Post-Message-Slack

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Author: Yaniv Shasha

Attribute Value
Type Playbook
Solution SentinelSOARessentials
Source View on GitHub

Additional Documentation

📄 Source: Post-Message-Slack/readme.md

Author: Yaniv Shasha

Summary

This playbook will post a message in a Slack channel when an alert or incident is created in Microsoft Sentinel.

Prerequisites

Deployment Instructions

Deploy with Incident Trigger (Recommended)

After deployment, attach this playbook to an automation rule so it runs when the incident is created.

Learn more about automation rules

Deploy to Azure Deploy to Azure Gov

Deploy with Alert Trigger

After deployment, you can run this playbook manually on an alert or attach it to an analytics rule so it will run when an alert is created.

Deploy to Azure Deploy to Azure Gov

Post-deployment Instructions

  1. Open the Logic App in the Azure portal.
  2. Click the Slack connector resource.
  3. Click Edit API connection.
  4. Click Authorize and sign in with your Slack account.
  5. Click Save.
  6. Repeat for other connections if needed.

Note: The message will be sent from the user who creates the connection.

Screenshots

Incident Trigger
Incident Trigger Incident Trigger

Alert Trigger
Alert Trigger

Slack
Slack


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Playbooks · Back to SentinelSOARessentials