Skip to main content

Overview

Discover all the available notification integrations in CrowdSec. Each integration is designed to help you receive alerts and notifications to various platforms, ensuring you stay informed about security events and incidents. Available here.

🌟 Premium feature. CrowdSec let you be linked to any notification integration. However, you need to be a ⭐ Premium organization to unlock the full potential of the notification integrations.

Available Integrations

  • Slack
  • Coming soon: Discord
  • Coming soon: Webhook
  • Coming soon: Microsoft Teams

How to use notification integrations

  1. Link your integration: Navigate to the Settings > Integrations section in the CrowdSec Console and select the integration you want to link. Follow the instructions provided for each integration.
  2. Create a notification rule: Once your integration is linked, navigate to the Rules tab of the integration page. Here, you can create notification rules based on specific events or conditions. (See the documentation for more details on creating rules.)

Available Events

The following events are available for notification integrations:

Threat Hunting

NameDescription
Is AttackingAn attack has been detected from your Security Engine.
Is AttackedYour organization is being attacked.
Alert TriggeredAn alert has been triggered.

Stack - Management

NameDescription
Security Engine EnrolledA new Security Engine has been enrolled.
Security Engine UnenrolledA Security Engine has been unenrolled.
Security Engine Long Pending EnrollA Security Engine has been pending for a long time.

Stack - Monitoring

NameDescription
Firewall Integration OfflineA firewall integration is offline.
Log Processor No AlertA log processor has not sent any alerts for 48h.
Log Processor OfflineA log processor is offline.
Remediation Component Integration OfflineA remediation component integration is offline.
Remediation Component OfflineA remediation component is offline.
CrowdSec Stack Component OutdatedA CrowdSec stack component is outdated (Security Engine, Log Processor, Remediation component).
Security Engine No AlertsA Security Engine has not sent any alerts for 48h.
Security Engine OfflineA Security Engine is offline.

Admin

NameDescription
API Key ExpiredAn API key has expired.
Payment FailedA payment has failed.

Examples