Ask the community

Netskope Alerts via Slack Messages

jramirez
Moderator
Moderator

Netskope Alerts via Slack Messages

Prerequisites:

Procedure:

Step 1. Netskope ITSM (CTO) Plugin Setup (skip to step 2 if already setup):

  1. Login to Cloud Exchange as a user with admin privileges.
  2. Navigate to Settings > Plugins.
    jramirez_0-1672243995101.png

     

    jramirez_1-1672243995108.png

     

  3. Click on the Netskope ITSM (CTO) plugin.
    jramirez_2-1672243995110.png

     

  4. Name the configuration and set the tenant field to the Netskope tenant you want to receive alerts from. Click Next.
    jramirez_3-1672243995105.png

     

  5. Navigate to Ticket Orchestrator and click on Alerts. Make sure the section is being populated with alert data from the configured tenant.
    jramirez_4-1672243995114.png

     

Step 2. Notifier Plugin for Slack Webhook (CTO) Setup:

  1. Navigate to Settings > Plugins.
    jramirez_5-1672243995660.png

     


    jramirez_6-1672243995112.png

     

  2. Click on the Notifier (CTO) plugin.
    jramirez_7-1672243995829.png

     

  3. Name the configuration and set the sync interval. The default of 60 minutes is recommended, but for testing purposes you can set it to 30 to 60 seconds for faster results. Click Next.
    jramirez_8-1672243995765.png

     

  4. Set the Platform Name to Slack (Webhooks) and click Next.
    jramirez_9-1672243995919.png

     

  5. Enter the channel’s webhook URL into the Webhook URL field. The other fields within the setup are optional. More information on each can be found by hovering over the gray “i” next to each field. Click Save on the top right of the page.
    jramirez_10-1672243995733.png

     

Step 3. Setup Business Rules:

  1. Navigate to Ticket Orchestrator > Alerts.
    jramirez_11-1672243995924.png

     


    jramirez_12-1672243995269.png

     

  2. Use the filter section to create a useful query for a business rule you wish to receive notifications for. Once your query is set, click on the Create Business Rule button. Give the rule a name and click on Save.
    jramirez_13-1672243995659.png

jramirez_14-1672243996022.png

 

  1. (Optional) Navigate to Business Rules and click on the business rule created. You can create deduplication rules and mute rules to help manage the amount of alerts generated.
    jramirez_15-1672243995802.png

     

  2. Follow steps 1-3 for any other business rules you need notifications for.

Step 4. Create the Slack Notification Queue:

  1. Navigate to Ticket Orchestrator > Queues.
    jramirez_16-1672243995925.png

     


    jramirez_17-1672243995686.png

     

  2. Click on Add Queue Configuration. Select the business rule created in Step 3. Select the Notifier plugin created in Step 2 as the configuration. Set the Queues value to Notification, this will be the only value available.
    jramirez_18-1672243995482.png

     

  3. Create a custom message using alert variables, use a $ symbol to see available variables (variables are based off of alert details, so not all variables will work within your notifications, stick with fields that are seen within the alerts caught by your business rule). Instead of a custom message, you can choose from the same variables as values. Once finished click on Save.
    jramirez_19-1672243995882.png
    jramirez_20-1672243995932.png

     

  4. Follow steps 1-3 for any other business rules that need to be sent as notifications, replacing the original business rule in step 2 with the other business rules.
  5. Once saved, the queue configuration can be tested, the timespan to look back for can be configured depending on the amount of data you want to fetch. The sync button will send any notifications caught by the fetch to Slack. This is usually done automatically by the plugin’s sync period set in Step 2, but it can be forced for testing.
    jramirez_21-1672243995376.png

jramirez_22-1672243995987.png

 

jramirez_23-1672243995447.png

0 Replies 0

In order to view this content, you will need to sign in to your account. Simply click the "Sign In" button below

Sign In