> ## Documentation Index
> Fetch the complete documentation index at: https://docs.flashduty.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Zeek alert integration

> Zeek's Notice framework can send notices by email; use a Flashduty email integration to bring Zeek notices into Flashduty.

Zeek records detections as notices through its Notice framework, and the `Notice::ACTION_EMAIL` action sends each notice as one email. It has no webhook. The Flashduty [email integration](/en/on-call/integration/alert-integration/alert-sources/email) receives these emails, so no separate Zeek integration is needed: create an email integration in Flashduty and set its email address as the Zeek notice recipient.

<div className="hide">
  ## In Flashduty On-call

  ***

  Get the integration email address in either of the two ways below. **In both cases choose the Email integration type**, not Zeek.

  ### Use a dedicated integration

  1. In the Flashduty console, select **Channels** and open a channel
  2. Select **Settings** → **Integrations** → **Dedicated integrations** and click **Add an integration**
  3. Select **Email** and click **Save**
  4. Open the new integration card, copy the **email address**, then configure Zeek as described below

  ### Use a shared integration

  1. In the Flashduty console, select **Integration Center → Alert events**
  2. Select **Email**, enter an integration name and copy the **email address**
  3. Configure Zeek as described below
  4. Set a default route, select a channel and click **Save**
</div>

## Configure the push mode in Flashduty

***

Zeek notice emails only trigger; there is no resolve email, so no rules are needed to close alerts. Set the email integration's push mode to the one that always triggers a new alert (the create page may preselect a different mode, so check it), which creates a new alert for every email.

* The alert title is the email title, for example `[Zeek] SSH::Password_Guessing` (bracketed prefix plus the notice type)
* The alert description is the email body, with the notice message, the source and destination addresses and ports of the connection, and so on
* Severity is always Warning; adjust it by notice type with [alert pipelines](/en/on-call/integration/alert-integration/alert-pipelines)

Zeek already suppresses repeats of the same notice for `suppress_for` (1 hour by default), so merging in Flashduty is usually unnecessary. To merge notices of the same type into one alert, switch the push mode to **Trigger or Update Alert Based on Email Subject**. The title holds only the notice type, so notices of the same type from different hosts merge together.

## Configure Zeek

***

### Recipient and mailer (ZeekControl)

Set these options in the ZeekControl configuration file `zeekctl.cfg`, then run `zeekctl deploy`:

| Option | Description |
| :- | :- |
| `MailTo` | Recipient for non-summary emails; enter the Flashduty email integration address. Overrides the Zeek script variable `Notice::mail_dest` |
| `SendMail` | Path of the sendmail binary. Leave it empty and no email is sent, so make sure the host can send mail with sendmail |
| `MailFrom` | Sender, `Zeek <zeek@localhost>` by default; change as needed |
| `MailSubjectPrefix` | Email title prefix, `[Zeek]` by default |

Without ZeekControl, set `Notice::mail_dest`, `Notice::mail_from` and `Notice::sendmail` in a Zeek script; they mean the same.

### Choose which notices are emailed

Zeek emails only notices that have the `Notice::ACTION_EMAIL` action applied. In `local.zeek`, select notice types with `Notice::emailed_types`:

```zeek theme={null}
redef Notice::emailed_types += {
    SSH::Password_Guessing,
    SSL::Invalid_Server_Cert,
};
```

You can also add the action conditionally in a `Notice::policy` hook and set the recipient directly:

```zeek theme={null}
hook Notice::policy(n: Notice::Info)
    {
    if ( n$note == SSH::Password_Guessing )
        {
        add n$actions[Notice::ACTION_EMAIL];
        n$email_dest = set("<Flashduty email integration address>");
        }
    }
```

Redeploy Zeek (`zeekctl deploy`) for the change to take effect.

## Email format

***

A single-notice email (`Notice::ACTION_EMAIL`) has the title `Notice::mail_subject_prefix` (`[Zeek]` by default), a space, then the notice type. The body is made of the parts below:

```
Subject: [Zeek] SSH::Password_Guessing

Message: 192.168.56.1 appears to be guessing SSH passwords (seen in 10 connections).
Sub-message: Sampled servers:  192.168.56.103, 192.168.56.103

Connection: 192.168.56.1:51234 -> 192.168.56.103:22
Connection uid: CXWv6p3arKYeMETxOg
```

* `Message` is the notice message; `Sub-message` is extra detail and appears only when the notice has one
* A notice tied to a connection has `Connection` and `Connection uid`; one tied only to an address has `Address`
* A notice with file information also has `File Description` and `File MIME Type`
* Content that scripts add through `email_body_sections` is appended at the end of the body

## Limitations

***

* **Trigger only, no resolve**: Zeek never sends a resolve email. Turn on the [auto-resolve timeout](/en/on-call/channel/create-edit) in the channel that receives this integration; 24 hours is a reasonable start. Otherwise alerts must be closed manually.
* **Summary emails**: `Notice::ACTION_ALARM` does not send one email per notice. It bundles the `notice_alarm` log on a schedule (`MailAlarmsInterval` in ZeekControl, 86400 seconds by default) into one summary email titled like `[Zeek] Log Contents: ...`, which holds several notices and creates a single alert. Use `Notice::ACTION_EMAIL` when you need one alert per notice.
* **Title has no detail**: the email title holds only the notice type; hosts, addresses and other details are in the body, so read the alert description in Flashduty.
* **Severity**: Zeek notices have no severity field, so alert severity is always Warning.
