☰

Introduce

Configure webhooks

There are a variety of services you can connect to Nexusguard using webhooks to receive alert notifications. Refer to the table below to learn how to connect your account to popular webhook services.

Configure webhooks

  1. Get into Notifier Apps.
  2. In the Webhook page, select Create.
  3. Give your webhook a name to use for identification later.
  4. In the URL field, enter the URL of the third-party service that you have previously set up and want to connect to your account.
  5. If needed, insert the custom HTTP Header and put the Secret in it.
  6. Select Save to finish setting up your webhook.
  7. The new webhook will appear in the Webhooks page.

Firewall settings

Webhook notifications are sent from Nexusguard’s IP ranges. If your webhook endpoint is protected by a firewall, you must allowlist these Agent IP addresses to receive notifications.

Generic webhooks

If you use a service that is not covered by Nexusguard’s currently available webhooks, you can configure your own, and enter a valid webhook URL.

It is always recommended to use a secret for generic webhooks. You can put a secret in a Custom HTTP Header of every request made. If this header is not present, or is not your specified value, you should reject the webhook.

After selecting Save and Test, your webhook should now be configured as a destination that you can use to attach to policies.

Limitations of generic webhooks

Nexusguard generic webhook notifications will only be dispatched to a publicly resolvable IP address on port 80 or 443.

Nexusguard currently supports the following popular webhook services.

Google Chat

Secret: The secret is part of the URL. Nexusguard parses this information automatically and there is no input needed from the user. URL: URL varies depending on the Google Chat channel’s address.

Slack

Secret: The secret is part of the URL. Nexusguard parses this information automatically and there is no input needed from the user. URL: URL varies depending on the Slack channel’s address.

Discord

Secret: The secret is part of the URL. Nexusguard parses this information automatically and there is no input needed from the user. URL: URL varies depending on the Discord channel’s address.

Zoom Chat

Secret: The secret is part of the URL. Nexusguard parses this information automatically and there is no input needed from the user. URL: The URL varies depending on the Custom Robot.

Feishu

Secret: The secret is part of the URL. Nexusguard parses this information automatically and there is no input needed from the user. URL: The URL varies depending on the Custom Robot.

Teams

Secret: The secret is part of the URL. Nexusguard parses this information automatically and there is no input needed from the user. URL: URL is provided by Teams when the Incoming Webhook connector is created.


Webhook Payload

This document describes the payload data structures of webhook notifications:

  1. Generic webhook schema — unified outer CloudEvents-style envelope
  2. Notification data by type — data fields and examples for each notification type
  3. Other Incoming Webhook payloads — target formats when delivering to Google Chat / Slack / Zoom Chat / Discord / Feishu / Teams and similar platforms

Sections 1 and 2 describe generic notifications sent by the system. Section 3 describes the payloads used when mapping those notifications to third-party chat platform Incoming Webhooks.


1. Generic Webhook Payload Schema

All generic webhook notifications follow this schema:

{
  "specversion": "string",
  "id": "string",
  "title": "string",
  "message": "string",
  "source": "/nxg/notifier/global",
  "type": "string",
  "time": "intval",
  "datacontenttype": "application/json",
  "data": {}
}

Field description

Field Type Description
specversion string Payload schema version. Currently "1.0".
id string Unique identifier of this webhook delivery (UUID recommended). Used for idempotency / deduplication.
title string Short human-readable title of the notification.
message string Human-readable summary of the notification.
source string Origin of the event (e.g. service name or URI identifying the producer).
type string Notification type. Determines the structure of data. See section 2.
time integer Unix timestamp (seconds) when the event occurred or was generated. (Timezone is always GMT+0)
datacontenttype string Media type of data. Always "application/json".
data object Type-specific payload. Shape depends on type.

Example (envelope only)

{
  "specversion": "1.0",
  "id": "550e8400-e29b-41d4-a716-446655440000",
  "title": "AP DDoS attack alert",
  "message": "High severity volumetric attack detected on site example.com",
  "source": "/nxg/notifier/global",
  "type": "AP.DDoS",
  "time": 1711677960,
  "datacontenttype": "application/json",
  "data": {}
}

2. Notification data by type

type values use uppercase letters joined by . (for example, AP.DDoS). The table below lists the main types, with field descriptions and examples for each data payload.

type Service Description
AP.DDoS AP Application Protection DDoS event
AP.WAF AP Application Protection WAF / Web Attack event
AP.SSL AP Application Protection SSL / certificate related event
OP.DDoS OP Origin Protection DDoS event
OP.Flow OP Origin Protection Flow event. As of now, only Flow down event is available.
OP.Traffic_Director OP Origin Protection Traffic Director event
OP.BGP OP Origin Protection BGP Change Status event
CP.DDoS CP Clean Pipe DDoS event
DP.HOSTING.DDoS DP DNS Protection(HOSTING) DDoS event
DP.PROXY.DDoS DP DNS Protection(PROXY) DDoS event
DNS.Zone_Transfer DNS DNS Zone Transfer event
CD.Auto_Divert Cloud Diversion Cloud Diversion Auto Divert Event
CD.BGP_ON_NET Cloud Diversion Cloud Diversion On-Net BGP Status Change
BASTIONS.BGP BASTIONS BASTIONS BGP Status Changed.
BASTIONS.Flow BASTIONS Cloud Diversion Flow event. As of now, only Flow down event is available.
BASTIONS.Ethernet_Port BASTIONS Bastions — Ethernet Port Status Change

2.1 AP.DDoS — AP DDoS

Fields
Field Type Description
event_id string Unique event ID.
customer_id integer Customer ID.
customer_name string Customer display name.
site_id integer Site ID.
site_name string Site display name.
target string Attack target (IP, VIP, or network prefix).
domain string Related domain hostname. May be empty when not applicable.
domain_id string Domain ID. May be empty string when not applicable.
start_time integer Event / alert start time (Unix timestamp, seconds).
end_time integer Event end time (Unix timestamp, seconds). 0 while ongoing.
type string Attack category: Volumetric or mixed.
status string Event status: Ongoing or Stopped.
severity string Severity level: Low, Medium, High, Blackhole.
organization string Comma-separated country / region codes of attack sources (e.g. US,CN).
attack_type string Internal attack type identifier.
mail_type string Mail / notification category identifier.
message string Human-readable message or message template. Placeholders in {} are replaced with actual values.
event_url string Deep link to the event in the portal.
Example
{
  "specversion": "1.0",
  "id": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
  "title": "AP DDoS attack alert.",
  "message": "AP DDoS attack alert [{customer_name} / {event_id}]",
  "source": "/nxg/notifier/global",
  "type": "AP.DDoS",
  "time": 1711677960,
  "datacontenttype": "application/json",
  "data": {
    "event_id": "EVENT-EF54F79D52439CDA8AD8E7FF5C",
    "customer_id": 1,
    "customer_name": "NXG-123456-TEST",
    "site_id": 73,
    "site_name": "holodark.com",
    "target": "192.168.0.1",
    "domain": "",
    "domain_id": "",
    "start_time": 1711677960,
    "end_time": 0,
    "type": "Volumetric | Application | mixed",
    "status": "Ongoing | Stopped",
    "severity": "Low | Medium | High | Blackhole",
    "organization": "US,CN",
    "attack_type": "ap_ddos",
    "mail_type": "ap_ddos",
    "message": "AP DDoS attack alert [{customer_name} / {event_id}]",
    "event_url": ".../#/customer/{uid}/ap/dashboard/site/{site_id}/ddos"
  }
}

2.2 AP.WAF — AP Web Attack (WAF)

Fields
Field Type Description
event_id string Unique event ID.
customer_id integer Customer ID.
customer_name string Customer display name.
site_id integer Site ID.
site_name string Site display name.
target string Attack target (IP, VIP, or network prefix).
domain string Related domain hostname.
domain_id integer Domain ID.
start_time integer Event / alert start time (Unix timestamp, seconds).
end_time integer Event end time (Unix timestamp, seconds). 0 while ongoing.
type string Attack category. Always "Web Attack" for this notification type.
status string Event status: Ongoing or Stopped.
severity string Severity level: Low, Medium, High.
organization string Comma-separated country / region codes of attack sources (e.g. US,CN).
attack_type string Internal attack type identifier.
mail_type string Mail / notification category identifier.
message string Human-readable message or message template. Placeholders in {} are replaced with actual values.
event_url string Deep link to the event in the portal.
Example
{
  "specversion": "1.0",
  "id": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
  "title": "AP Web attack alert.",
  "message": "AP Web attack alert [{customer_name} / {event_id}]",
  "source": "/nxg/notifier/global",
  "type": "AP.WAF",
  "time": 1711681200,
  "datacontenttype": "application/json",
  "data": {
    "event_id": "WAF-EVENT-xxx",
    "customer_id": 1,
    "customer_name": "NXG-123456-TEST",
    "site_id": 73,
    "site_name": "holodark.com",
    "target": "https://example.com/path",
    "domain": "example.com",
    "domain_id": 12,
    "start_time": 1711677960,
    "end_time": 0,
    "type": "Web Attack",
    "status": "Ongoing | Stopped",
    "severity": "Low | Medium | High",
    "organization": "US,CN",
    "attack_type": "ap_waf",
    "mail_type": "ap_waf",
    "message": "AP Web attack alert [{customer_name} / {event_id}]",
    "event_url": ".../#/customer/{uid}/ap/dashboard/site/{site_id}/waf"
  }
}

2.3 AP.SSL — AP SSL Certificate Expiration

Fields
Field Type Description
customer_id integer Customer ID.
customer_name string Customer display name.
site_name string Site display name.
domain string Related domain hostname.
expires_time string Certificate expiration datetime (YYYY-MM-DD HH:mm:ss, GMT+0).
expires_days string Days remaining until expiration: 30, 7, 3, 1, or 0 (already expired).
status string Expiration status: Expiring in 30 days, Expiring in 7 days, Expiring in 3 days, Expiring in 1 days, or Expired.
message string Human-readable message or message template. Placeholders in {} are replaced with actual values.
url string Deep link to the related settings page in the portal.
Example
{
  "specversion": "1.0",
  "id": "f6a7b8c9-d0e1-2345-f012-456789012345",
  "title": "SSL certificate expiration alert.",
  "message": "SSL certificate expiration alert[{domain} certificate is about to expire in {expires_days} days]",
  "source": "/nxg/notifier/global",
  "type": "AP.SSL",
  "time": 1711684800,
  "datacontenttype": "application/json",
  "data": {
    "customer_id": 1,
    "customer_name": "NXG-123456-TEST",
    "site_name": "holodark.com",
    "domain": "www.example.com",
    "expires_time": "2026-08-28 00:00:00",
    "expires_days": "30",
    "status": "Expiring in 30 days",
    "message": "SSL certificate expiration alert[{domain} certificate is about to expire in {expires_days} days]",
    "url": "https://customer.example.com/#/customer/1/action/site_info/site/73/domain"
  }
}

2.4 OP.DDoS — OP DDoS

Fields
Field Type Description
event_id string Unique event ID.
customer_id integer Customer ID.
customer_name string Customer display name.
site_id integer Site ID.
site_name string Site display name.
target string Attack target (IP, VIP, or network prefix).
start_time integer Event / alert start time (Unix timestamp, seconds).
end_time integer Event end time (Unix timestamp, seconds). 0 while ongoing.
severity string Severity level: Low, Medium, High, Blackhole.
status string Event status: Ongoing or Stopped.
type string Attack or event category: Volumetric, mixed, UDP.
top_attack_type string Dominant attack signature / protocol: UDP, TCP, ICMP.
max_bps integer Peak traffic in bits per second.
max_pps integer Peak packets per second.
moids array of string Related MO / mitigation object IDs.
profile_name string Protection profile name.
profile_desc string Protection profile description.
is_network string Whether this is a network-level event: 0 or 1: 0, 1.
host_events integer Number of related host events.
host_ongoing integer Number of ongoing host events.
confidence_setting string Confidence detection setting: off or on: off, on.
event_flag integer Event flag value.
mode string Detection mode: Normal, Rapid, Smart.
duration string Human-readable event duration.
attack_type string Internal attack type identifier.
message string Human-readable message or message template. Placeholders in {} are replaced with actual values.
event_url string Deep link to the event in the portal.
Example
{
  "specversion": "1.0",
  "id": "c3d4e5f6-a7b8-9012-cdef-123456789012",
  "title": "OP DDoS attack alert.",
  "message": "OP DDoS attack alert - [{customer_name} / {event_id}]",
  "source": "/nxg/notifier/global",
  "type": "OP.DDoS",
  "time": 1704855421,
  "datacontenttype": "application/json",
  "data": {
    "event_id": "EVENT-FE3B5B45FC8712D6584B844D8E",
    "customer_id": 31,
    "customer_name": "NXG-123456-TEST",
    "site_id": 100,
    "site_name": "op-site",
    "target": "192.168.0.1",
    "start_time": 1711677960,
    "end_time": 0,
    "severity": "Low | Medium | High | Blackhole",
    "status": "Ongoing | Stopped",
    "type": "Volumetric | mixed | UDP | ...",
    "top_attack_type": "UDP | TCP | ICMP | ...",
    "max_bps": 1000000,
    "max_pps": 12666,
    "moids": [
      "5090d43c"
    ],
    "profile_name": "...",
    "profile_desc": "...",
    "is_network": "0 | 1",
    "host_events": 0,
    "host_ongoing": 0,
    "confidence_setting": "off | on",
    "event_flag": 0,
    "mode": "Normal | Rapid | Smart",
    "duration": "20 mins 2 secs",
    "attack_type": "op_ddos",
    "message": "OP DDoS attack alert - [{customer_name} / {event_id}]",
    "event_url": ".../#/customer/{uid}/op/dashboard/site/{site_id}/op_type/cloud/ddos"
  }
}

2.5 OP.Flow — OP Flow

Fields
Field Type Description
customer_id integer Customer ID.
customer_name string Customer display name.
alert_id string Unique alert ID.
router_name string Router / agent name.
router_desc string Router description.
export_ip string Flow export IP address.
start_time integer Event / alert start time (Unix timestamp, seconds).
message string Human-readable message or message template. Placeholders in {} are replaced with actual values.
Example
{
  "specversion": "1.0",
  "id": "c3d4e5f6-a7b8-9012-cdef-123456789012",
  "title": "Flow Down Alert.",
  "message": "Flow Down Alert since {Y-m-d H:i:s}(GMT) for router {router_name}",
  "source": "/nxg/notifier/global",
  "type": "OP.Flow",
  "time": 1711677960,
  "datacontenttype": "application/json",
  "data": {
    "customer_id": 1,
    "customer_name": "NXG-123456-TEST",
    "alert_id": "flow-down-id",
    "router_name": "router-1",
    "router_desc": "XXXXXXX",
    "export_ip": "192.168.0.1",
    "start_time": 1711677960,
    "message": "Flow Down Alert since {Y-m-d H:i:s}(GMT) for router {router_name}"
  }
}

2.6 OP.Traffic_Director — OP Traffic Director

Fields
Field Type Description
customer_id integer Customer ID.
customer_name string Customer display name.
network string Affected network prefix.
origin string Traffic origin / service context.
change string Status or path change description.
update_time integer Change / update time (Unix timestamp, seconds).
message string Human-readable message or message template. Placeholders in {} are replaced with actual values.
Example
{
  "specversion": "1.0",
  "id": "c3d4e5f6-a7b8-9012-cdef-123456789012",
  "title": "Traffic Director changed.",
  "message": "Traffic Director change on {network} for {customer_name}",
  "source": "/nxg/notifier/global",
  "type": "OP.Traffic_Director",
  "time": 1711677960,
  "datacontenttype": "application/json",
  "data": {
    "customer_id": 1,
    "customer_name": "NXG-123456-TEST",
    "network": "192.168.0.1/24",
    "origin": "Origin Protection",
    "change": "Primary -> Backup",
    "update_time": 1711677960,
    "message": "Traffic Director change on {network} for {customer_name}"
  }
}

2.7 OP.BGP — OP BGP Change Status

Fields
Field Type Description
customer_id integer Customer ID.
customer_name string Customer display name.
site_name string Site display name.
router_name string Router / agent name.
tunnel_unique_id string Unique tunnel identifier.
tunnel_type string Tunnel type (e.g. GRE, IPSec): GRE, IPSec.
local_ip string Local IP address.
remote_ip string Remote / peer IP address.
bgp_status string Current BGP status: UP or DOWN: UP, DOWN.
change string Status or path change description: Change from DOWN to UP, Change from UP to DOWN.
update_time integer Change / update time (Unix timestamp, seconds).
flapping string Whether BGP is flapping: 0 or 1: 0, 1.
service_name string Related service name: Origin Protection, Edge Protection.
message string Human-readable message or message template. Placeholders in {} are replaced with actual values.
Example
{
  "specversion": "1.0",
  "id": "c3d4e5f6-a7b8-9012-cdef-123456789012",
  "title": "Traffic Director changed.",
  "message": "BGP status change alert [Site Name: {site_name} / Router Name: {router_name} / Tunnel ID: {tunnel_unique_id}]",
  "source": "/nxg/notifier/global",
  "type": "OP.BGP",
  "time": 1711677960,
  "datacontenttype": "application/json",
  "data": {
    "customer_id": 1,
    "customer_name": "NXG-123456-TEST",
    "site_name": "op-site",
    "router_name": "r1",
    "tunnel_unique_id": "tun-1",
    "tunnel_type": "GRE | IPSec | ...",
    "local_ip": "192.168.0.1",
    "remote_ip": "192.168.0.1",
    "bgp_status": "UP | DOWN",
    "change": "Change from DOWN to UP | Change from UP to DOWN",
    "update_time": 1711677960,
    "flapping": "0 | 1",
    "service_name": "Origin Protection | Edge Protection",
    "message": "BGP status change alert [Site Name: {site_name} / Router Name: {router_name} / Tunnel ID: {tunnel_unique_id}]"
  }
}

2.8 CP.DDoS — Clean Pipe DDoS

Fields
Field Type Description
event_id string Unique event ID.
customer_id integer Customer ID.
customer_name string Customer display name.
site_id integer Site ID.
site_name string Site display name.
target string Attack target (IP, VIP, or network prefix).
start_time integer Event / alert start time (Unix timestamp, seconds).
end_time integer Event end time (Unix timestamp, seconds). 0 while ongoing.
severity string Severity level: Low, Medium, High, Blackhole.
status string Event status: Ongoing or Stopped.
type string Attack or event category: Volumetric, mixed, UDP.
top_attack_type string Dominant attack signature / protocol: UDP, TCP, ICMP.
max_bps integer Peak traffic in bits per second.
max_pps integer Peak packets per second.
moids array of string Related MO / mitigation object IDs.
profile_name string Protection profile name.
profile_desc string Protection profile description.
is_network string Whether this is a network-level event: 0 or 1: 0, 1.
host_events integer Number of related host events.
host_ongoing integer Number of ongoing host events.
confidence_setting string Confidence detection setting: off or on: off, on.
event_flag integer Event flag value.
is_change_tag integer 1 is a false alarm; 0 is not.
mode string Detection mode: Normal, Rapid, or Smart: Normal, Rapid, Smart.
event_threshold string Rapid detection threshold. Present when mode is Rapid.
event_threshold_unit string Unit of event_threshold, for example pps. Present when mode is Rapid.
event_start_seconds integer Seconds elapsed from Rapid event start. Present when mode is Rapid.
event_pps_agg integer Aggregated packets per second. Present when mode is Rapid.
attack_type string Internal attack type identifier.
message string Human-readable message or message template. Placeholders in {} are replaced with actual values.
event_url string Deep link to the event in the portal.
Example
{
  "specversion": "1.0",
  "id": "d4e5f6a7-b8c9-0123-def0-234567890123",
  "title": "CP DDoS attack alert.",
  "message": "CP DDoS attack alert - [{customer_name} / {event_id}]",
  "source": "/nxg/notifier/global",
  "type": "CP.DDoS",
  "time": 1711700000,
  "datacontenttype": "application/json",
  "data": {
    "event_id": "EVENT-xxxxxxxx",
    "customer_id": 1,
    "customer_name": "NXG-123456-TEST",
    "site_id": 103717,
    "site_name": "cp-site",
    "target": "192.168.0.1/24",
    "start_time": 1711677960,
    "end_time": 0,
    "severity": "Low | Medium | High | Blackhole",
    "status": "Ongoing | Stopped",
    "type": "Volumetric | mixed | UDP | ...",
    "top_attack_type": "UDP | TCP | ICMP | ...",
    "max_bps": 1000000,
    "max_pps": 12666,
    "moids": [
      "5090d43c"
    ],
    "profile_name": "...",
    "profile_desc": "...",
    "is_network": "0 | 1",
    "host_events": 0,
    "host_ongoing": 0,
    "confidence_setting": "off | on",
    "event_flag": 0,
    "is_change_tag": 0,
    "mode": "Normal | Rapid | Smart",
    "event_threshold": "10",
    "event_threshold_unit": "pps",
    "event_start_seconds": 0,
    "event_pps_agg": 4000,
    "attack_type": "cp_ddos",
    "message": "CP DDoS attack alert - [{customer_name} / {event_id}]",
    "event_url": ".../#/customer/123123/cleanpipe/dashboard/site/123123/op_type/local/ddos"
  }
}

2.9 DP.HOSTING.DDoS — DP Hosting DDoS

Fields
Field Type Description
event_id string Unique event ID.
customer_id integer Customer ID.
customer_name string Customer display name.
site_id integer Site ID.
site_name string Site display name.
target string Attack target (IP, VIP, or network prefix).
start_time integer Event / alert start time (Unix timestamp, seconds).
end_time integer Event end time (Unix timestamp, seconds). 0 while ongoing.
severity string Severity level: Low, Medium, High, Blackhole.
status string Event status: Ongoing or Stopped.
type string Attack or event category: Volumetric, mixed, UDP.
top_attack_type string Dominant attack signature / protocol: UDP, TCP, ICMP.
max_bps integer Peak traffic in bits per second.
max_pps integer Peak packets per second.
profile_name string Protection profile name.
profile_desc string Protection profile description.
is_network string Whether this is a network-level event: 0 or 1: 0, 1.
host_events integer Number of related host events.
host_ongoing integer Number of ongoing host events.
confidence_setting string Confidence detection setting: off or on: off, on.
event_flag integer Event flag value.
mode string Detection mode: Normal, Rapid, or Smart: Normal, Rapid, Smart.
attack_type string Internal attack type identifier.
message string Human-readable message or message template. Placeholders in {} are replaced with actual values.
event_url string Deep link to the event in the portal.
Example
{
  "specversion": "1.0",
  "id": "e5f6a7b8-c9d0-1234-ef01-345678901234",
  "title": "DP L3 DDoS attack alert.",
  "message": "DP L3 DDoS attack alert - [{customer_name} / {event_id}]",
  "source": "/nxg/notifier/global",
  "type": "DP.HOSTING.DDoS",
  "time": 1711710000,
  "datacontenttype": "application/json",
  "data": {
    "event_id": "EVENT-xxxxxxxx",
    "customer_id": 1,
    "customer_name": "NXG-123456-TEST",
    "site_id": 200,
    "site_name": "dp-site",
    "target": "192.168.0.1",
    "start_time": 1711677960,
    "end_time": 0,
    "severity": "Low | Medium | High | Blackhole",
    "status": "Ongoing | Stopped",
    "type": "Volumetric | mixed | UDP | ...",
    "top_attack_type": "UDP | TCP | ICMP | ...",
    "max_bps": 1000000,
    "max_pps": 12666,
    "profile_name": "...",
    "profile_desc": "...",
    "is_network": "0 | 1",
    "host_events": 0,
    "host_ongoing": 0,
    "confidence_setting": "off | on",
    "event_flag": 0,
    "mode": "Normal | Rapid | Smart",
    "attack_type": "dp_l3_ddos",
    "message": "DP L3 DDoS attack alert - [{customer_name} / {event_id}]",
    "event_url": ".../main.html#/dp_l3/dashboard/action/dashboard/site/{site_id}/op_type/local/ddos"
  }
}

2.10 DP.PROXY.DDoS — DP Proxy DDoS

Fields
Field Type Description
event_id string Unique event ID.
customer_id integer Customer ID.
customer_name string Customer display name.
site_id integer Site ID.
site_name string Site display name.
target string Attack target (IP, VIP, or network prefix).
start_time integer Event / alert start time (Unix timestamp, seconds).
end_time integer Event end time (Unix timestamp, seconds). 0 while ongoing.
severity string Severity level: Low, Medium, High, Blackhole.
status string Event status: Ongoing or Stopped.
type string Attack or event category: Volumetric, mixed, UDP.
top_attack_type string Dominant attack signature / protocol: UDP, TCP, ICMP.
max_bps integer Peak traffic in bits per second.
max_pps integer Peak packets per second.
profile_name string Protection profile name.
profile_desc string Protection profile description.
is_network string Whether this is a network-level event: 0 or 1: 0, 1.
host_events integer Number of related host events.
host_ongoing integer Number of ongoing host events.
confidence_setting string Confidence detection setting: off or on: off, on.
event_flag integer Event flag value.
mode string Detection mode: Normal, Rapid, or Smart: Normal, Rapid, Smart.
attack_type string Internal attack type identifier.
message string Human-readable message or message template. Placeholders in {} are replaced with actual values.
event_url string Deep link to the event in the portal.
Example
{
  "specversion": "1.0",
  "id": "e5f6a7b8-c9d0-1234-ef01-345678901234",
  "title": "DP Proxy DDoS attack alert.",
  "message": "DP Proxy DDoS attack alert - [{customer_name} / {event_id}]",
  "source": "/nxg/notifier/global",
  "type": "DP.PROXY.DDoS",
  "time": 1711710000,
  "datacontenttype": "application/json",
  "data": {
    "event_id": "EVENT-xxxxxxxx",
    "customer_id": 1,
    "customer_name": "NXG-123456-TEST",
    "site_id": 200,
    "site_name": "dp-proxy-site",
    "target": "192.168.0.1",
    "start_time": 1711677960,
    "end_time": 0,
    "severity": "Low | Medium | High | Blackhole",
    "status": "Ongoing | Stopped",
    "type": "Volumetric | mixed | UDP | ...",
    "top_attack_type": "UDP | TCP | ICMP | ...",
    "max_bps": 1000000,
    "max_pps": 12666,
    "profile_name": "...",
    "profile_desc": "...",
    "is_network": "0 | 1",
    "host_events": 0,
    "host_ongoing": 0,
    "confidence_setting": "off | on",
    "event_flag": 0,
    "mode": "Normal | Rapid | Smart",
    "attack_type": "dp_proxy_ddos",
    "message": "DP Proxy DDoS attack alert - [{customer_name} / {event_id}]",
    "event_url": ".../main.html#/customer/{uid}/action/dns_info"
  }
}

2.11 DNS.Zone_Transfer — DNS Zone Transfer

Fields
Field Type Description
customer_id integer Customer ID.
customer_name string Customer display name.
zone_name string DNS zone name.
date_time integer Event datetime (Unix timestamp, seconds).
status string Zone transfer result status (e.g. Fail).
desc string Failure / event description (may contain HTML line breaks).
message string Human-readable message or message template. Placeholders in {} are replaced with actual values.
Example
{
  "specversion": "1.0",
  "id": "e5f6a7b8-c9d0-1234-ef01-345678901234",
  "title": "Zone transfer fail alert.",
  "message": "Zone transfer fail alert - [{zone_name}]",
  "source": "/nxg/notifier/global",
  "type": "DNS.Zone_Transfer",
  "time": 1711710000,
  "datacontenttype": "application/json",
  "data": {
    "customer_id": 1,
    "customer_name": "NXG-123456-TEST",
    "zone_name": "example.com",
    "date_time": 1711677960,
    "status": "Fail",
    "desc": "line1<br/>line2",
    "message": "Zone transfer fail alert - [{zone_name}]"
  }
}

2.12 CD.Auto_Divert — Cloud Diversion Auto Divert

Fields
Field Type Description
event_id string Unique event ID.
customer_id integer Customer ID.
customer_name string Customer display name.
network string Affected network prefix.
service string Related service name.
start_time integer Event / alert start time (Unix timestamp, seconds).
end_time integer Event end time (Unix timestamp, seconds). 0 while ongoing.
type string Divert type code: 1 or 3.
event_status string Event status: Ongoing or Stopped: Ongoing, Stopped.
event_type string Event type (e.g. Divert, Auto-Divert): Divert, Auto-Divert.
message string Human-readable message or message template. Placeholders in {} are replaced with actual values.
Example
{
  "specversion": "1.0",
  "id": "e5f6a7b8-c9d0-1234-ef01-345678901234",
  "title": "Cloud diversion attack alert.",
  "message": "Cloud diversion attack alert [{customer_name} / {event_id}]",
  "source": "/nxg/notifier/global",
  "type": "CD.Auto_Divert",
  "time": 1711710000,
  "datacontenttype": "application/json",
  "data": {
    "event_id": "cd-event-id",
    "customer_id": 1,
    "customer_name": "NXG-123456-TEST",
    "network": "192.168.0.1/24",
    "service": "Cloud Diversion",
    "start_time": 1711677960,
    "end_time": 0,
    "type": "1 | 3",
    "event_status": "Ongoing | Stopped",
    "event_type": "Divert | Auto-Divert",
    "message": "Cloud diversion attack alert [{customer_name} / {event_id}]"
  }
}

2.13 CD.BGP_ON_NET — Cloud Diversion On-Net BGP Status Change

Fields
Field Type Description
customer_id integer Customer ID.
customer_name string Customer display name.
local_ip string Local IP address.
remote_ip string Remote / peer IP address.
router_name string Router / agent name.
agent string Agent name.
bgp_status string Current BGP status: UP or DOWN: UP, DOWN.
change string Status or path change description: Change from DOWN to UP, Change from UP to DOWN.
update_time integer Change / update time (Unix timestamp, seconds).
flapping string Whether BGP is flapping: 0 or 1: 0, 1.
message string Human-readable message or message template. Placeholders in {} are replaced with actual values.
Example
{
  "specversion": "1.0",
  "id": "e5f6a7b8-c9d0-1234-ef01-345678901234",
  "title": "BGP status change alert.",
  "message": "BGP status change alert - Cloud Diversion agent [Peer IP: {remote_ip} ]",
  "source": "/nxg/notifier/global",
  "type": "CD.BGP_ON_NET",
  "time": 1711710000,
  "datacontenttype": "application/json",
  "data": {
    "customer_id": 1,
    "customer_name": "NXG-123456-TEST",
    "local_ip": "192.168.0.1",
    "remote_ip": "192.168.0.1",
    "router_name": "cd-agent",
    "agent": "agent-name",
    "bgp_status": "UP | DOWN",
    "change": "Change from DOWN to UP | Change from UP to DOWN",
    "update_time": 1711677960,
    "flapping": "0 | 1",
    "message": "BGP status change alert - Cloud Diversion agent [Peer IP: {remote_ip} ]"
  }
}

2.14 BASTIONS.BGP — BASTIONS BGP Status Changed

Fields
Field Type Description
customer_id integer Customer ID.
customer_name string Customer display name.
local_ip string Local IP address.
remote_ip string Remote / peer IP address.
router_name string Router / agent name.
agent string Agent name.
bgp_status string Current BGP status: UP or DOWN: UP, DOWN.
change string Status or path change description: Change from DOWN to UP, Change from UP to DOWN.
update_time integer Change / update time (Unix timestamp, seconds).
flapping string Whether BGP is flapping: 0 or 1: 0, 1.
message string Human-readable message or message template. Placeholders in {} are replaced with actual values.
Example
{
  "specversion": "1.0",
  "id": "e5f6a7b8-c9d0-1234-ef01-345678901234",
  "title": "BGP status change alert.",
  "message": "BGP status change alert - Cloud Diversion agent [Peer IP: {remote_ip} ]",
  "source": "/nxg/notifier/global",
  "type": "BASTIONS.BGP",
  "time": 1711710000,
  "datacontenttype": "application/json",
  "data": {
    "customer_id": 1,
    "customer_name": "NXG-123456-TEST",
    "local_ip": "192.168.0.1",
    "remote_ip": "192.168.0.1",
    "router_name": "cd-agent",
    "agent": "agent-name",
    "bgp_status": "UP | DOWN",
    "change": "Change from DOWN to UP | Change from UP to DOWN",
    "update_time": 1711677960,
    "flapping": "0 | 1",
    "message": "BGP status change alert - Cloud Diversion agent [Peer IP: {remote_ip} ]"
  }
}

2.15 BASTIONS.Flow — BASTIONS Flow

Fields
Field Type Description
customer_name string Customer display name.
alert_id string Unique alert ID.
router_name string Router / agent name.
router_desc string Router description.
export_ip string Flow export IP address.
start_time integer Event / alert start time (Unix timestamp, seconds).
message string Human-readable message or message template. Placeholders in {} are replaced with actual values.
Example
{
  "specversion": "1.0",
  "id": "e5f6a7b8-c9d0-1234-ef01-345678901234",
  "title": "Flow Down Alert.",
  "message": "Flow Down Alert since {Y-m-d H:i:s}(GMT) for router {router_name}",
  "source": "/nxg/notifier/global",
  "type": "BASTIONS.Flow",
  "time": 1711710000,
  "datacontenttype": "application/json",
  "data": {
    "customer_name": "NXG-123456-TEST",
    "alert_id": "eId",
    "router_name": "np-r1",
    "router_desc": "...",
    "export_ip": "192.168.0.1",
    "start_time": 1711677960,
    "message": "Flow Down Alert since {Y-m-d H:i:s}(GMT) for router {router_name}"
  }
}

2.16 BASTIONS.Ethernet_Port — BASTIONS Ethernet Port Status Change

Fields
Field Type Description
event_id string Unique event ID.
customer_name string Customer display name.
host string Host name.
idc string IDC / PoP identifier.
start_time integer Event / alert start time (Unix timestamp, seconds).
message string Human-readable message or message template. Placeholders in {} are replaced with actual values.
item_name string Port or item name (e.g. eth0).
item_show_key string Display category for the item (e.g. Ethernet Port, LAG Port): Ethernet Port, LAG Port.
item_status string Item status (e.g. Up, Down, Join, Leave, Healthy): Up, Down, Join, Leave, Healthy.
item_key string Item key identifier (e.g. ethernetPort).
is_bond string Whether the port is bonded: 0 or 1: 0, 1.
port_type string Port type: static or lacp: static, lacp.
reason string Status change reason (e.g. link_up, link_down, join, leave, lacp_up, lacp_down): link_up, link_down, join, leave, lacp_up, lacp_down.
item_group array of object History / grouped status entries for the item.
item_group[].item_status string Item status (e.g. Up, Down, Join, Leave, Healthy): Down, Up, Join, Leave, Healthy.
item_group[].start_time integer Event / alert start time (Unix timestamp, seconds).
Example
{
  "specversion": "1.0",
  "id": "e5f6a7b8-c9d0-1234-ef01-345678901234",
  "title": "Ethernet Port Up Event.",
  "message": "Ethernet Port Up Event | Ethernet Port Down Event | LAG Port Healthy Event | ...",
  "source": "/nxg/notifier/global",
  "type": "BASTIONS.Ethernet_Port",
  "time": 1711710000,
  "datacontenttype": "application/json",
  "data": {
    "event_id": "ea7f581ec36dd92a927cf8eb645c62d8",
    "customer_name": "NXG-123456-TEST",
    "host": "vm71",
    "idc": "spe_nxg_pop",
    "start_time": 1779456697,
    "message": "Ethernet Port Up Event | Ethernet Port Down Event | LAG Port Healthy Event | ...",
    "item_name": "eth0",
    "item_show_key": "Ethernet Port | LAG Port",
    "item_status": "Up | Down | Join | Leave | Healthy",
    "item_key": "ethernetPort",
    "is_bond": "0 | 1",
    "port_type": "static | lacp",
    "reason": "link_up | link_down | join | leave | lacp_up | lacp_down",
    "item_group": [
      {
        "item_status": "Down | Up | Join | Leave | Healthy",
        "start_time": 1779456600
      }
    ]
  }
}

3. Other Incoming Webhook Payload Structures (chat room)

This section describes the HTTP POST JSON structures expected by each third-party messaging / collaboration platform when delivering Incoming Webhook messages.

These payloads differ from the generic CloudEvents-style notification schema in sections 1 and 2. The Notifier / integration layer typically maps an internal event into the target platform format, then POSTs it to the webhook URL provided by that platform.

Platform Content-Type Notes
Google Chat application/json; charset=UTF-8 Supports plain text or cardsV2
Slack application/json Supports text, Block Kit, and attachments
Zoom Chat application/json Primarily message / content
Discord application/json Supports content and embeds
Feishu (Lark) application/json Message type is selected with msg_type
Microsoft Teams application/json Classic MessageCard or Adaptive Card

3.1 Google Chat

Google Chat Incoming Webhooks accept Chat Message objects. The simplest form is plain text; use cardsV2 for rich layouts.

Fields (text message)
Field Type Description
text string Plain / basic-formatted message body shown in the space.
thread object Optional. Threading info when replying in an existing thread.
thread.threadKey string Client-defined thread key. Requires messageReplyOption query param on the webhook URL for reply behavior.
cardsV2 array of object Optional. Rich card layout. Prefer this over legacy cards.
Example (text)
{
  "text": "AP DDoS attack alert [NXG-123456-TEST / EVENT-EF54F79D52439CDA8AD8E7FF5C]"
}
Example (cardsV2)
{
  "text": "AP DDoS attack alert",
  "cardsV2": [
    {
      "cardId": "ap-ddos-alert",
      "card": {
        "header": {
          "title": "AP DDoS attack alert",
          "subtitle": "NXG-123456-TEST"
        },
        "sections": [
          {
            "widgets": [
              {
                "decoratedText": {
                  "topLabel": "Event ID",
                  "text": "EVENT-EF54F79D52439CDA8AD8E7FF5C"
                }
              },
              {
                "decoratedText": {
                  "topLabel": "Target",
                  "text": "192.168.0.1"
                }
              },
              {
                "buttonList": {
                  "buttons": [
                    {
                      "text": "Open Event",
                      "onClick": {
                        "openLink": {
                          "url": "https://customer.example.com/#/customer/1/ap/dashboard/site/73/ddos"
                        }
                      }
                    }
                  ]
                }
              }
            ]
          }
        ]
      }
    }
  ]
}

3.2 Slack

Slack Incoming Webhooks accept message JSON. You can send plain text, or use Block Kit (blocks) to build structured messages.

Fields
Field Type Description
text string Fallback / notification text. Also used when blocks is absent.
blocks array of object Optional. Block Kit layout blocks (section, divider, actions, etc.).
attachments array of object Optional. Legacy attachment cards. Prefer blocks for new integrations.
username string Optional. Override the webhook bot display name (if allowed by workspace settings).
icon_emoji string Optional. Emoji icon override (e.g. :warning:).
icon_url string Optional. Image URL for the bot icon.
channel string Optional. Override destination channel (often disabled for modern Incoming Webhooks).
Example (text)
{
  "text": "AP DDoS attack alert [NXG-123456-TEST / EVENT-EF54F79D52439CDA8AD8E7FF5C]"
}
Example (Block Kit)
{
  "text": "AP DDoS attack alert [NXG-123456-TEST / EVENT-EF54F79D52439CDA8AD8E7FF5C]",
  "blocks": [
    {
      "type": "header",
      "text": {
        "type": "plain_text",
        "text": "AP DDoS attack alert"
      }
    },
    {
      "type": "section",
      "fields": [
        {
          "type": "mrkdwn",
          "text": "*Customer:*\nNXG-123456-TEST"
        },
        {
          "type": "mrkdwn",
          "text": "*Target:*\n192.168.0.1"
        },
        {
          "type": "mrkdwn",
          "text": "*Severity:*\nHigh"
        },
        {
          "type": "mrkdwn",
          "text": "*Status:*\nOngoing"
        }
      ]
    },
    {
      "type": "actions",
      "elements": [
        {
          "type": "button",
          "text": {
            "type": "plain_text",
            "text": "More Details"
          },
          "url": "https://customer.example.com/#/customer/1/ap/dashboard/site/73/ddos"
        }
      ]
    }
  ]
}

3.3 Zoom Chat

Zoom Team Chat Incoming Webhooks deliver messages to a specified channel. The simplest payload uses message; you can also send structured content.

Fields (simple)
Field Type Description
message string Message body posted to the Zoom Chat channel.
Fields (structured content)
Field Type Description
content object Structured message envelope.
content.head object Optional. Message header.
content.head.text string Header title text.
content.body array of object Message body widgets / segments.
content.body[].type string Segment type (e.g. message).
content.body[].text string Segment text content.
Example (simple)
{
  "message": "AP DDoS attack alert [NXG-123456-TEST / EVENT-EF54F79D52439CDA8AD8E7FF5C]"
}
Example (structured)
{
  "content": {
    "head": {
      "text": "AP DDoS attack alert"
    },
    "body": [
      {
        "type": "message",
        "text": "Customer: NXG-123456-TEST\nTarget: 192.168.0.1\nSeverity: High\nStatus: Ongoing"
      }
    ]
  }
}

3.4 Discord

Discord Incoming Webhooks send messages to a channel. They support plain-text content and one or more embeds.

Fields
Field Type Description
content string Message text content (plain / Discord markdown). Max length limited by Discord.
username string Optional. Override webhook display name for this message.
avatar_url string Optional. Override webhook avatar URL for this message.
tts boolean Optional. Whether to send as text-to-speech. Default false.
embeds array of object Optional. Rich embed objects.
embeds[].title string Embed title.
embeds[].description string Embed body text.
embeds[].url string Optional. URL opened when the title is clicked.
embeds[].color integer Optional. Sidebar color as decimal integer.
embeds[].fields array of object Optional. Named fields shown in the embed.
embeds[].fields[].name string Field name.
embeds[].fields[].value string Field value.
embeds[].fields[].inline boolean Whether to display the field inline.
allowed_mentions object Optional. Controls which mentions are parsed.
Example (text)
{
  "content": "AP DDoS attack alert [NXG-123456-TEST / EVENT-EF54F79D52439CDA8AD8E7FF5C]"
}
Example (embed)
{
  "username": "NXG Notifier",
  "content": "AP DDoS attack alert",
  "embeds": [
    {
      "title": "AP DDoS attack alert",
      "description": "High severity attack detected",
      "url": "https://customer.example.com/#/customer/1/ap/dashboard/site/73/ddos",
      "color": 15158332,
      "fields": [
        {
          "name": "Customer",
          "value": "NXG-123456-TEST",
          "inline": true
        },
        {
          "name": "Target",
          "value": "192.168.0.1",
          "inline": true
        },
        {
          "name": "Severity",
          "value": "High",
          "inline": true
        },
        {
          "name": "Status",
          "value": "Ongoing",
          "inline": true
        }
      ]
    }
  ]
}

3.5 Feishu (Lark)

Feishu / Lark custom-bot Incoming Webhooks select the message type with msg_type. Common types are text, post, and interactive (card).

Fields (text)
Field Type Description
msg_type string Message type. For plain text use "text".
content object Message content object. Shape depends on msg_type.
content.text string Text body when msg_type is "text".
Fields (interactive card)
Field Type Description
msg_type string Use "interactive" for card messages.
card object Card definition (header, elements, actions).
Example (text)
{
  "msg_type": "text",
  "content": {
    "text": "AP DDoS attack alert [NXG-123456-TEST / EVENT-EF54F79D52439CDA8AD8E7FF5C]"
  }
}
Example (interactive card)
{
  "msg_type": "interactive",
  "card": {
    "header": {
      "title": {
        "tag": "plain_text",
        "content": "AP DDoS attack alert"
      },
      "template": "red"
    },
    "elements": [
      {
        "tag": "div",
        "text": {
          "tag": "lark_md",
          "content": "**Customer:** NXG-123456-TEST\n**Target:** 192.168.0.1\n**Severity:** High\n**Status:** Ongoing"
        }
      },
      {
        "tag": "action",
        "actions": [
          {
            "tag": "button",
            "text": {
              "tag": "plain_text",
              "content": "Open Event"
            },
            "type": "primary",
            "url": "https://customer.example.com/#/customer/1/ap/dashboard/site/73/ddos"
          }
        ]
      }
    ]
  }
}

3.6 Microsoft Teams

Microsoft Teams Incoming Webhooks (Office 365 Connector / Workflows) commonly use two formats:

  1. MessageCard (classic Incoming Webhook)
  2. Adaptive Card (recommended for Workflows / Bot scenarios)
Fields (MessageCard)
Field Type Description
@type string Always "MessageCard".
@context string Always "https://schema.org/extensions" (or http://schema.org/extensions).
summary string Short summary used in notifications / accessibility.
themeColor string Hex color without # (e.g. "FF0000").
title string Card title.
text string Optional. Main body text.
sections array of object Optional. Content sections with facts / text.
sections[].activityTitle string Section title.
sections[].facts array of object Key/value facts displayed as a list.
sections[].facts[].name string Fact label.
sections[].facts[].value string Fact value.
potentialAction array of object Optional. Action buttons (e.g. OpenUri).
Example (MessageCard)
{
  "@type": "MessageCard",
  "@context": "https://schema.org/extensions",
  "summary": "AP DDoS attack alert",
  "themeColor": "FF0000",
  "title": "AP DDoS attack alert",
  "sections": [
    {
      "activityTitle": "NXG-123456-TEST",
      "facts": [
        {
          "name": "Event ID",
          "value": "EVENT-EF54F79D52439CDA8AD8E7FF5C"
        },
        {
          "name": "Target",
          "value": "192.168.0.1"
        },
        {
          "name": "Severity",
          "value": "High"
        },
        {
          "name": "Status",
          "value": "Ongoing"
        }
      ]
    }
  ],
  "potentialAction": [
    {
      "@type": "OpenUri",
      "name": "Open Event",
      "targets": [
        {
          "os": "default",
          "uri": "https://customer.example.com/#/customer/1/ap/dashboard/site/73/ddos"
        }
      ]
    }
  ]
}
Example (Adaptive Card wrapper for Workflows)
{
  "type": "message",
  "attachments": [
    {
      "contentType": "application/vnd.microsoft.card.adaptive",
      "contentUrl": null,
      "content": {
        "$schema": "http://adaptivecards.io/schemas/adaptive-card.json",
        "type": "AdaptiveCard",
        "version": "1.4",
        "body": [
          {
            "type": "TextBlock",
            "size": "Medium",
            "weight": "Bolder",
            "text": "AP DDoS attack alert"
          },
          {
            "type": "FactSet",
            "facts": [
              {
                "title": "Customer",
                "value": "NXG-123456-TEST"
              },
              {
                "title": "Target",
                "value": "192.168.0.1"
              },
              {
                "title": "Severity",
                "value": "High"
              },
              {
                "title": "Status",
                "value": "Ongoing"
              }
            ]
          }
        ],
        "actions": [
          {
            "type": "Action.OpenUrl",
            "title": "Open Event",
            "url": "https://customer.example.com/#/customer/1/ap/dashboard/site/73/ddos"
          }
        ]
      }
    }
  ]
}

Notes for consumers

  1. Parse by type: For generic notifications (sections 1–2), always branch on the top-level type field before interpreting data.
  2. Idempotency: Use top-level id (delivery ID) and/or data.event_id to avoid duplicate processing.
  3. Timestamps: time, start_time, and end_time are Unix epoch seconds unless otherwise noted.
  4. Optional fields: Fields may be omitted or empty when not applicable (e.g. end_time / duration while an event is still ongoing).
  5. Content type: For generic notifications, datacontenttype is always application/json; the HTTP body is a single JSON object matching this document.
  6. Platform webhooks: When delivering to third-party chat platforms (section 3), map the generic notification into the target platform payload and POST it to that platform’s Incoming Webhook URL with Content-Type: application/json.