Creare un webhook per Slack
Informazioni su questa attività
Un webhook facilita l'integrazione di IBM Storage Insights con Slack. Con questa integrazione, quando viene attivato un allarme ransomware in IBM Storage Insights, si riceve una notifica attraverso il messaggio slack.
Procedura
Per creare un webhook per Slack in IBM Storage Insights, completare i seguenti passaggi:
Risultati
{
"severity": "critical",
"deviceType": "flashFamily",
"subcategory": "SECURITY",
"creator": "",
"alert": {
"source": {
"deviceModel": "ABC",
"deviceSerialNumber": "0000011111222222",
"deviceType": "FlashSystem 0000-1111",
"deviceName": "tpcflash9100"
},
"method": "FCM4"
},
"name": "Ransomware Threat Detection",
"occurrenceTimeInMs": 1722414176890,
"id": "2ca10680-4f16-11ef-b133-5f7dcde81b1d",
"resourceType": "Storage System",
"details": [
{
"volumeID": "69",
"status": "offline_threat_detected",
"hosts": "",
"virtualVolumeID": "",
"uID": "60050768108100cd000000000001ce6a",
"description": "The volume has received an anomalous workload. This anomaly could be the result of a new application configuration where encryption is enabled or a security threat such as ransomware"
}
],
"tenantUUID": "01ecebec-f792-11d0-a794-f2c6a924f488",
"alertURL": "https://dev.insights.ibm.com/gui/01ecebec-f792-11d0-a794-f2c6a924f488#alerts?id=2ca10680-4f16-11ef-b133-5f7dcde81b1d&parentType=storageSystem&parentId=95a5f1d0-4995-11ef-8ee9-a920a5b6ca70"
}