In Flashduty On-call
You can obtain an integration push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, select Channel and open a channel
- Select Configuration → Integrations → Private integration, then click Add an integration
- Select Aqua Tracee, then click Save
- Open the generated integration card and copy the Push URL
Use a shared integration
- In the Flashduty console, select Integration Center → Alert Events
- Select Aqua Tracee and enter an integration name
- Configure the default route and select a channel; after creation, add more rules under Route if needed
- Click Save and copy the generated Push URL
Configure Tracee
1
Add a webhook output destination
Tracee defines output destinations with the Configuration file:
--output flag or the output: section of its configuration file. Put the Flashduty push URL in url and keep the default json format. The webhook POSTs every event to that URL as application/json, with no signature and no extra headers needed.Command line:2
Send detections only
Flashduty creates alerts only for detection events, which carry a List the detection events you want to alert on under
threat field. Events without threat (for example sched_process_exec) are acknowledged and dropped. To avoid sending every event to Flashduty, use a stream so that only detection events reach this destination:events (events produced by a detector or signature, such as anti_debugging).3
Turn on auto-close
Tracee’s detections have no recovery notification: after a threat is handled, Flashduty receives nothing.Turn on auto-close in the channel that receives these alerts, with a suggested duration of 24 hours. When the same rule fires again in the same container within the grouping window, the same alert is updated; after the alert is closed, the next detection opens a new one.
4
Verify
Tracee has no “send test notification” feature. Trigger a real detection in Tracee, or send a sample detection to the push URL:Confirm that an active alert appears in Flashduty with
threat.name as the title. The sample opens a real alert, so close it manually after verifying.Alert Key
Tracee events have no unique ID. Flashduty builds the Alert Key from the rule identity plus where the event ran (the MD5 of
"tracee", the rule identity and the location, separated by NUL):
- Rule identity: the first non-empty of
threat.properties.signatureID,threat.properties.idand the eventname. Tracee documentsthreat.properties.signatureIDas the signature ID of a detection; events from newer detectors do not carry it, so the eventnamestands in - Location:
workload.container.idfor an event inside a container; otherwiseworkload.process.host_pid, thenworkload.process.pid
threat.name do not change the Alert Key.
Events outside a container are told apart by process ID only. Tracee events carry no hostname, so the same rule on two hosts with the same process ID merges into one alert; in that case use a separate integration per host.
Severity
In the default JSON,
threat.severity is a number (INFO=0 to CRITICAL=4):
Labels
Flashduty sets these labels when they have a value:
rule_id, signature_id, event_name, category, threat_severity, mitre_tactic, mitre_technique_id, mitre_technique, container_id, container_name, image, pod, namespace, process, executable, pid, host_pid, policies, detected_from. The event’s data array (file paths, command arguments and so on) is never copied into labels.
Troubleshooting
- Tracee logs
Error sending webhook, http status: confirm the URL is complete and includesintegration_key - No alerts arrive: confirm the event carries a
threatfield; ordinary events create no alert, and the stream’seventsmust include the detection event - Alerts do not recover: Tracee sends no recovery notification; turn on the channel’s auto-close or close alerts manually
- Alerts from different hosts merge: events outside a container are told apart by process ID only; see the note under Alert Key