Notice::ACTION_EMAIL action sends each notice as one email. It has no webhook. The Flashduty email integration receives these emails, so no separate Zeek integration is needed: create an email integration in Flashduty and set its email address as the Zeek notice recipient.
In Flashduty On-call
Get the integration email address in either of the two ways below. In both cases choose the Email integration type, not Zeek.
Use a dedicated integration
- In the Flashduty console, select Channels and open a channel
- Select Settings → Integrations → Dedicated integrations and click Add an integration
- Select Email and click Save
- Open the new integration card, copy the email address, then configure Zeek as described below
Use a shared integration
- In the Flashduty console, select Integration Center → Alert events
- Select Email, enter an integration name and copy the email address
- Configure Zeek as described below
- Set a default route, select a channel and click Save
Configure the push mode in Flashduty
Zeek notice emails only trigger; there is no resolve email, so no rules are needed to close alerts. Set the email integration’s push mode to the one that always triggers a new alert (the create page may preselect a different mode, so check it), which creates a new alert for every email.
- The alert title is the email title, for example
[Zeek] SSH::Password_Guessing(bracketed prefix plus the notice type) - The alert description is the email body, with the notice message, the source and destination addresses and ports of the connection, and so on
- Severity is always Warning; adjust it by notice type with alert pipelines
suppress_for (1 hour by default), so merging in Flashduty is usually unnecessary. To merge notices of the same type into one alert, switch the push mode to Trigger or Update Alert Based on Email Subject. The title holds only the notice type, so notices of the same type from different hosts merge together.
Configure Zeek
Recipient and mailer (ZeekControl)
Set these options in the ZeekControl configuration filezeekctl.cfg, then run zeekctl deploy:
Without ZeekControl, set
Notice::mail_dest, Notice::mail_from and Notice::sendmail in a Zeek script; they mean the same.
Choose which notices are emailed
Zeek emails only notices that have theNotice::ACTION_EMAIL action applied. In local.zeek, select notice types with Notice::emailed_types:
Notice::policy hook and set the recipient directly:
zeekctl deploy) for the change to take effect.
Email format
A single-notice email (
Notice::ACTION_EMAIL) has the title Notice::mail_subject_prefix ([Zeek] by default), a space, then the notice type. The body is made of the parts below:
Messageis the notice message;Sub-messageis extra detail and appears only when the notice has one- A notice tied to a connection has
ConnectionandConnection uid; one tied only to an address hasAddress - A notice with file information also has
File DescriptionandFile MIME Type - Content that scripts add through
email_body_sectionsis appended at the end of the body
Limitations
- Trigger only, no resolve: Zeek never sends a resolve email. Turn on the auto-resolve timeout in the channel that receives this integration; 24 hours is a reasonable start. Otherwise alerts must be closed manually.
- Summary emails:
Notice::ACTION_ALARMdoes not send one email per notice. It bundles thenotice_alarmlog on a schedule (MailAlarmsIntervalin ZeekControl, 86400 seconds by default) into one summary email titled like[Zeek] Log Contents: ..., which holds several notices and creates a single alert. UseNotice::ACTION_EMAILwhen you need one alert per notice. - Title has no detail: the email title holds only the notice type; hosts, addresses and other details are in the body, so read the alert description in Flashduty.
- Severity: Zeek notices have no severity field, so alert severity is always Warning.