Skip to main content
Zeek records detections as notices through its Notice framework, and the Notice::ACTION_EMAIL action sends each notice as one email. It has no webhook. The Flashduty email integration receives these emails, so no separate Zeek integration is needed: create an email integration in Flashduty and set its email address as the Zeek notice recipient.

In Flashduty On-call


Get the integration email address in either of the two ways below. In both cases choose the Email integration type, not Zeek.

Use a dedicated integration

  1. In the Flashduty console, select Channels and open a channel
  2. Select Settings → Integrations → Dedicated integrations and click Add an integration
  3. Select Email and click Save
  4. Open the new integration card, copy the email address, then configure Zeek as described below

Use a shared integration

  1. In the Flashduty console, select Integration Center → Alert events
  2. Select Email, enter an integration name and copy the email address
  3. Configure Zeek as described below
  4. Set a default route, select a channel and click Save

Configure the push mode in Flashduty


Zeek notice emails only trigger; there is no resolve email, so no rules are needed to close alerts. Set the email integration’s push mode to the one that always triggers a new alert (the create page may preselect a different mode, so check it), which creates a new alert for every email.
  • The alert title is the email title, for example [Zeek] SSH::Password_Guessing (bracketed prefix plus the notice type)
  • The alert description is the email body, with the notice message, the source and destination addresses and ports of the connection, and so on
  • Severity is always Warning; adjust it by notice type with alert pipelines
Zeek already suppresses repeats of the same notice for suppress_for (1 hour by default), so merging in Flashduty is usually unnecessary. To merge notices of the same type into one alert, switch the push mode to Trigger or Update Alert Based on Email Subject. The title holds only the notice type, so notices of the same type from different hosts merge together.

Configure Zeek


Recipient and mailer (ZeekControl)

Set these options in the ZeekControl configuration file zeekctl.cfg, then run zeekctl deploy: Without ZeekControl, set Notice::mail_dest, Notice::mail_from and Notice::sendmail in a Zeek script; they mean the same.

Choose which notices are emailed

Zeek emails only notices that have the Notice::ACTION_EMAIL action applied. In local.zeek, select notice types with Notice::emailed_types:
You can also add the action conditionally in a Notice::policy hook and set the recipient directly:
Redeploy Zeek (zeekctl deploy) for the change to take effect.

Email format


A single-notice email (Notice::ACTION_EMAIL) has the title Notice::mail_subject_prefix ([Zeek] by default), a space, then the notice type. The body is made of the parts below:
  • Message is the notice message; Sub-message is extra detail and appears only when the notice has one
  • A notice tied to a connection has Connection and Connection uid; one tied only to an address has Address
  • A notice with file information also has File Description and File MIME Type
  • Content that scripts add through email_body_sections is appended at the end of the body

Limitations


  • Trigger only, no resolve: Zeek never sends a resolve email. Turn on the auto-resolve timeout in the channel that receives this integration; 24 hours is a reasonable start. Otherwise alerts must be closed manually.
  • Summary emails: Notice::ACTION_ALARM does not send one email per notice. It bundles the notice_alarm log on a schedule (MailAlarmsInterval in ZeekControl, 86400 seconds by default) into one summary email titled like [Zeek] Log Contents: ..., which holds several notices and creates a single alert. Use Notice::ACTION_EMAIL when you need one alert per notice.
  • Title has no detail: the email title holds only the notice type; hosts, addresses and other details are in the body, so read the alert description in Flashduty.
  • Severity: Zeek notices have no severity field, so alert severity is always Warning.