Configure Slack Webhook Connector
You can configure a webhook connector in the Alert Logic console to send notifications to Slack in near real time. When you set up a notification and subscribe a webhook connector, the connector sends the event to the target URL you configured and creates a message in Slack automatically.
Alert Logic notifications alert you to threats, changes, and scheduled events in your environment so you can respond quickly. From the Alert Logic console, you can subscribe your Slack webhook to receive:
- Incident notifications—Send a message when incidents occur that meet specific criteria, such as escalated incidents.
- Log correlation notifications—Send a message when your log correlation rules trigger an incident or observation.
- Scheduled report notifications—Send a message when Alert Logic generates a scheduled report that is available for download.
Complete the following steps to successfully send messages to Slack:
- Generate the target URL
- (Optional) Customize the payload template
- Create the Slack webhook connector from the Alert Logic console
- Subscribe your webhook to receive notifications
Generate the target URL
Before you create the webhook connector in the Alert Logic console, complete the instructions in the Slack documentation to generate the incoming webhook URL. Copy the URL, which you must paste into the Target URL field.
(Optional) Customize the payload template
Decide which type of security information that you want Alert Logic to send to Slack: Incident, Observation (of a log correlation), or a Scheduled Report Notification payload.
Alert Logic provides a payload template for an incident and an observation in JSON format using Mustache template-like transformations where a field in the JSON payload can be referenced by enclosing it in braces ({{}}. For example, the threatRating field in the following JSON {'incident': {'threat.Rating': "critical"}} is specified as {{incident.threatRating}}. A payload template converts the Alert Logic security information to the format expected by Slack. You can add or remove lines in the sample template to meet your workflow requirements and security goals. If you want to create a Slack connector for scheduled report notifications, you will need to configure the payload template.
For definitions of the Alert Logic variables in the templates and the full JSON that you can use to configure your payload template in JQ or JSON format, see:
Incident payload template
JSON Template
{
"text": "{{incident.summary}}",
"blocks": [{
"type": "section",
"text": {
"text": "{{incident.summary}}",
"type": "plain_text"
}
}, {
"type": "section",
"text": {
"text": "{{desc}}",
"type": "mrkdwn"
}
}, {
"type": "section",
"text": {
"text": "{{incident.recommendations}}",
"type": "mrkdwn"
}
}]
}
Observation payload template
JSON Template
{
"text": "{{fields.summary}}",
"blocks": [{
"type": "section",
"text": {
"text": "*Summary:* {{fields.summary}}",
"type": "mrkdwn"
}
}, {
"type": "divider",
"block_id": "divider1"
}, {
"type": "section",
"text": {
"text": "*Description:* {{fields.desc}}",
" type": "mrkdwn"
}
}, {
"type": "divider",
"block_id": "divider2"
}, {
"type": "section",
"text": {
"text": "*Recommendations:* {{fields.recommendations}}",
"type": "mrkdwn"
}
}, {
"type": "divider",
"block_id": "divider3"
}, {
"type": "section",
"text": {
"text": "*Details*",
"type": "mrkdwn"
},
"fields": [{
"text": "*Customer ID:*",
"type": "mrkdwn"
}, {
"type": "plain_text",
"text": "{{id.account}}"
}, {
"type": "mrkdwn",
"text": "*Class:*"
}, {
"type": "plain_text",
"text": "{{fields.class}}"
}, {
"type": "mrkdwn",
"text": "*Subclass:*"
}, {
"type": "plain_text",
"text": "{{fields.subclass}}"
}, {
"type": "mrkdwn",
"text": "*Severity*"
}, {
"type": "plain_text",
"text": "{{fields.severity}}"
}]
}]
}
Create the Slack webhook connector from the Alert Logic console
After you generate the target URL and
To create a Slack webhook connector:
- In the Alert Logic console, click the Settings icon (
), and then click Connectors.
- On the Connectors page, click the add icon (
), and then click Slack.
- On the Create a Slack Connector page, type a descriptive name for the webhook connector—for example, "Slack Webhook Connector for Incidents."
- In Target URL, paste the URL that you copied earlier.
- Choose the Payload Type, which is the type of Alert Logic security information that you want to send: Incident, Observation (of a log correlation), or Scheduled Report Notification.
- Choose the format of the payload template you customized earlier: JSON or JQ.
- Enter the payload template that you customized.
- Click TEST to send a test webhook request to the target URL provided. For more information, see Connector test results.
- If your webhook connector sent the test event to the target URL successfully, click SAVE.
Connector test results
If you receive a message that the connector was successfully tested, Alert Logic sends the payload template you configured and populates a message in Slack with sample data. Check Slack to ensure the results are expected, and adjust the payload template if necessary.
If the test is unsuccessful, Alert Logic displays an error message. For server response errors, you can use the error code and message that Alert Logic passes through to troubleshoot the issue. Alert Logic also informs you if your JSON or JQ payload template contains syntax errors.
Subscribe your webhook to receive notifications
After you test and save the connector configuration, the last step is to set up your notification criteria and subscribe the webhook.
You can set up and manage a notification of any type directly from the Notifications page. For more information, see Manage Notifications. You can create notifications from other pages according to notification type:
- For incidents, you can also create a notification from the Incidents page. For more information, see Incident Notifications.
- For observations, you can also create a notification from the Search page (Log Search tab or Correlations tab) during the process of creating the correlation or by editing an existing correlation listed on the Correlations tab. For more information, see Correlations and Notifications and Observation Notifications.
- For scheduled reports, you can also schedule the report and subscribe notification recipients from the Reports page. For more information, see Scheduled Reports and Notifications.
Manage your connectors
You can view the list of connectors and edit or delete an existing one. For more information, see Manage Connectors.