# Integration of IQ Webhook with Fortify SSC Sync Service

The Fortify SSC synchronization service supports data synchronization with the IQ server in two ways:

1. Scheduled polling (cron jobs) using the Synchronization Scheduler
   
   Refer to details on [Synchronization Scheduler](https://help.sonatype.com/en/sonatype-fortify-ssc.html#synchronization-scheduler).

2. Using IQ webhooks

The following sections describe the integration of Fortify SSC Sync service with IQ webhook event.

## Data Flow Using IQ Webhook Events

All application evaluations are sent to the Fortify SSC synchronization services. However, only those applications that are in the mapping file are processed.

Similar to the [Synchronization Scheduler](https://help.sonatype.com/en/sonatype-fortify-ssc.html#synchronization-scheduler), continuous monitoring results are synchronized only if there is a change in the data or violation.

## Steps to Integrate IQ Webhook with Fortify SSC Sync Service

1. **Turn "off" Fortify SSC Sync Service and Update Continuous Configuration**  
   Turn off the synchronization service and set the `synchronize.projects.continously` property in the iqapplication.properties file to `false`. This will turn off polling and free system resources to process webhook events.
   
   **NOTE:** It is possible for the sync service to poll as well as process webhook events, provided that the cron jobs are scheduled infrequently and there are fewer webhook events.

2. **Turn "on" Fortify Sync Service and Configure IQ Webhook Event**.
   1. Turn on the synchronization service.
   2. Login to _Lifecycle_ as an _admin_ user or a user with system configuration permissions.
   3. Navigate to the WebHooks configuration in the _System Preferences_ menu.
   
      
   4. Click on _Add a Webhook_ button.
   
      
   5. On the _Webhook Details_ page, set the Website URL field to point to the address of the Fortify SSC synchronization service with the endpoint set to `/iqWebhook`
      
      E.g. `http://<sync-service-address>:<sync-service-port>/iqWebhook`
      
      For _Event Types_, check the _Application Evaluation_ checkbox and click on the _Create_ button.
   
      
3. **Test the Webhook Integration**
   If the Webhook has been created successfully, you should now be able to evaluate the applications that exist in your mapping file and confirm that they are being sent to the synchronization service.
   1. Select an evaluation report stage for an application that exists in your mapping file on the Lifecycle _Reports_ page.
   
      
   2. Click on the _Re-Evaluate Report_ button.

On completion of the re-evaluation, a webhook event will be pushed to the synchronization service.
   3. Check the synchronization service log or console output to confirm that the webhook event was received and processed.
