ACTIVE when the alert triggers and when it renotifies, and sends OK when the alert condition clears, which recovers the alert. For alerts segmented with Segment by, each segment maps to its own Flashduty alert.
In Flashduty On-call
You can obtain an integration push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, select Channel and open a channel
- Select Configuration → Integrations → Private integration, then click Add an integration
- Select Sysdig, then click Save
- Open the generated integration card and copy the Push URL
Use a shared integration
- In the Flashduty console, select Integration Center → Alert Events
- Select Sysdig and enter an integration name
- Configure the default route and select a channel; after creation, add more rules under Route if needed
- Click Save and copy the generated Push URL
Configure Sysdig Monitor
Creating a notification channel requires administrator privileges in Sysdig Monitor.
1
Create a Webhook notification channel
- Log in to Sysdig Monitor as an administrator and go to Integrations → Notification Channels (Settings → Notification Channels in some versions)
- Click Add Notification Channel and select Webhook. Do not select Custom Webhook: Flashduty parses the fixed format of the Webhook channel
- Fill in the fields as follows:
- Click Save
2
Use the channel in alert rules
- Go to Alerts and create or edit an alert rule
- In the notification settings (Notify), select the Webhook channel created in the previous step
- If the alert rule overrides this channel’s notification options, make sure resolve notifications are not turned off
- Save the alert rule
3
Verify
- When you save the notification channel, Sysdig sends a test notification named
TEST ALERT: Testing Notification Channel <channel name>. Flashduty returns success but does not create an alert - Make an alert rule that uses the channel fire, and confirm that Flashduty receives an active alert
- Wait for the alert condition to clear, and confirm that the alert recovers
Alert Key
Flashduty uses the Sysdig event ID (
event.id) as the Alert Key. Sysdig creates one event each time an alert fires, and the first notification, renotifications, and the resolve notification of that event all carry the same event ID, so they merge into one alert, which the resolve notification recovers.
- Segmented alerts: Sysdig sends a separate notification for each segment that fires, and each segment has its own event ID, so each segment is a separate Flashduty alert that recovers on its own
- Firing again: when a rule fires again after it resolved, Sysdig creates a new event and Flashduty creates a new alert
- Changes to the alert name, severity, metric value, and time do not change the Alert Key. Requests without
event.idare rejected
Status and severity
state sets the status:
The alert rule’s severity (
alert.severity, 0 to 7) sets the alert severity. If it is missing, Flashduty uses alert.severityLabel:
A recovered alert keeps the severity of its last trigger.
Labels
The alert description is the Sysdig notification body (
alert.body), which includes the metric value, segment, and trigger time.
Troubleshooting
- Flashduty returns a parameter error: make sure the URL is complete and includes
integration_key, and that the channel type is Webhook, not Custom Webhook - No alert after saving the channel: this is expected. The test notification does not create an alert; use a real alert to verify
- The alert does not recover: make sure the channel has Notify when Resolved on and that the alert rule does not turn off resolve notifications for this channel
- One rule creates several alerts: the alert rule uses Segment by, and each segment fires and recovers on its own. This is expected
- Sysdig disabled the notification channel: after repeated 4xx responses, Sysdig puts the channel under observation and disables it after several failures. After fixing the URL, re-enable the channel in Sysdig manually