Navigation :
Overview
API Catalog
-
Get Started
-
Account
-
Services
-
Technology
--
Customer API
--
SPEAdmin API
--
Apps
---
Notifier
----
Webhook
----- Introduce
Nexusguard App
Introduce
There are a variety of services you can connect to Nexusguard using webhooks to receive alert notifications. Refer to the table below to learn how to connect your account to popular webhook services.
Get into Notifier Apps .
In the Webhook page, select Create .
Give your webhook a name to use for identification later.
In the URL field, enter the URL of the third-party service that you have previously set up and want to connect to your account.
If needed, insert the custom HTTP Header and put the Secret in it.
Select Save to finish setting up your webhook.
The new webhook will appear in the Webhooks page.
Firewall settings
Webhook notifications are sent from Nexusguard’s IP ranges. If your webhook endpoint is protected by a firewall, you must allowlist these Agent IP addresses to receive notifications.
Generic webhooks
If you use a service that is not covered by Nexusguard’s currently available webhooks, you can configure your own, and enter a valid webhook URL.
It is always recommended to use a secret for generic webhooks. You can put a secret in a Custom HTTP Header of every request made. If this header is not present, or is not your specified value, you should reject the webhook.
After selecting Save and Test , your webhook should now be configured as a destination that you can use to attach to policies.
Limitations of generic webhooks
Nexusguard generic webhook notifications will only be dispatched to a publicly resolvable IP address on port 80 or 443 .
Popular webhook services
Nexusguard currently supports the following popular webhook services.
Google Chat
Secret: The secret is part of the URL. Nexusguard parses this information automatically and there is no input needed from the user.
URL: URL varies depending on the Google Chat channel’s address.
Slack
Secret: The secret is part of the URL. Nexusguard parses this information automatically and there is no input needed from the user.
URL: URL varies depending on the Slack channel’s address.
Discord
Secret: The secret is part of the URL. Nexusguard parses this information automatically and there is no input needed from the user.
URL: URL varies depending on the Discord channel’s address.
Zoom Chat
Secret: The secret is part of the URL. Nexusguard parses this information automatically and there is no input needed from the user.
URL: The URL varies depending on the Custom Robot.
Feishu
Secret: The secret is part of the URL. Nexusguard parses this information automatically and there is no input needed from the user.
URL: The URL varies depending on the Custom Robot.
Teams
Secret: The secret is part of the URL. Nexusguard parses this information automatically and there is no input needed from the user.
URL: URL is provided by Teams when the Incoming Webhook connector is created.
Webhook Payload
This document describes the payload data structures of webhook notifications:
Generic webhook schema — unified outer CloudEvents-style envelope
Notification data by type — data fields and examples for each notification type
Other Incoming Webhook payloads — target formats when delivering to Google Chat / Slack / Zoom Chat / Discord / Feishu / Teams and similar platforms
Sections 1 and 2 describe generic notifications sent by the system. Section 3 describes the payloads used when mapping those notifications to third-party chat platform Incoming Webhooks.
1. Generic Webhook Payload Schema
All generic webhook notifications follow this schema:
{
"specversion": "string",
"id": "string",
"title": "string",
"message": "string",
"source": "/nxg/notifier/global",
"type": "string",
"time": "intval",
"datacontenttype": "application/json",
"data": {}
}
Field description
Field
Type
Description
specversion
string
Payload schema version. Currently "1.0".
id
string
Unique identifier of this webhook delivery (UUID recommended). Used for idempotency / deduplication.
title
string
Short human-readable title of the notification.
message
string
Human-readable summary of the notification.
source
string
Origin of the event (e.g. service name or URI identifying the producer).
type
string
Notification type. Determines the structure of data. See section 2 .
time
integer
Unix timestamp (seconds) when the event occurred or was generated. (Timezone is always GMT+0)
datacontenttype
string
Media type of data. Always "application/json".
data
object
Type-specific payload. Shape depends on type.
Example (envelope only)
{
"specversion": "1.0",
"id": "550e8400-e29b-41d4-a716-446655440000",
"title": "AP DDoS attack alert",
"message": "High severity volumetric attack detected on site example.com",
"source": "/nxg/notifier/global",
"type": "AP.DDoS",
"time": 1711677960,
"datacontenttype": "application/json",
"data": {}
}
2. Notification data by type
type values use uppercase letters joined by . (for example, AP.DDoS). The table below lists the main types, with field descriptions and examples for each data payload.
type
Service
Description
AP.DDoS
AP
Application Protection DDoS event
AP.WAF
AP
Application Protection WAF / Web Attack event
AP.SSL
AP
Application Protection SSL / certificate related event
OP.DDoS
OP
Origin Protection DDoS event
OP.Flow
OP
Origin Protection Flow event. As of now, only Flow down event is available.
OP.Traffic_Director
OP
Origin Protection Traffic Director event
OP.BGP
OP
Origin Protection BGP Change Status event
CP.DDoS
CP
Clean Pipe DDoS event
DP.HOSTING.DDoS
DP
DNS Protection(HOSTING) DDoS event
DP.PROXY.DDoS
DP
DNS Protection(PROXY) DDoS event
DNS.Zone_Transfer
DNS
DNS Zone Transfer event
CD.Auto_Divert
Cloud Diversion
Cloud Diversion Auto Divert Event
CD.BGP_ON_NET
Cloud Diversion
Cloud Diversion On-Net BGP Status Change
BASTIONS.BGP
BASTIONS
BASTIONS BGP Status Changed.
BASTIONS.Flow
BASTIONS
Cloud Diversion Flow event. As of now, only Flow down event is available.
BASTIONS.Ethernet_Port
BASTIONS
Bastions — Ethernet Port Status Change
2.1 AP.DDoS — AP DDoS
Fields
Field
Type
Description
event_id
string
Unique event ID.
customer_id
integer
Customer ID.
customer_name
string
Customer display name.
site_id
integer
Site ID.
site_name
string
Site display name.
target
string
Attack target (IP, VIP, or network prefix).
domain
string
Related domain hostname. May be empty when not applicable.
domain_id
string
Domain ID. May be empty string when not applicable.
start_time
integer
Event / alert start time (Unix timestamp, seconds).
end_time
integer
Event end time (Unix timestamp, seconds). 0 while ongoing.
type
string
Attack category: Volumetric or mixed.
status
string
Event status: Ongoing or Stopped.
severity
string
Severity level: Low, Medium, High, Blackhole.
organization
string
Comma-separated country / region codes of attack sources (e.g. US,CN).
attack_type
string
Internal attack type identifier.
mail_type
string
Mail / notification category identifier.
message
string
Human-readable message or message template. Placeholders in {} are replaced with actual values.
event_url
string
Deep link to the event in the portal.
Example
{
"specversion": "1.0",
"id": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
"title": "AP DDoS attack alert.",
"message": "AP DDoS attack alert [{customer_name} / {event_id}]",
"source": "/nxg/notifier/global",
"type": "AP.DDoS",
"time": 1711677960,
"datacontenttype": "application/json",
"data": {
"event_id": "EVENT-EF54F79D52439CDA8AD8E7FF5C",
"customer_id": 1,
"customer_name": "NXG-123456-TEST",
"site_id": 73,
"site_name": "holodark.com",
"target": "192.168.0.1",
"domain": "",
"domain_id": "",
"start_time": 1711677960,
"end_time": 0,
"type": "Volumetric | Application | mixed",
"status": "Ongoing | Stopped",
"severity": "Low | Medium | High | Blackhole",
"organization": "US,CN",
"attack_type": "ap_ddos",
"mail_type": "ap_ddos",
"message": "AP DDoS attack alert [{customer_name} / {event_id}]",
"event_url": ".../#/customer/{uid}/ap/dashboard/site/{site_id}/ddos"
}
}
2.2 AP.WAF — AP Web Attack (WAF)
Fields
Field
Type
Description
event_id
string
Unique event ID.
customer_id
integer
Customer ID.
customer_name
string
Customer display name.
site_id
integer
Site ID.
site_name
string
Site display name.
target
string
Attack target (IP, VIP, or network prefix).
domain
string
Related domain hostname.
domain_id
integer
Domain ID.
start_time
integer
Event / alert start time (Unix timestamp, seconds).
end_time
integer
Event end time (Unix timestamp, seconds). 0 while ongoing.
type
string
Attack category. Always "Web Attack" for this notification type.
status
string
Event status: Ongoing or Stopped.
severity
string
Severity level: Low, Medium, High.
organization
string
Comma-separated country / region codes of attack sources (e.g. US,CN).
attack_type
string
Internal attack type identifier.
mail_type
string
Mail / notification category identifier.
message
string
Human-readable message or message template. Placeholders in {} are replaced with actual values.
event_url
string
Deep link to the event in the portal.
Example
{
"specversion": "1.0",
"id": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
"title": "AP Web attack alert.",
"message": "AP Web attack alert [{customer_name} / {event_id}]",
"source": "/nxg/notifier/global",
"type": "AP.WAF",
"time": 1711681200,
"datacontenttype": "application/json",
"data": {
"event_id": "WAF-EVENT-xxx",
"customer_id": 1,
"customer_name": "NXG-123456-TEST",
"site_id": 73,
"site_name": "holodark.com",
"target": "https://example.com/path",
"domain": "example.com",
"domain_id": 12,
"start_time": 1711677960,
"end_time": 0,
"type": "Web Attack",
"status": "Ongoing | Stopped",
"severity": "Low | Medium | High",
"organization": "US,CN",
"attack_type": "ap_waf",
"mail_type": "ap_waf",
"message": "AP Web attack alert [{customer_name} / {event_id}]",
"event_url": ".../#/customer/{uid}/ap/dashboard/site/{site_id}/waf"
}
}
2.3 AP.SSL — AP SSL Certificate Expiration
Fields
Field
Type
Description
customer_id
integer
Customer ID.
customer_name
string
Customer display name.
site_name
string
Site display name.
domain
string
Related domain hostname.
expires_time
string
Certificate expiration datetime (YYYY-MM-DD HH:mm:ss, GMT+0).
expires_days
string
Days remaining until expiration: 30, 7, 3, 1, or 0 (already expired).
status
string
Expiration status: Expiring in 30 days, Expiring in 7 days, Expiring in 3 days, Expiring in 1 days, or Expired.
message
string
Human-readable message or message template. Placeholders in {} are replaced with actual values.
url
string
Deep link to the related settings page in the portal.
Example
{
"specversion": "1.0",
"id": "f6a7b8c9-d0e1-2345-f012-456789012345",
"title": "SSL certificate expiration alert.",
"message": "SSL certificate expiration alert[{domain} certificate is about to expire in {expires_days} days]",
"source": "/nxg/notifier/global",
"type": "AP.SSL",
"time": 1711684800,
"datacontenttype": "application/json",
"data": {
"customer_id": 1,
"customer_name": "NXG-123456-TEST",
"site_name": "holodark.com",
"domain": "www.example.com",
"expires_time": "2026-08-28 00:00:00",
"expires_days": "30",
"status": "Expiring in 30 days",
"message": "SSL certificate expiration alert[{domain} certificate is about to expire in {expires_days} days]",
"url": "https://customer.example.com/#/customer/1/action/site_info/site/73/domain"
}
}
2.4 OP.DDoS — OP DDoS
Fields
Field
Type
Description
event_id
string
Unique event ID.
customer_id
integer
Customer ID.
customer_name
string
Customer display name.
site_id
integer
Site ID.
site_name
string
Site display name.
target
string
Attack target (IP, VIP, or network prefix).
start_time
integer
Event / alert start time (Unix timestamp, seconds).
end_time
integer
Event end time (Unix timestamp, seconds). 0 while ongoing.
severity
string
Severity level: Low, Medium, High, Blackhole.
status
string
Event status: Ongoing or Stopped.
type
string
Attack or event category: Volumetric, mixed, UDP.
top_attack_type
string
Dominant attack signature / protocol: UDP, TCP, ICMP.
max_bps
integer
Peak traffic in bits per second.
max_pps
integer
Peak packets per second.
moids
array of string
Related MO / mitigation object IDs.
profile_name
string
Protection profile name.
profile_desc
string
Protection profile description.
is_network
string
Whether this is a network-level event: 0 or 1: 0, 1.
host_events
integer
Number of related host events.
host_ongoing
integer
Number of ongoing host events.
confidence_setting
string
Confidence detection setting: off or on: off, on.
event_flag
integer
Event flag value.
mode
string
Detection mode: Normal, Rapid, Smart.
duration
string
Human-readable event duration.
attack_type
string
Internal attack type identifier.
message
string
Human-readable message or message template. Placeholders in {} are replaced with actual values.
event_url
string
Deep link to the event in the portal.
Example
{
"specversion": "1.0",
"id": "c3d4e5f6-a7b8-9012-cdef-123456789012",
"title": "OP DDoS attack alert.",
"message": "OP DDoS attack alert - [{customer_name} / {event_id}]",
"source": "/nxg/notifier/global",
"type": "OP.DDoS",
"time": 1704855421,
"datacontenttype": "application/json",
"data": {
"event_id": "EVENT-FE3B5B45FC8712D6584B844D8E",
"customer_id": 31,
"customer_name": "NXG-123456-TEST",
"site_id": 100,
"site_name": "op-site",
"target": "192.168.0.1",
"start_time": 1711677960,
"end_time": 0,
"severity": "Low | Medium | High | Blackhole",
"status": "Ongoing | Stopped",
"type": "Volumetric | mixed | UDP | ...",
"top_attack_type": "UDP | TCP | ICMP | ...",
"max_bps": 1000000,
"max_pps": 12666,
"moids": [
"5090d43c"
],
"profile_name": "...",
"profile_desc": "...",
"is_network": "0 | 1",
"host_events": 0,
"host_ongoing": 0,
"confidence_setting": "off | on",
"event_flag": 0,
"mode": "Normal | Rapid | Smart",
"duration": "20 mins 2 secs",
"attack_type": "op_ddos",
"message": "OP DDoS attack alert - [{customer_name} / {event_id}]",
"event_url": ".../#/customer/{uid}/op/dashboard/site/{site_id}/op_type/cloud/ddos"
}
}
2.5 OP.Flow — OP Flow
Fields
Field
Type
Description
customer_id
integer
Customer ID.
customer_name
string
Customer display name.
alert_id
string
Unique alert ID.
router_name
string
Router / agent name.
router_desc
string
Router description.
export_ip
string
Flow export IP address.
start_time
integer
Event / alert start time (Unix timestamp, seconds).
message
string
Human-readable message or message template. Placeholders in {} are replaced with actual values.
Example
{
"specversion": "1.0",
"id": "c3d4e5f6-a7b8-9012-cdef-123456789012",
"title": "Flow Down Alert.",
"message": "Flow Down Alert since {Y-m-d H:i:s}(GMT) for router {router_name}",
"source": "/nxg/notifier/global",
"type": "OP.Flow",
"time": 1711677960,
"datacontenttype": "application/json",
"data": {
"customer_id": 1,
"customer_name": "NXG-123456-TEST",
"alert_id": "flow-down-id",
"router_name": "router-1",
"router_desc": "XXXXXXX",
"export_ip": "192.168.0.1",
"start_time": 1711677960,
"message": "Flow Down Alert since {Y-m-d H:i:s}(GMT) for router {router_name}"
}
}
2.6 OP.Traffic_Director — OP Traffic Director
Fields
Field
Type
Description
customer_id
integer
Customer ID.
customer_name
string
Customer display name.
network
string
Affected network prefix.
origin
string
Traffic origin / service context.
change
string
Status or path change description.
update_time
integer
Change / update time (Unix timestamp, seconds).
message
string
Human-readable message or message template. Placeholders in {} are replaced with actual values.
Example
{
"specversion": "1.0",
"id": "c3d4e5f6-a7b8-9012-cdef-123456789012",
"title": "Traffic Director changed.",
"message": "Traffic Director change on {network} for {customer_name}",
"source": "/nxg/notifier/global",
"type": "OP.Traffic_Director",
"time": 1711677960,
"datacontenttype": "application/json",
"data": {
"customer_id": 1,
"customer_name": "NXG-123456-TEST",
"network": "192.168.0.1/24",
"origin": "Origin Protection",
"change": "Primary -> Backup",
"update_time": 1711677960,
"message": "Traffic Director change on {network} for {customer_name}"
}
}
2.7 OP.BGP — OP BGP Change Status
Fields
Field
Type
Description
customer_id
integer
Customer ID.
customer_name
string
Customer display name.
site_name
string
Site display name.
router_name
string
Router / agent name.
tunnel_unique_id
string
Unique tunnel identifier.
tunnel_type
string
Tunnel type (e.g. GRE, IPSec): GRE, IPSec.
local_ip
string
Local IP address.
remote_ip
string
Remote / peer IP address.
bgp_status
string
Current BGP status: UP or DOWN: UP, DOWN.
change
string
Status or path change description: Change from DOWN to UP, Change from UP to DOWN.
update_time
integer
Change / update time (Unix timestamp, seconds).
flapping
string
Whether BGP is flapping: 0 or 1: 0, 1.
service_name
string
Related service name: Origin Protection, Edge Protection.
message
string
Human-readable message or message template. Placeholders in {} are replaced with actual values.
Example
{
"specversion": "1.0",
"id": "c3d4e5f6-a7b8-9012-cdef-123456789012",
"title": "Traffic Director changed.",
"message": "BGP status change alert [Site Name: {site_name} / Router Name: {router_name} / Tunnel ID: {tunnel_unique_id}]",
"source": "/nxg/notifier/global",
"type": "OP.BGP",
"time": 1711677960,
"datacontenttype": "application/json",
"data": {
"customer_id": 1,
"customer_name": "NXG-123456-TEST",
"site_name": "op-site",
"router_name": "r1",
"tunnel_unique_id": "tun-1",
"tunnel_type": "GRE | IPSec | ...",
"local_ip": "192.168.0.1",
"remote_ip": "192.168.0.1",
"bgp_status": "UP | DOWN",
"change": "Change from DOWN to UP | Change from UP to DOWN",
"update_time": 1711677960,
"flapping": "0 | 1",
"service_name": "Origin Protection | Edge Protection",
"message": "BGP status change alert [Site Name: {site_name} / Router Name: {router_name} / Tunnel ID: {tunnel_unique_id}]"
}
}
2.8 CP.DDoS — Clean Pipe DDoS
Fields
Field
Type
Description
event_id
string
Unique event ID.
customer_id
integer
Customer ID.
customer_name
string
Customer display name.
site_id
integer
Site ID.
site_name
string
Site display name.
target
string
Attack target (IP, VIP, or network prefix).
start_time
integer
Event / alert start time (Unix timestamp, seconds).
end_time
integer
Event end time (Unix timestamp, seconds). 0 while ongoing.
severity
string
Severity level: Low, Medium, High, Blackhole.
status
string
Event status: Ongoing or Stopped.
type
string
Attack or event category: Volumetric, mixed, UDP.
top_attack_type
string
Dominant attack signature / protocol: UDP, TCP, ICMP.
max_bps
integer
Peak traffic in bits per second.
max_pps
integer
Peak packets per second.
moids
array of string
Related MO / mitigation object IDs.
profile_name
string
Protection profile name.
profile_desc
string
Protection profile description.
is_network
string
Whether this is a network-level event: 0 or 1: 0, 1.
host_events
integer
Number of related host events.
host_ongoing
integer
Number of ongoing host events.
confidence_setting
string
Confidence detection setting: off or on: off, on.
event_flag
integer
Event flag value.
is_change_tag
integer
1 is a false alarm; 0 is not.
mode
string
Detection mode: Normal, Rapid, or Smart: Normal, Rapid, Smart.
event_threshold
string
Rapid detection threshold. Present when mode is Rapid.
event_threshold_unit
string
Unit of event_threshold, for example pps. Present when mode is Rapid.
event_start_seconds
integer
Seconds elapsed from Rapid event start. Present when mode is Rapid.
event_pps_agg
integer
Aggregated packets per second. Present when mode is Rapid.
attack_type
string
Internal attack type identifier.
message
string
Human-readable message or message template. Placeholders in {} are replaced with actual values.
event_url
string
Deep link to the event in the portal.
Example
{
"specversion": "1.0",
"id": "d4e5f6a7-b8c9-0123-def0-234567890123",
"title": "CP DDoS attack alert.",
"message": "CP DDoS attack alert - [{customer_name} / {event_id}]",
"source": "/nxg/notifier/global",
"type": "CP.DDoS",
"time": 1711700000,
"datacontenttype": "application/json",
"data": {
"event_id": "EVENT-xxxxxxxx",
"customer_id": 1,
"customer_name": "NXG-123456-TEST",
"site_id": 103717,
"site_name": "cp-site",
"target": "192.168.0.1/24",
"start_time": 1711677960,
"end_time": 0,
"severity": "Low | Medium | High | Blackhole",
"status": "Ongoing | Stopped",
"type": "Volumetric | mixed | UDP | ...",
"top_attack_type": "UDP | TCP | ICMP | ...",
"max_bps": 1000000,
"max_pps": 12666,
"moids": [
"5090d43c"
],
"profile_name": "...",
"profile_desc": "...",
"is_network": "0 | 1",
"host_events": 0,
"host_ongoing": 0,
"confidence_setting": "off | on",
"event_flag": 0,
"is_change_tag": 0,
"mode": "Normal | Rapid | Smart",
"event_threshold": "10",
"event_threshold_unit": "pps",
"event_start_seconds": 0,
"event_pps_agg": 4000,
"attack_type": "cp_ddos",
"message": "CP DDoS attack alert - [{customer_name} / {event_id}]",
"event_url": ".../#/customer/123123/cleanpipe/dashboard/site/123123/op_type/local/ddos"
}
}
2.9 DP.HOSTING.DDoS — DP Hosting DDoS
Fields
Field
Type
Description
event_id
string
Unique event ID.
customer_id
integer
Customer ID.
customer_name
string
Customer display name.
site_id
integer
Site ID.
site_name
string
Site display name.
target
string
Attack target (IP, VIP, or network prefix).
start_time
integer
Event / alert start time (Unix timestamp, seconds).
end_time
integer
Event end time (Unix timestamp, seconds). 0 while ongoing.
severity
string
Severity level: Low, Medium, High, Blackhole.
status
string
Event status: Ongoing or Stopped.
type
string
Attack or event category: Volumetric, mixed, UDP.
top_attack_type
string
Dominant attack signature / protocol: UDP, TCP, ICMP.
max_bps
integer
Peak traffic in bits per second.
max_pps
integer
Peak packets per second.
profile_name
string
Protection profile name.
profile_desc
string
Protection profile description.
is_network
string
Whether this is a network-level event: 0 or 1: 0, 1.
host_events
integer
Number of related host events.
host_ongoing
integer
Number of ongoing host events.
confidence_setting
string
Confidence detection setting: off or on: off, on.
event_flag
integer
Event flag value.
mode
string
Detection mode: Normal, Rapid, or Smart: Normal, Rapid, Smart.
attack_type
string
Internal attack type identifier.
message
string
Human-readable message or message template. Placeholders in {} are replaced with actual values.
event_url
string
Deep link to the event in the portal.
Example
{
"specversion": "1.0",
"id": "e5f6a7b8-c9d0-1234-ef01-345678901234",
"title": "DP L3 DDoS attack alert.",
"message": "DP L3 DDoS attack alert - [{customer_name} / {event_id}]",
"source": "/nxg/notifier/global",
"type": "DP.HOSTING.DDoS",
"time": 1711710000,
"datacontenttype": "application/json",
"data": {
"event_id": "EVENT-xxxxxxxx",
"customer_id": 1,
"customer_name": "NXG-123456-TEST",
"site_id": 200,
"site_name": "dp-site",
"target": "192.168.0.1",
"start_time": 1711677960,
"end_time": 0,
"severity": "Low | Medium | High | Blackhole",
"status": "Ongoing | Stopped",
"type": "Volumetric | mixed | UDP | ...",
"top_attack_type": "UDP | TCP | ICMP | ...",
"max_bps": 1000000,
"max_pps": 12666,
"profile_name": "...",
"profile_desc": "...",
"is_network": "0 | 1",
"host_events": 0,
"host_ongoing": 0,
"confidence_setting": "off | on",
"event_flag": 0,
"mode": "Normal | Rapid | Smart",
"attack_type": "dp_l3_ddos",
"message": "DP L3 DDoS attack alert - [{customer_name} / {event_id}]",
"event_url": ".../main.html#/dp_l3/dashboard/action/dashboard/site/{site_id}/op_type/local/ddos"
}
}
2.10 DP.PROXY.DDoS — DP Proxy DDoS
Fields
Field
Type
Description
event_id
string
Unique event ID.
customer_id
integer
Customer ID.
customer_name
string
Customer display name.
site_id
integer
Site ID.
site_name
string
Site display name.
target
string
Attack target (IP, VIP, or network prefix).
start_time
integer
Event / alert start time (Unix timestamp, seconds).
end_time
integer
Event end time (Unix timestamp, seconds). 0 while ongoing.
severity
string
Severity level: Low, Medium, High, Blackhole.
status
string
Event status: Ongoing or Stopped.
type
string
Attack or event category: Volumetric, mixed, UDP.
top_attack_type
string
Dominant attack signature / protocol: UDP, TCP, ICMP.
max_bps
integer
Peak traffic in bits per second.
max_pps
integer
Peak packets per second.
profile_name
string
Protection profile name.
profile_desc
string
Protection profile description.
is_network
string
Whether this is a network-level event: 0 or 1: 0, 1.
host_events
integer
Number of related host events.
host_ongoing
integer
Number of ongoing host events.
confidence_setting
string
Confidence detection setting: off or on: off, on.
event_flag
integer
Event flag value.
mode
string
Detection mode: Normal, Rapid, or Smart: Normal, Rapid, Smart.
attack_type
string
Internal attack type identifier.
message
string
Human-readable message or message template. Placeholders in {} are replaced with actual values.
event_url
string
Deep link to the event in the portal.
Example
{
"specversion": "1.0",
"id": "e5f6a7b8-c9d0-1234-ef01-345678901234",
"title": "DP Proxy DDoS attack alert.",
"message": "DP Proxy DDoS attack alert - [{customer_name} / {event_id}]",
"source": "/nxg/notifier/global",
"type": "DP.PROXY.DDoS",
"time": 1711710000,
"datacontenttype": "application/json",
"data": {
"event_id": "EVENT-xxxxxxxx",
"customer_id": 1,
"customer_name": "NXG-123456-TEST",
"site_id": 200,
"site_name": "dp-proxy-site",
"target": "192.168.0.1",
"start_time": 1711677960,
"end_time": 0,
"severity": "Low | Medium | High | Blackhole",
"status": "Ongoing | Stopped",
"type": "Volumetric | mixed | UDP | ...",
"top_attack_type": "UDP | TCP | ICMP | ...",
"max_bps": 1000000,
"max_pps": 12666,
"profile_name": "...",
"profile_desc": "...",
"is_network": "0 | 1",
"host_events": 0,
"host_ongoing": 0,
"confidence_setting": "off | on",
"event_flag": 0,
"mode": "Normal | Rapid | Smart",
"attack_type": "dp_proxy_ddos",
"message": "DP Proxy DDoS attack alert - [{customer_name} / {event_id}]",
"event_url": ".../main.html#/customer/{uid}/action/dns_info"
}
}
2.11 DNS.Zone_Transfer — DNS Zone Transfer
Fields
Field
Type
Description
customer_id
integer
Customer ID.
customer_name
string
Customer display name.
zone_name
string
DNS zone name.
date_time
integer
Event datetime (Unix timestamp, seconds).
status
string
Zone transfer result status (e.g. Fail).
desc
string
Failure / event description (may contain HTML line breaks).
message
string
Human-readable message or message template. Placeholders in {} are replaced with actual values.
Example
{
"specversion": "1.0",
"id": "e5f6a7b8-c9d0-1234-ef01-345678901234",
"title": "Zone transfer fail alert.",
"message": "Zone transfer fail alert - [{zone_name}]",
"source": "/nxg/notifier/global",
"type": "DNS.Zone_Transfer",
"time": 1711710000,
"datacontenttype": "application/json",
"data": {
"customer_id": 1,
"customer_name": "NXG-123456-TEST",
"zone_name": "example.com",
"date_time": 1711677960,
"status": "Fail",
"desc": "line1<br/>line2",
"message": "Zone transfer fail alert - [{zone_name}]"
}
}
2.12 CD.Auto_Divert — Cloud Diversion Auto Divert
Fields
Field
Type
Description
event_id
string
Unique event ID.
customer_id
integer
Customer ID.
customer_name
string
Customer display name.
network
string
Affected network prefix.
service
string
Related service name.
start_time
integer
Event / alert start time (Unix timestamp, seconds).
end_time
integer
Event end time (Unix timestamp, seconds). 0 while ongoing.
type
string
Divert type code: 1 or 3.
event_status
string
Event status: Ongoing or Stopped: Ongoing, Stopped.
event_type
string
Event type (e.g. Divert, Auto-Divert): Divert, Auto-Divert.
message
string
Human-readable message or message template. Placeholders in {} are replaced with actual values.
Example
{
"specversion": "1.0",
"id": "e5f6a7b8-c9d0-1234-ef01-345678901234",
"title": "Cloud diversion attack alert.",
"message": "Cloud diversion attack alert [{customer_name} / {event_id}]",
"source": "/nxg/notifier/global",
"type": "CD.Auto_Divert",
"time": 1711710000,
"datacontenttype": "application/json",
"data": {
"event_id": "cd-event-id",
"customer_id": 1,
"customer_name": "NXG-123456-TEST",
"network": "192.168.0.1/24",
"service": "Cloud Diversion",
"start_time": 1711677960,
"end_time": 0,
"type": "1 | 3",
"event_status": "Ongoing | Stopped",
"event_type": "Divert | Auto-Divert",
"message": "Cloud diversion attack alert [{customer_name} / {event_id}]"
}
}
2.13 CD.BGP_ON_NET — Cloud Diversion On-Net BGP Status Change
Fields
Field
Type
Description
customer_id
integer
Customer ID.
customer_name
string
Customer display name.
local_ip
string
Local IP address.
remote_ip
string
Remote / peer IP address.
router_name
string
Router / agent name.
agent
string
Agent name.
bgp_status
string
Current BGP status: UP or DOWN: UP, DOWN.
change
string
Status or path change description: Change from DOWN to UP, Change from UP to DOWN.
update_time
integer
Change / update time (Unix timestamp, seconds).
flapping
string
Whether BGP is flapping: 0 or 1: 0, 1.
message
string
Human-readable message or message template. Placeholders in {} are replaced with actual values.
Example
{
"specversion": "1.0",
"id": "e5f6a7b8-c9d0-1234-ef01-345678901234",
"title": "BGP status change alert.",
"message": "BGP status change alert - Cloud Diversion agent [Peer IP: {remote_ip} ]",
"source": "/nxg/notifier/global",
"type": "CD.BGP_ON_NET",
"time": 1711710000,
"datacontenttype": "application/json",
"data": {
"customer_id": 1,
"customer_name": "NXG-123456-TEST",
"local_ip": "192.168.0.1",
"remote_ip": "192.168.0.1",
"router_name": "cd-agent",
"agent": "agent-name",
"bgp_status": "UP | DOWN",
"change": "Change from DOWN to UP | Change from UP to DOWN",
"update_time": 1711677960,
"flapping": "0 | 1",
"message": "BGP status change alert - Cloud Diversion agent [Peer IP: {remote_ip} ]"
}
}
2.14 BASTIONS.BGP — BASTIONS BGP Status Changed
Fields
Field
Type
Description
customer_id
integer
Customer ID.
customer_name
string
Customer display name.
local_ip
string
Local IP address.
remote_ip
string
Remote / peer IP address.
router_name
string
Router / agent name.
agent
string
Agent name.
bgp_status
string
Current BGP status: UP or DOWN: UP, DOWN.
change
string
Status or path change description: Change from DOWN to UP, Change from UP to DOWN.
update_time
integer
Change / update time (Unix timestamp, seconds).
flapping
string
Whether BGP is flapping: 0 or 1: 0, 1.
message
string
Human-readable message or message template. Placeholders in {} are replaced with actual values.
Example
{
"specversion": "1.0",
"id": "e5f6a7b8-c9d0-1234-ef01-345678901234",
"title": "BGP status change alert.",
"message": "BGP status change alert - Cloud Diversion agent [Peer IP: {remote_ip} ]",
"source": "/nxg/notifier/global",
"type": "BASTIONS.BGP",
"time": 1711710000,
"datacontenttype": "application/json",
"data": {
"customer_id": 1,
"customer_name": "NXG-123456-TEST",
"local_ip": "192.168.0.1",
"remote_ip": "192.168.0.1",
"router_name": "cd-agent",
"agent": "agent-name",
"bgp_status": "UP | DOWN",
"change": "Change from DOWN to UP | Change from UP to DOWN",
"update_time": 1711677960,
"flapping": "0 | 1",
"message": "BGP status change alert - Cloud Diversion agent [Peer IP: {remote_ip} ]"
}
}
2.15 BASTIONS.Flow — BASTIONS Flow
Fields
Field
Type
Description
customer_name
string
Customer display name.
alert_id
string
Unique alert ID.
router_name
string
Router / agent name.
router_desc
string
Router description.
export_ip
string
Flow export IP address.
start_time
integer
Event / alert start time (Unix timestamp, seconds).
message
string
Human-readable message or message template. Placeholders in {} are replaced with actual values.
Example
{
"specversion": "1.0",
"id": "e5f6a7b8-c9d0-1234-ef01-345678901234",
"title": "Flow Down Alert.",
"message": "Flow Down Alert since {Y-m-d H:i:s}(GMT) for router {router_name}",
"source": "/nxg/notifier/global",
"type": "BASTIONS.Flow",
"time": 1711710000,
"datacontenttype": "application/json",
"data": {
"customer_name": "NXG-123456-TEST",
"alert_id": "eId",
"router_name": "np-r1",
"router_desc": "...",
"export_ip": "192.168.0.1",
"start_time": 1711677960,
"message": "Flow Down Alert since {Y-m-d H:i:s}(GMT) for router {router_name}"
}
}
2.16 BASTIONS.Ethernet_Port — BASTIONS Ethernet Port Status Change
Fields
Field
Type
Description
event_id
string
Unique event ID.
customer_name
string
Customer display name.
host
string
Host name.
idc
string
IDC / PoP identifier.
start_time
integer
Event / alert start time (Unix timestamp, seconds).
message
string
Human-readable message or message template. Placeholders in {} are replaced with actual values.
item_name
string
Port or item name (e.g. eth0).
item_show_key
string
Display category for the item (e.g. Ethernet Port, LAG Port): Ethernet Port, LAG Port.
item_status
string
Item status (e.g. Up, Down, Join, Leave, Healthy): Up, Down, Join, Leave, Healthy.
item_key
string
Item key identifier (e.g. ethernetPort).
is_bond
string
Whether the port is bonded: 0 or 1: 0, 1.
port_type
string
Port type: static or lacp: static, lacp.
reason
string
Status change reason (e.g. link_up, link_down, join, leave, lacp_up, lacp_down): link_up, link_down, join, leave, lacp_up, lacp_down.
item_group
array of object
History / grouped status entries for the item.
item_group[].item_status
string
Item status (e.g. Up, Down, Join, Leave, Healthy): Down, Up, Join, Leave, Healthy.
item_group[].start_time
integer
Event / alert start time (Unix timestamp, seconds).
Example
{
"specversion": "1.0",
"id": "e5f6a7b8-c9d0-1234-ef01-345678901234",
"title": "Ethernet Port Up Event.",
"message": "Ethernet Port Up Event | Ethernet Port Down Event | LAG Port Healthy Event | ...",
"source": "/nxg/notifier/global",
"type": "BASTIONS.Ethernet_Port",
"time": 1711710000,
"datacontenttype": "application/json",
"data": {
"event_id": "ea7f581ec36dd92a927cf8eb645c62d8",
"customer_name": "NXG-123456-TEST",
"host": "vm71",
"idc": "spe_nxg_pop",
"start_time": 1779456697,
"message": "Ethernet Port Up Event | Ethernet Port Down Event | LAG Port Healthy Event | ...",
"item_name": "eth0",
"item_show_key": "Ethernet Port | LAG Port",
"item_status": "Up | Down | Join | Leave | Healthy",
"item_key": "ethernetPort",
"is_bond": "0 | 1",
"port_type": "static | lacp",
"reason": "link_up | link_down | join | leave | lacp_up | lacp_down",
"item_group": [
{
"item_status": "Down | Up | Join | Leave | Healthy",
"start_time": 1779456600
}
]
}
}
3. Other Incoming Webhook Payload Structures (chat room)
This section describes the HTTP POST JSON structures expected by each third-party messaging / collaboration platform when delivering Incoming Webhook messages.
These payloads differ from the generic CloudEvents-style notification schema in sections 1 and 2. The Notifier / integration layer typically maps an internal event into the target platform format, then POSTs it to the webhook URL provided by that platform.
Platform
Content-Type
Notes
Google Chat
application/json; charset=UTF-8
Supports plain text or cardsV2
Slack
application/json
Supports text, Block Kit, and attachments
Zoom Chat
application/json
Primarily message / content
Discord
application/json
Supports content and embeds
Feishu (Lark)
application/json
Message type is selected with msg_type
Microsoft Teams
application/json
Classic MessageCard or Adaptive Card
3.1 Google Chat
Google Chat Incoming Webhooks accept Chat Message objects. The simplest form is plain text; use cardsV2 for rich layouts.
Fields (text message)
Field
Type
Description
text
string
Plain / basic-formatted message body shown in the space.
thread
object
Optional. Threading info when replying in an existing thread.
thread.threadKey
string
Client-defined thread key. Requires messageReplyOption query param on the webhook URL for reply behavior.
cardsV2
array of object
Optional. Rich card layout. Prefer this over legacy cards.
Example (text)
{
"text": "AP DDoS attack alert [NXG-123456-TEST / EVENT-EF54F79D52439CDA8AD8E7FF5C]"
}
Example (cardsV2)
{
"text": "AP DDoS attack alert",
"cardsV2": [
{
"cardId": "ap-ddos-alert",
"card": {
"header": {
"title": "AP DDoS attack alert",
"subtitle": "NXG-123456-TEST"
},
"sections": [
{
"widgets": [
{
"decoratedText": {
"topLabel": "Event ID",
"text": "EVENT-EF54F79D52439CDA8AD8E7FF5C"
}
},
{
"decoratedText": {
"topLabel": "Target",
"text": "192.168.0.1"
}
},
{
"buttonList": {
"buttons": [
{
"text": "Open Event",
"onClick": {
"openLink": {
"url": "https://customer.example.com/#/customer/1/ap/dashboard/site/73/ddos"
}
}
}
]
}
}
]
}
]
}
}
]
}
3.2 Slack
Slack Incoming Webhooks accept message JSON. You can send plain text, or use Block Kit (blocks) to build structured messages.
Fields
Field
Type
Description
text
string
Fallback / notification text. Also used when blocks is absent.
blocks
array of object
Optional. Block Kit layout blocks (section, divider, actions, etc.).
attachments
array of object
Optional. Legacy attachment cards. Prefer blocks for new integrations.
username
string
Optional. Override the webhook bot display name (if allowed by workspace settings).
icon_emoji
string
Optional. Emoji icon override (e.g. :warning:).
icon_url
string
Optional. Image URL for the bot icon.
channel
string
Optional. Override destination channel (often disabled for modern Incoming Webhooks).
Example (text)
{
"text": "AP DDoS attack alert [NXG-123456-TEST / EVENT-EF54F79D52439CDA8AD8E7FF5C]"
}
Example (Block Kit)
{
"text": "AP DDoS attack alert [NXG-123456-TEST / EVENT-EF54F79D52439CDA8AD8E7FF5C]",
"blocks": [
{
"type": "header",
"text": {
"type": "plain_text",
"text": "AP DDoS attack alert"
}
},
{
"type": "section",
"fields": [
{
"type": "mrkdwn",
"text": "*Customer:*\nNXG-123456-TEST"
},
{
"type": "mrkdwn",
"text": "*Target:*\n192.168.0.1"
},
{
"type": "mrkdwn",
"text": "*Severity:*\nHigh"
},
{
"type": "mrkdwn",
"text": "*Status:*\nOngoing"
}
]
},
{
"type": "actions",
"elements": [
{
"type": "button",
"text": {
"type": "plain_text",
"text": "More Details"
},
"url": "https://customer.example.com/#/customer/1/ap/dashboard/site/73/ddos"
}
]
}
]
}
3.3 Zoom Chat
Zoom Team Chat Incoming Webhooks deliver messages to a specified channel. The simplest payload uses message; you can also send structured content.
Fields (simple)
Field
Type
Description
message
string
Message body posted to the Zoom Chat channel.
Fields (structured content)
Field
Type
Description
content
object
Structured message envelope.
content.head
object
Optional. Message header.
content.head.text
string
Header title text.
content.body
array of object
Message body widgets / segments.
content.body[].type
string
Segment type (e.g. message).
content.body[].text
string
Segment text content.
Example (simple)
{
"message": "AP DDoS attack alert [NXG-123456-TEST / EVENT-EF54F79D52439CDA8AD8E7FF5C]"
}
Example (structured)
{
"content": {
"head": {
"text": "AP DDoS attack alert"
},
"body": [
{
"type": "message",
"text": "Customer: NXG-123456-TEST\nTarget: 192.168.0.1\nSeverity: High\nStatus: Ongoing"
}
]
}
}
3.4 Discord
Discord Incoming Webhooks send messages to a channel. They support plain-text content and one or more embeds.
Fields
Field
Type
Description
content
string
Message text content (plain / Discord markdown). Max length limited by Discord.
username
string
Optional. Override webhook display name for this message.
avatar_url
string
Optional. Override webhook avatar URL for this message.
tts
boolean
Optional. Whether to send as text-to-speech. Default false.
embeds
array of object
Optional. Rich embed objects.
embeds[].title
string
Embed title.
embeds[].description
string
Embed body text.
embeds[].url
string
Optional. URL opened when the title is clicked.
embeds[].color
integer
Optional. Sidebar color as decimal integer.
embeds[].fields
array of object
Optional. Named fields shown in the embed.
embeds[].fields[].name
string
Field name.
embeds[].fields[].value
string
Field value.
embeds[].fields[].inline
boolean
Whether to display the field inline.
allowed_mentions
object
Optional. Controls which mentions are parsed.
Example (text)
{
"content": "AP DDoS attack alert [NXG-123456-TEST / EVENT-EF54F79D52439CDA8AD8E7FF5C]"
}
Example (embed)
{
"username": "NXG Notifier",
"content": "AP DDoS attack alert",
"embeds": [
{
"title": "AP DDoS attack alert",
"description": "High severity attack detected",
"url": "https://customer.example.com/#/customer/1/ap/dashboard/site/73/ddos",
"color": 15158332,
"fields": [
{
"name": "Customer",
"value": "NXG-123456-TEST",
"inline": true
},
{
"name": "Target",
"value": "192.168.0.1",
"inline": true
},
{
"name": "Severity",
"value": "High",
"inline": true
},
{
"name": "Status",
"value": "Ongoing",
"inline": true
}
]
}
]
}
3.5 Feishu (Lark)
Feishu / Lark custom-bot Incoming Webhooks select the message type with msg_type. Common types are text, post, and interactive (card).
Fields (text)
Field
Type
Description
msg_type
string
Message type. For plain text use "text".
content
object
Message content object. Shape depends on msg_type.
content.text
string
Text body when msg_type is "text".
Fields (interactive card)
Field
Type
Description
msg_type
string
Use "interactive" for card messages.
card
object
Card definition (header, elements, actions).
Example (text)
{
"msg_type": "text",
"content": {
"text": "AP DDoS attack alert [NXG-123456-TEST / EVENT-EF54F79D52439CDA8AD8E7FF5C]"
}
}
Example (interactive card)
{
"msg_type": "interactive",
"card": {
"header": {
"title": {
"tag": "plain_text",
"content": "AP DDoS attack alert"
},
"template": "red"
},
"elements": [
{
"tag": "div",
"text": {
"tag": "lark_md",
"content": "**Customer:** NXG-123456-TEST\n**Target:** 192.168.0.1\n**Severity:** High\n**Status:** Ongoing"
}
},
{
"tag": "action",
"actions": [
{
"tag": "button",
"text": {
"tag": "plain_text",
"content": "Open Event"
},
"type": "primary",
"url": "https://customer.example.com/#/customer/1/ap/dashboard/site/73/ddos"
}
]
}
]
}
}
3.6 Microsoft Teams
Microsoft Teams Incoming Webhooks (Office 365 Connector / Workflows) commonly use two formats:
MessageCard (classic Incoming Webhook)
Adaptive Card (recommended for Workflows / Bot scenarios)
Fields (MessageCard)
Field
Type
Description
@type
string
Always "MessageCard".
@context
string
Always "https://schema.org/extensions" (or http://schema.org/extensions).
summary
string
Short summary used in notifications / accessibility.
themeColor
string
Hex color without # (e.g. "FF0000").
title
string
Card title.
text
string
Optional. Main body text.
sections
array of object
Optional. Content sections with facts / text.
sections[].activityTitle
string
Section title.
sections[].facts
array of object
Key/value facts displayed as a list.
sections[].facts[].name
string
Fact label.
sections[].facts[].value
string
Fact value.
potentialAction
array of object
Optional. Action buttons (e.g. OpenUri).
Example (MessageCard)
{
"@type": "MessageCard",
"@context": "https://schema.org/extensions",
"summary": "AP DDoS attack alert",
"themeColor": "FF0000",
"title": "AP DDoS attack alert",
"sections": [
{
"activityTitle": "NXG-123456-TEST",
"facts": [
{
"name": "Event ID",
"value": "EVENT-EF54F79D52439CDA8AD8E7FF5C"
},
{
"name": "Target",
"value": "192.168.0.1"
},
{
"name": "Severity",
"value": "High"
},
{
"name": "Status",
"value": "Ongoing"
}
]
}
],
"potentialAction": [
{
"@type": "OpenUri",
"name": "Open Event",
"targets": [
{
"os": "default",
"uri": "https://customer.example.com/#/customer/1/ap/dashboard/site/73/ddos"
}
]
}
]
}
Example (Adaptive Card wrapper for Workflows)
{
"type": "message",
"attachments": [
{
"contentType": "application/vnd.microsoft.card.adaptive",
"contentUrl": null,
"content": {
"$schema": "http://adaptivecards.io/schemas/adaptive-card.json",
"type": "AdaptiveCard",
"version": "1.4",
"body": [
{
"type": "TextBlock",
"size": "Medium",
"weight": "Bolder",
"text": "AP DDoS attack alert"
},
{
"type": "FactSet",
"facts": [
{
"title": "Customer",
"value": "NXG-123456-TEST"
},
{
"title": "Target",
"value": "192.168.0.1"
},
{
"title": "Severity",
"value": "High"
},
{
"title": "Status",
"value": "Ongoing"
}
]
}
],
"actions": [
{
"type": "Action.OpenUrl",
"title": "Open Event",
"url": "https://customer.example.com/#/customer/1/ap/dashboard/site/73/ddos"
}
]
}
}
]
}
Notes for consumers
Parse by type: For generic notifications (sections 1–2), always branch on the top-level type field before interpreting data.
Idempotency : Use top-level id (delivery ID) and/or data.event_id to avoid duplicate processing.
Timestamps : time, start_time, and end_time are Unix epoch seconds unless otherwise noted.
Optional fields : Fields may be omitted or empty when not applicable (e.g. end_time / duration while an event is still ongoing).
Content type : For generic notifications, datacontenttype is always application/json; the HTTP body is a single JSON object matching this document.
Platform webhooks : When delivering to third-party chat platforms (section 3), map the generic notification into the target platform payload and POST it to that platform’s Incoming Webhook URL with Content-Type: application/json.