Focus
Strata Cloud Manager

Incident Integrations

Table of Contents

Incident Integrations

Learn how incident integrations in Strata Cloud Manager to deliver real-time incident alerts to your external operations platforms.
Where Can I Use This?What Do I Need?
Strata Cloud Manager uses integrations to synchronize incidents with your external tool set, such as operational management and ticketing platforms, for example, PagerDuty for on-call alerting. Built on outbound webhook infrastructure, incident integrations automatically transform internal data structures into the exact payload format required by your destination systems without requiring custom middleware.
When an incident occurs, Strata Cloud Manager compiles your field mappings into transformation rules and applies them automatically at event time. You can describe what your destination tool expects to receive by pasting a sample payload, or entering fields manually in a notification profile and then map each destination field to an incident field from Strata Cloud Manager or to a static value you specify.
Incident integrations handle the complete incident lifecycle automatically:
  • Incident raise events: When Strata Cloud Manager raises an incident, it formats and sends the payload to your destination tool according to your transformation rules.
  • Incident resolve events: When an incident clears, Strata Cloud Manager sends a corresponding resolve payload. It matches the resolve event to the original raise event using the reference identifier returned by the destination system, eliminating manual tracking.
    Enable Include Associated Events in a notification profile to get all updates related to an incident.
External integrations and webhooks operate as independent channels. Both or either can be configured within a single notification profile, and external integrations do not serve as a replacement for webhooks.
To configure an integration, define the destination schema and perform a test to verify the payload structure in the notification profile. Strata Cloud Manager then manages payload delivery for both raise and clear events automatically. The Notification Profiles page includes the Integrations column to indicate whether the integration has been set up (which can be in one of three states: not set up, partially set up/draft, or fully set up), but it is not an indication of delivery success or failure.

Configure Integration for Incidents

Use the following steps to create and activate an integration in Strata Cloud Manager.
  1. Select IncidentsIncidentsNotification Profiles.
  2. Click + Create Notification Profile.
  3. Enter a Profile Name.
  4. Select Integration and enter the Integration Name.
  5. Enter the URL of your external tool set.
  6. Choose an Auth Type:
    • None
    • Basic: Enter a username and password.
    • Bearer token: Enter the token value.
  7. (Optional) In the Webhook Signing Secret field, Generate Secret. Strata Cloud Manager generates a cryptographic signing secret and displays it in cleartext. If a secret already exists, the field displays a masked value. See Create Notification Profiles for Incidents.
  8. Enable Include Associated Events to get all updates related to an incident excluding the initial trigger and resolution. See Associated Events Email Notifications.
  9. Under Field mapping, you have two options:
    • Import from JSON
      Copy an example JSON payload from the destination tool's developer documentation and paste it here. Strata Cloud Manager parses the fields, infers their types, and builds the field list automatically.
    • Add manually
      Choose a source Strata Cloud Manager field and enter the corresponding destination field. Add fields based on your requirements.
    Make sure that all the fields are mapped.
  10. Under Test & Activate, click Preview Payload to review the exact JSON that Strata Cloud Manager would send, using a synthetic incident. All mapping rules and static values are applied. No network call is made at this step.
  11. When the payload looks correct, Send Test. Strata Cloud Manager creates a synthetic incident, applies the compiled mapping rules, sends the payload to the destination URL, and displays the result.
  12. Click Save Profile. You can save your profile at any time to preserve your progress as a draft and finish configuring it later. If all required fields and mappings are fully configured, the integration becomes Active; otherwise, it remains saved in a Draft state until configuration is complete.

Example: PagerDuty Integration

The incident integration framework in Strata Cloud Manager is designed for payload customization across multiple downstream tools. PagerDuty is one example of a supported destination. The same approach applies to any external operations platform that accepts webhook payloads.
PagerDuty Events API v2 requires the following fields in every trigger event payload. If any of these fields are missing or contain invalid values, PagerDuty rejects the API call:
  • routing_key: The integration key from your PagerDuty service or global event orchestration rule. Enter this as a static custom field value in the Strata Cloud Manager notification profile.
  • event_action: The action to perform. For raise events from Strata Cloud Manager, always set this to the static value trigger. The resolve lifecycle is handled by a PagerDuty event orchestration rule, not by changing this value in Strata Cloud Manager. See Resolve Lifecycle below.
  • payload.summary: A human-readable description of the event. Map this to the Strata Cloud Manager field title.
  • payload.source: The source of the event. Map this to the Strata Cloud Manager field details_link to link directly to the Strata Cloud Manager incident detail page.
  • payload.severity: The severity of the event. Must be one of the following exact values (case-sensitive): critical, warning, error, or info. You need to set this as a static custom field value.
Configure the following field mappings in your Strata Cloud Manager notification profile. The following table reflects a complete 12-field mapping. Source fields are from Strata Cloud Manager; destination fields use PagerDuty's dot-notation paths.
Strata Cloud Manager Notification Profile — PagerDuty Field Mapping
PagerDuty FieldStrata Cloud Manager Source ValueSource TypeNotes
routing_keyYour PagerDuty routing keyCustom Field (static)Required. Enter your PagerDuty integration key as a static value.
event_actiontriggerCustom Field (static)Required. Always set to trigger in Strata Cloud Manager. Resolve behavior is controlled by a PagerDuty event orchestration rule.
dedup_keyincident_idStrata Cloud Manager fieldRecommended. Links trigger and resolve events for the same incident, preventing duplicate PagerDuty alerts.
clienttenant_service_groupStrata Cloud Manager fieldIdentifies the source tenant in PagerDuty.
payload.summarytitleStrata Cloud Manager fieldRequired. Appears as the alert title in PagerDuty.
payload.sourcedetails_linkStrata Cloud Manager fieldRequired. Links to the Strata Cloud Manager incident detail page.
payload.severitycriticalCustom Field (static)Required. In this example, set as a static value.
payload.custom_details.titletitleStrata Cloud Manager fieldPasses the incident title as additional context in PagerDuty.
payload.custom_details.statusstatusStrata Cloud Manager fieldUsed by the PagerDuty event orchestration rule to detect when Strata Cloud Manager clears an incident and automatically resolve the PagerDuty alert.
payload.custom_details.tenanttenant_idStrata Cloud Manager field
payload.custom_details.incident_idincident_idStrata Cloud Manager field
payload.custom_details.raised_timeraised_timeStrata Cloud Manager field
PagerDuty enforces exact string matching for event_action and payload.severity. All values are case-sensitive. Payloads that use incorrect casing or values outside the accepted enums are rejected by the PagerDuty API.
If you want to dynamically map Strata Cloud Manager severity levels to PagerDuty-accepted values, use a PagerDuty event orchestration rule. The following mapping is recommended:
Strata Cloud Manager SeverityPagerDuty Severity
Criticalcritical
Higherror
Medium/Lowwarning
Informationalinfo

Resolve Lifecycle for PagerDuty

Strata Cloud Manager always sends event_action: trigger as a static value in the notification profile. To handle the resolve lifecycle, Strata Cloud Manager maps its status field to payload.custom_details.status in the payload. When a Strata Cloud Manager incident clears, it sends a payload with payload.custom_details.status: Cleared. You configure an event orchestration rule in PagerDuty to detect this value and automatically resolve the corresponding alert.
Configure the following event orchestration rule in PagerDuty:
  1. In PagerDuty, navigate to your service's Event Orchestration rules and create a new rule.
  2. In Step 1: When should this rule be applied?, set the condition to: event.custom_details.status matches Cleared.
    PagerDuty Event Orchestration Rule — Step 1 (Condition)
  3. In Step 2: What action(s) should be applied?, under Alert Data, select Always resolve an alert. Optionally, set the alert severity to info for cleared events.
    PagerDuty Event Orchestration Rule — Step 2 (Alert Behavior)
  4. Save the rule. PagerDuty automatically resolves any open alert whose dedup_key matches an incoming event where event.custom_details.status is Cleared.

Sample Payloads

The following is the test payload that Strata Cloud Manager sends when you click Send Test in the notification profile. All field values use a test_ prefix and do not represent real incident data:
{ "routing_key": "<your-pagerduty-routing-key>", "event_action": "trigger", "dedup_key": "test_incident_id", "client": "test_tenant_service_group", "payload": { "summary": "Test Integration", "severity": "critical", "source": "test_details_link", "custom_details": { "title": "Test Integration", "status": "test_status", "tenant": "test_tenant_id", "incident_id": "test_incident_id", "raised_time": "2026-09-22 16:33:46.553000 UTC" } } }
The following is an example of the payload that Strata Cloud Manager sends when a real incident is raised:
{ "routing_key": "<your-pagerduty-routing-key>", "event_action": "trigger", "dedup_key": "74a58d3b-76de-44e8-9060-example", "client": "xxxxxxxx", "payload": { "summary": "ADEM/GP Log Certificate (globalprotect_app_log_cert) to expire on 2026-06-06", "severity": "critical", "source": "https://stratacloudmanager.paloaltonetworks.com/incidents/details/74a58d3b-76de-44e8-9060-example", "custom_details": { "title": "ADEM/GP Log Certificate (globalprotect_app_log_cert) to expire on 2026-06-06", "status": "Raised", "tenant": "xxxxxxx", "incident_id": "74a58d3b-76de-44e8-9060-76dfec5c8407", "raised_time": "2026-09-22T16:46:16.731068Z" } } }
The following screenshot shows the Strata Cloud Manager incident that triggered the PagerDuty alert. The activity log confirms that the external adapter notification was sent to the notification profile:
Strata Cloud Manager Incident Detail — Notification Sent to PagerDuty
The following screenshot shows the alert successfully received in PagerDuty, with the dedup_key mapped to the Strata Cloud Manager incident ID and custom details visible in the alert view:
PagerDuty Alert — Triggered with Custom Details
The following screenshot shows the resulting open incident in PagerDuty:
PagerDuty Open Incidents — Incident Raised from Strata Cloud Manager