> ## Documentation Index
> Fetch the complete documentation index at: https://docs.flashduty.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Panther 告警集成

> 通过 Panther 的 Custom Webhook 告警目的地，将 Panther 检测告警同步到 Flashduty On-call。

通过 Panther 的 Custom Webhook 告警目的地（Alert Destination），将规则、策略等检测产生的告警同步到 Flashduty On-call。每个 Panther 告警对应一条 Flashduty 告警。Panther 只在告警送达目的地时推送一次，不会再发送状态变更或解决通知，因此 Flashduty 告警不会自动恢复，请务必开启协作空间的超时自动关闭。

<div className="hide">
  ## 在 Flashduty On-call

  ***

  您可通过以下两种方式获取集成推送地址，任选其一即可。

  ### 使用专属集成

  1. 进入 Flashduty 控制台，选择 **协作空间**，打开一个协作空间
  2. 选择 **配置** → **集成数据** → **专属集成**，点击 **新增一个集成**
  3. 选择 **Panther**，点击 **保存**
  4. 打开生成的集成卡片，复制 **推送地址**

  ### 使用共享集成

  1. 进入 Flashduty 控制台，选择 **集成中心 → 告警事件**
  2. 选择 **Panther**，填写集成名称
  3. 配置默认路由并选择协作空间；创建后可在 **路由** 中增加更多规则
  4. 点击 **保存**，复制生成的 **推送地址**
</div>

## 在 Panther 中配置

***

<Steps>
  <Step title="创建 Custom Webhook 目的地">
    1. 登录 Panther Console，在左侧栏点击 **Alert Destinations**
    2. 点击 **Create New**（首次使用点击 **+Add your first Destination**），选择 **Custom Webhook**
    3. 填写表单：
       * **Display Name**：自定义名称，例如 `Flashduty`
       * **Custom Webhook URL**：粘贴 Flashduty 集成的完整推送地址
       * **Severity Levels**：选择要发送的告警等级
       * **Default Alert Types**：选择要发送的告警类型
       * **Log Types**：默认发送所有日志类型，可按需限定
    4. 点击 **Add Destination**

    Panther 对 Custom Webhook 发送 HTTP `POST` 的 JSON 请求，期望返回 `2XX`；失败时最多重试 10 次。Flashduty 推送地址已包含认证信息，无需添加自定义 HTTP 头。
  </Step>

  <Step title="发送测试告警">
    在创建完成页点击 **Send Test Alert**。Panther 文档没有给出测试请求的内容，Flashduty 把它当作普通告警处理：测试请求会按其 `alertId` 产生一条告警，不会关联任何真实告警，也没有对应的恢复事件，请确认收到后手动关闭。
  </Step>

  <Step title="开启超时自动关闭">
    为接收 Panther 告警的协作空间开启[超时自动关闭](/zh/on-call/channel/create-edit)，建议时长 24 小时，可按团队处置时效调整。
  </Step>

  <Step title="验证">
    等待检测规则命中（或在 Panther 的告警详情页重新分发告警），确认 Flashduty 收到对应告警。
  </Step>
</Steps>

## Alert Key

***

Flashduty 使用请求体中的 `alertId` 作为 Alert Key。Panther 文档对该字段的说明是 “Identifier of the alert in Panther Backend”。同一个 Panther 告警从告警详情页手动重新发送时，会落在同一条 Flashduty 告警上。

标题、等级、描述等字段的变化不会改变 Alert Key。请求缺少 `alertId` 时 Flashduty 会返回参数错误。

## 状态和告警等级

***

Panther 的 Custom Webhook 没有状态字段，Flashduty 每次收到的都是触发事件。

| Panther `severity` | Flashduty 等级 |
| :- | :- |
| `CRITICAL`、`HIGH` | Critical |
| `MEDIUM` | Warning |
| `LOW`、`INFO` | Info |
| 空值或其他 | Warning |

告警标签包含检测名称、检测 ID（`id`）、告警 ID、告警类型、原始等级、告警链接和标签（`tags`）。`alertContext` 由检测规则的作者定义，可能包含原始日志字段，不会写入告警；`runbook` 同样不写入。

## 排查问题

***

* **Panther 显示投递失败**：确认推送地址完整且包含 `integration_key`，Flashduty 返回非 `2XX` 时 Panther 会重试最多 10 次
* **没有收到告警**：确认目的地的 **Severity Levels**、**Default Alert Types** 与 **Log Types** 覆盖了该告警，并检查检测规则的目的地路由
* **告警一直不关闭**：Panther 不推送解决通知，请开启协作空间的超时自动关闭
* **收到测试告警**：这是 **Send Test Alert** 产生的告警，按普通告警处理，手动关闭即可

更多信息请参阅 Panther 文档 [Custom Webhook Destination](https://docs.panther.com/alerts/destinations/custom_webhook)。
