Opsgenie Integration with DefectDojo
Opsgenie Integration with DefectDojo
Opsgenie is Atlassian's alerting and on-call management service. It receives alerts from monitoring and other systems, routes them to teams according to on-call schedules, routing rules, and escalation policies, and tracks each alert through open, acknowledged, and closed. Atlassian is folding Opsgenie into Jira Service Management Operations, and the DefectDojo connector supports both the Opsgenie API and the JSM Operations integration endpoint.
Opsgenie Integration with DefectDojo
Most security findings belong in a backlog, but a few need a human now: an exposed service with a known exploited vulnerability, a leaked credential, a Critical on an internet-facing Asset. We use the Opsgenie Downstream Connector in DefectDojo Pro for exactly those. DefectDojo pushes the selected Findings or Finding Groups to Opsgenie as alerts, maps severity to Opsgenie priority, and can name a responder team, so the on-call rotation that already handles production incidents sees security emergencies the same way. Alerts update as the Finding changes, and re-pushing the same Finding updates the open alert instead of paging twice.
Why Opsgenie Matters
Ticket queues are the right place for planned remediation. They are the wrong place for something that should wake someone up.
- Opsgenie already knows who is on call, how to reach them, and when to escalate, which is work a security team should not rebuild.
- Its P1 to P5 priority scale is understood by the operations teams who respond to alerts.
- Routing rules and team-scoped integration keys decide responders inside Opsgenie, so the security team does not maintain a separate contact list.
- Without an integration, urgent findings depend on someone noticing them and sending a chat message, which fails exactly when it matters, outside business hours.
Advantages of This Integration
What changes when DefectDojo raises the alerts:
- Only findings that deserve a page. Push filters on an assignment can restrict automatic alert creation to a minimum severity and to active Findings, so Opsgenie never sees false positives or low findings unless someone pushes them manually.
- Severity becomes priority. The default mapping sends Critical as P1, High as P2, Medium as P3, Low as P4, and Info as P5.
- No duplicate alerts. DefectDojo sets each alert's alias to a stable key derived from the Finding or Finding Group. Opsgenie de-duplicates open alerts by alias, so a re-push updates the existing alert.
- Content stays current. Opsgenie allows edits after creation, so pushing an updated Finding syncs the alert's message, description, and priority along with its status.
- Status follows the Finding. Active maps to open, Closed and False Positive map to closed, and Risk Accepted maps to acknowledged.
- Finding Groups as one alert. Grouping related findings and pushing the group raises a single alert instead of a burst of them.
How This Integration Works
Downstream Connectors are part of DefectDojo Pro and are generally available on Cloud and On-Premise instances. Community Edition's issue tracking integration covers Jira only and has no Opsgenie connector.
Configuration has three layers. The Integration Instance holds the connection, an Issue Tracker Mapping holds the destination and field mappings, and Issue Tracker Assignments attach Assets or Engagements to a mapping. Start from Connect > Downstream in the Pro UI.
1. Create an API integration key in Opsgenie. An account administrator adds an integration of type API under Settings > Integrations, with Create and Update Access, plus Read Access so DefectDojo can verify the connection. This must be an integration key, not a personal API key, because DefectDojo authenticates with GenieKey authorization, which only integration keys support.
2. Create the Integration Instance.
- Label: a name for this integration.
- Location:
https://api.opsgenie.com, orhttps://api.eu.opsgenie.comfor the EU service region. If your alerts live in Jira Service Management Operations, usehttps://api.atlassian.com/jsm/ops/integration. - API Key: the API integration key.
3. Create an Issue Tracker Mapping. Team Name is optional. Set it to an Opsgenie team to add that team as a responder on created alerts. If you leave it empty, a team-scoped integration key routes alerts to its team automatically, and otherwise your account's routing rules decide.
4. Review severity and status mappings. The Severity Field Name is Priority and the Status Field Name is Status, with the defaults listed below. A severity mapped to an unrecognized value omits the priority, and Opsgenie applies its default of P3.
5. Assign Assets or Engagements. For each Asset or Engagement, choose a push behavior: explicit pushes only, automatically link new Findings, automatically update existing links on edit, or both. Add push filters as needed.
Data Granularity: What Gets Sent
| Opsgenie Field | Source in DefectDojo | Notes |
|---|---|---|
| Alert | Finding or Finding Group | Created by Push to Integrator or an automatic assignment |
| Alias | Stable key from the Finding or Finding Group | Opsgenie de-duplicates open alerts on it |
| Message and description | Finding content | Synced again when an updated Finding is pushed |
| Priority | Severity | Critical P1, High P2, Medium P3, Low P4, Info P5 |
| Status | Finding status | Active open, Closed closed, False Positive closed |
| Acknowledged | Risk Accepted | Marks the open alert as acknowledged |
| Responders | Team Name, key scope, or routing rules | Team Name is optional |
| Link back | Integrator Tickets column | Integration type, alert ID, link, and changelog |
Closed is final in Opsgenie. A closed alert cannot be reopened and its alias is released, so reactivating a Finding in DefectDojo will not bring its old alert back to open.
Use Cases
Paging on exposed Criticals: An assignment on internet-facing Assets automatically links new Findings, filtered to Critical and active only. When a scanner or connector reports a new Critical on one of those Assets, a P1 alert reaches the security on-call rotation within the same flow as production incidents.
Escalating a group, not a flood: A new vulnerability affects dozens of hosts. Grouping those findings and pushing the Finding Group raises one alert that responders can acknowledge, instead of dozens of separate pages.
Signalling accepted risk: When the team risk-accepts a Finding after review, the alert moves to acknowledged rather than closed, so operations can see that the issue is known and owned but not fixed.
Migrating to JSM Operations: Teams moving from standalone Opsgenie to Jira Service Management Operations change the Location to the JSM Operations endpoint and keep the same mappings and assignments.
Operational Tips
- Create the API integration with Read Access as well as Create and Update. Without it, DefectDojo cannot verify the connection.
- Use a team-scoped integration key if all security alerts belong to one team. It removes the need to set Team Name and keeps routing inside Opsgenie.
- Keep automatic creation narrow. Alerts interrupt people, so pair automatic linking with a Minimum Severity of High or Critical and Active findings only.
- Push filters only gate creation. Updates and closures for alerts that already exist are always sent.
- Remember that closing is permanent in Opsgenie. Map False Positive to closed only if you are sure those alerts never need to come back, and use Risk Accepted (acknowledged) for findings that stay open.
- Check the Total Errors column on the All Issue Tracker Mappings & Assignments page after rotating keys, and use Diagnostics to look at failures across all integrations at once.