These are some examples/quick guide on how to send Slack Webhooks from LogRhythm AIE alarms.
-
Add a webhook to your Slack team.
[ NOT SHOWN ] -
Create your AIE alarm with fields that you want to pass to your webhook.
[ NOT SHOWN ] -
Create a powershell script accepting the fields as parameters.
[ basic.ps1 ] -
Create the actions.xml manifest with the same parameters/fields.
[ actions.xml ] -
Create your SmartResponse Plugin using the powershell script and manifest.
[ NOT SHOWN ] -
Set your SmartResponse as an action to your AIE alarm, mapping the correct parameters:
-
Trigger your alarm, observe the webhook:





