key` and does not verify this header, so no extra setup is needed.

## Troubleshooting

***

* **No alerts arrive**: confirm the Action is attached to a rule and check the Action's message group scope
* **Flashduty returns a parameter error**: the push has neither `data.message.canonical_id` nor `data.message.id`, which happens for a manual trigger with no message selected
* **Alerts never close**: Sublime sends no recovery, so enable auto-close on timeout for the channel

For field details, see the [Sublime webhook documentation](https://docs.sublime.security/docs/webhooks).
