Using Webhooks in Notification Policies

For ITM/Endpoint DLP detection rules and CASB rules, Notification Policies can be defined to send notifications via webhooks. When the specific activity is detected, notifications are pushed to third party tools such as Slack, to your SIEM or to your ticketing system. (See Notification Policies.)

Adding Webhooks

You can add webhooks to send notifications to Slack, Outlook Groups, Splunk Cloud, Microsoft Teams or any other 3rd party application you choose.

  1. When setting up a Notification Policy, select IntegrationsNotification Policies . Click New Notification.

  2. In the For Rules area, click Create.

  3. Name the policy.

    1. Select Add in Webhooks area.

  4. Click Add in the Webhooks area.

  5. From the dropdown, select the type of webhook you want.

  6. In the example, Slack was selected. Click the link for detailed instructions.

  7. When you complete the instructions, you'll receive a URL. Copy the URL and click Save.

  8. The webhook is added and relevant notifications will be sent to Slack.

You can select to deliver your webhook to Slack, Outlook Groups, Splunk Clouds or Microsoft Teams.

For information about how to set up webhooks, use the following links:

Learn more about Slack webhooks

Learn more about Outlook Groups webhooks

Learn more about Splunk Cloud webhooks

Learn more about Teams webhooks

Webhooks Generic Template

If you prefer to deliver notifications using another third party tool, such as Service Now, you can select the Generic Template.

Select Generic from the dropdown and complete the fields in the template for the specific application you want.

  • You must provide the URL and Method which should be available from the third party tool you are working with.

  • Headers are optional and may be necessary for specific webhooks, for example to add a simple authentication.

  • In the Data field you can add any content you want, such as text you want to appear.

  • If the webhook requires a certificate, pasted it in the CA field.


Related Topics:

Notification Policies

Creating a Notification Policy for a Rule