/
CrowdStrike - iHub Data Center - OpsGenie - Jira

CrowdStrike - iHub Data Center - OpsGenie - Jira

This tutorial describes how you can send a webhook from Crowdstike when a detection or incident has happen to iHub and iHub will create an Alert in OpsGenie and inform the one on call.

 

Expand the instructions for Integrations Hub for Jira Data Center

  1. Goto integrations

  2. Add a new Action

  3. Enter the URL: https://api.opsgenie.com/v2/alerts

  4. Method: POST

  5. Expand headers and add Key: Authorization and Value: GenieKey {your_key}

  6. Click on Variables and add the one below:
    img

  7. In the body paste in

    { "message": "CrowdStrike Incident {{name}}", "alias": "CrowdStrike Incident", "description":"ID: {{id}} URL:{{url}}", "responders":[ {"id":"tt-xx-yy-zz-bb", "type":"team"} ], "visibleTo":[ {"id":"tt-xx-yy-zz-bb", "type":"team"} ], "tags": ["CrowdStrike"], "priority":"P1" }
  8. Goto Incoming Webhooks menu

  9. Create a new Rule

  10. In the then clause point to the action above

 

 

Crowdstrike steps

  1. Goto All apps

  2. Click on Webhooks

  3. Add a new webhook

  4. Enter the URL shown in the Incoming Webhooks page

  5. Add a HMAC key (wont be needed since it does not encrypt the message)

  6. Click save

  7. Goto Workflows

  8. Add a new workflow, select the trigger to be detection or incident

  9. On the then clause select Notifications → Webhook and select the webhook created above.

 

 

Related content

Jira migration with Insight
Jira migration with Insight
Read with this
CrowdStrike - iHub Cloud - OpsGenie - Jira
CrowdStrike - iHub Cloud - OpsGenie - Jira
More like this
Add New System
Read with this
Splunk
More like this
How to send an attachment
How to send an attachment
Read with this
Receive SOAP message
Receive SOAP message
More like this