Zendesk Integration with DefectDojo
Zendesk Integration with DefectDojo
Zendesk is a customer service and help desk platform from Zendesk, Inc. Teams use it to receive, assign, and resolve requests as tickets, which are routed to Groups of agents and carry a priority and a status. Many organizations also run internal IT or operations support in Zendesk. Zendesk provides a REST API with token-based access for agents, which is how DefectDojo Pro creates and updates tickets.
Zendesk Integration with DefectDojo
We connected Zendesk to DefectDojo Pro because the team that handles a big share of our remediation already lives in a Zendesk queue, and asking them to watch a second tool did not work. The Downstream Connector pushes a Finding or a Finding Group to Zendesk as a ticket assigned to the Group we choose. DefectDojo severity sets the ticket Priority, and the Finding's status sets the ticket status, so a mitigated Finding solves its ticket. Security keeps deduplication, SLAs, and reporting in DefectDojo, and the agents who make the fix see the work in the view they open every morning.
Why Zendesk Matters
Not every fix belongs in an engineering backlog. Some belong with a support or operations team whose work is already measured in tickets.
- Zendesk Groups route work to the agents responsible for it, so a ticket from DefectDojo reaches someone who owns that kind of change.
- Priority and status drive Zendesk views and SLA policies, so security tickets are sorted and tracked with everything else.
- Agents already know how to work, comment on, and solve tickets. There is nothing new to learn.
- Forwarding findings by email leaves no record of who picked them up, and nobody closes the loop when the finding is retested.
Advantages of This Integration
What we gained by pushing DefectDojo findings to Zendesk:
- Tickets assigned to a Group. Each Issue Tracker Mapping names a Zendesk Group, so different Assets can send tickets to different teams.
- Severity as Priority. DefectDojo's five severities map onto Zendesk's four priorities, with Critical defaulting to urgent.
- Status that follows the Finding. Active, Closed, False Positive, and Risk Accepted each map to a Zendesk status.
- One ticket per fix. Finding Groups can be pushed as a single ticket when one change resolves several Findings.
- Automatic or explicit pushes. An Issue Tracker Assignment can create tickets for new Findings automatically, update linked tickets when Findings change, do both, or leave every push to a person.
- Only what matters gets pushed. Push filters limit automatic creation to a minimum severity and to active Findings.
- Visible errors. Each Issue Tracker Mapping keeps a table of failed pushes with the time, reason, and Finding.
How This Integration Works
Zendesk is a DefectDojo Pro Downstream Connector, configured under Connect > Downstream. It is not part of Community Edition, where the documented issue-tracking integration is Jira.
1. Create an API token. A Zendesk administrator creates a token in the Admin Center under Apps and integrations > APIs > Zendesk API. Token access must be enabled there.
2. Create the Integration Instance. Add Zendesk and enter:
- Label: a name for this integration.
- Location: your Zendesk account URL, for example
https://your-subdomain.zendesk.com. - Email: the email address of the Zendesk agent the API token belongs to.
- API Token: the token from step 1.
3. Create an Issue Tracker Mapping. Set Group ID to the numeric ID of the Zendesk Group that tickets should be assigned to. Find it in the Admin Center under People > Team > Groups, or in the URL while viewing the group. Review the severity and status mappings.
4. Assign Assets or Engagements. An Issue Tracker Assignment links an Asset or Engagement to the Mapping and picks the push mode. Create one Assignment per Asset or Engagement, and a separate Mapping when another Group should own an Asset's tickets.
5. Push. Findings and Finding Groups in an assigned Asset or Engagement get a Push to Integrator action. Automatic pushes follow the Assignment, and DefectDojo Pro rules can push through the Triage Engine Create a Downstream Ticket node.
Data Granularity: What Gets Sent
| Zendesk Field | Source in DefectDojo | Notes |
|---|---|---|
| Ticket | Finding or Finding Group | One ticket per pushed object |
| Subject | Finding or Finding Group | Synced on later pushes |
| Description | Finding details at creation | Becomes the first comment and cannot be edited later |
| Group | Group ID on the Issue Tracker Mapping | Numeric Zendesk Group ID |
| Priority | Finding severity | Defaults: Info low, Low low, Medium normal, High high, Critical urgent |
| Status | Finding status | Defaults: Active new, Closed solved, False Positive solved, Risk Accepted pending |
| Removal | Finding deleted | Ticket is marked solved, not deleted |
| Ticket link | Zendesk ticket | Shown in the Integrator Tickets column with ID, link, and changelog |
Zendesk statuses are new, open, pending, hold, solved, and closed. The hold status must be enabled on your account before you can map to it.
Use Cases
IT support fixing endpoint findings: Findings on workstation and SaaS Assets are pushed automatically to the IT support Group. Agents work them as normal tickets, and the tickets are solved when DefectDojo mitigates the Finding.
One ticket for a fleet-wide change: Findings grouped by component become a Finding Group, so the operations Group gets one ticket to roll out a configuration change rather than one per host.
Risk acceptance that agents can see: When security accepts a risk, the linked ticket moves to pending by default, which tells the agent the work is paused rather than abandoned.
Separate queues per team: Two Mappings with different Group IDs let infrastructure findings and application support findings reach different Groups from the same Zendesk account.
Operational Tips
- Remember that the description is frozen at creation. Later pushes sync the subject, priority, and status, so finish editing a Finding's description before it is first pushed, especially for manual pushes of pentest results.
- Watch for tickets that reach
closed. Closed is final in Zendesk, and pushing a Finding whose ticket has closed reports an error. Zendesk closes solved tickets automatically after a period of time. - Map Risk Accepted to
holdinstead ofpendingif your account uses hold for paused work, after enabling it. - Use a token tied to an agent account created for DefectDojo, so ticket activity is easy to attribute.
- Set a minimum severity and the active-only filter on automatic Assignments. Updates to linked tickets are always sent, so status changes still reach Zendesk.
- Review the Mapping's error table after setup. Token, Group ID, and closed-ticket errors appear there.