Documentation Center
AlienVault® USM Anywhere™

Sending USM Anywhere Notifications to Slack

  Role Availability   Read-Only   Analyst   Manager

From USM Anywhere, you can send an alarm or event notification to a Slack channel so that team members are alerted. This facilitates communication and collaboration within the same messaging tool that your organization uses for incident responseIncident response is a business process or plan dictating how an organization handles security incidents such as a security breach or attack.. When you have this integration configured in USM Anywhere, you can create orchestration rules to automatically send these notifications when an eventAny traffic or data exchange detected by AlienVault products through a Sensor, or through external devices such as a firewall. or alarmAlarms provide notification of an event or sequence of events that require attention or investigation. matches the rule criteria.

Edition: Notification integrations are available in the Standard and Premium editions of USM Anywhere.

For more information about the feature and data support provided by each of the USM Anywhere editions, go to https://www.alienvault.com/pricing.

Note: While the direct integration with USM Anywhere is the easiest and most straightforward way to send messages to your Slack team from USM Anywhere, you can use the Amazon SNS messaging service as an alternative.

In this case, you create the webhook in Slack and then set up the integration in the Lambda function that you created in AWS to support USM Anywhere messaging (see Sending Notifications Through Amazon SNSand Set Up a Slack Integration through Amazon SNS).