Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

This tutorial describes how you can send a webhook from Crowdstike when a detection or incident has happen to iHub and iHub will create an Alert in OpsGenie and inform the one on call.

...

Expand
titleiHub Cloud Instructions
  1. Creata an Integration

  2. Select Incoming webbook as trigger

  3. Add a Action: Webhook action

  4. Enter the URL: https://api.opsgenie.com/v2/alerts

  5. Method: POST

  6. Expand headers and add Key: Authorization and Value: GenieKey {your_key}

  7. Click on Variables and add the one below:

  8. In the body paste in

    Code Block
    languagejs
    {
        "message": "CrowdStrike Incident {{name}}",
        "alias": "CrowdStrike Incident",
        "description":"ID: {{id}} URL:{{url}}",
        "responders":[
            {"id":"tt-xx-yy-zz-bb", "type":"team"}
        ],
        "visibleTo":[
            {"id":"tt-xx-yy-zz-bb", "type":"team"}
        ],
        "tags": ["CrowdStrike"],
        "priority":"P1"
    }

Expand
titleiHub DataCenter instructions
  1. Goto Outbound integrations

  2. Add a new Action

  3. Enter the URL: https://api.opsgenie.com/v2/alerts

  4. Method: POST

  5. Expand headers and add Key: Authorization and Value: GenieKey {your_key}

  6. Click on Variables and add the one below:
    img

  7. In the body paste in

    Code Block
    languagejs
    {
        "message": "CrowdStrike Incident {{name}}",
        "alias": "CrowdStrike Incident",
        "description":"ID: {{id}} URL:{{url}}",
        "responders":[
            {"id":"tt-xx-yy-zz-bb", "type":"team"}
        ],
        "visibleTo":[
            {"id":"tt-xx-yy-zz-bb", "type":"team"}
        ],
        "tags": ["CrowdStrike"],
        "priority":"P1"
    }
  8. Goto Inbound integrations

  9. Create a new Rule

  10. In the then clause point to the action above

...