Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution] Webhook - Case Management Connector Documentation #137726

Merged
merged 31 commits into from
Aug 12, 2022
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
31 commits
Select commit Hold shift + click to select a range
6442b11
tests and rm real url
stephmilovic Jul 26, 2022
7054387
Rename incidentViewUrl to viewIncidentUrl
stephmilovic Jul 26, 2022
1c6168b
beta badge all over
stephmilovic Jul 26, 2022
63c4f32
fix big whoops
stephmilovic Jul 27, 2022
751615e
pr fixes
stephmilovic Jul 27, 2022
08722d6
Merge branch 'main' into cases_webhook_followups
kibanamachine Jul 27, 2022
816e553
Merge branch 'main' into cases_webhook_followups
stephmilovic Jul 28, 2022
8fdc154
better badge alignment
stephmilovic Jul 28, 2022
f05f6d9
docs for cases webhook
stephmilovic Aug 1, 2022
1040222
resolve merge
stephmilovic Aug 1, 2022
7ca1077
Revert whoops
stephmilovic Aug 1, 2022
76ee40b
pr changes
stephmilovic Aug 1, 2022
86f0ccf
adjustments
stephmilovic Aug 1, 2022
214745a
Add example
stephmilovic Aug 2, 2022
b4d6795
fix headings
stephmilovic Aug 2, 2022
c483188
fix headings maybe
stephmilovic Aug 2, 2022
4e3dcfc
reference actual jira connector
stephmilovic Aug 2, 2022
2bd8312
indent steps hopefully
stephmilovic Aug 2, 2022
55434a9
rename
stephmilovic Aug 2, 2022
97c09ef
trying to indent step headings....
stephmilovic Aug 2, 2022
d1bc1d7
Merge branch 'main' into cases_webhook_docs
stephmilovic Aug 3, 2022
0c11bf3
rm getIncidentResponseCreatedDateKey and getIncidentResponseUpdatedDa…
stephmilovic Aug 3, 2022
0211a8a
Merge branch 'main' into cases_webhook_docs
stephmilovic Aug 8, 2022
b5af9a2
pr review changes
stephmilovic Aug 8, 2022
c028fc7
pr review changes 2
stephmilovic Aug 8, 2022
41360f2
Fix nesting level
lcawl Aug 9, 2022
c7b6e61
[DOCS] Text edits
lcawl Aug 9, 2022
6a11a53
[DOCS] Add connector to list of case connectors
lcawl Aug 10, 2022
aa170dd
[DOCS] Use shared attributes for connector names
lcawl Aug 12, 2022
7b1011f
[DOCS] Comment out example
lcawl Aug 12, 2022
4523790
Merge branch 'main' into cases_webhook_docs
lcawl Aug 12, 2022
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
42 changes: 23 additions & 19 deletions docs/management/action-types.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -7,58 +7,62 @@ Connectors provide a central place to store connection information for services
[cols="2"]
|===

a| <<email-action-type, Email>>
a| <<email-action-type,Email>>

| Send email from your server.

a| <<resilient-action-type, IBM Resilient>>
a| <<resilient-action-type,{ibm-r}>>

| Create an incident in IBM Resilient.
| Create an incident in {ibm-r}.

a| <<index-action-type, Index>>
a| <<index-action-type,Index>>

| Index data into Elasticsearch.

a| <<jira-action-type, Jira>>
a| <<jira-action-type,Jira>>

| Create an incident in Jira.

a| <<teams-action-type, Microsoft Teams>>
a| <<teams-action-type,Microsoft Teams>>

| Send a message to a Microsoft Teams channel.

a| <<pagerduty-action-type, PagerDuty>>
a| <<pagerduty-action-type,PagerDuty>>

| Send an event in PagerDuty.

a| <<server-log-action-type, ServerLog>>
a| <<server-log-action-type,ServerLog>>

| Add a message to a Kibana log.

a| <<servicenow-action-type, ServiceNow ITSM>>
a| <<servicenow-action-type,{sn-itsm}>>

| Create an incident in ServiceNow.
| Create an incident in {sn}.

a| <<servicenow-sir-action-type, ServiceNow SecOps>>
a| <<servicenow-sir-action-type,{sn-sir}>>

| Create a security incident in ServiceNow.
| Create a security incident in {sn}.

a| <<servicenow-itom-action-type, ServiceNow ITOM>>
a| <<servicenow-itom-action-type,{sn-itom}>>

| Create an event in ServiceNow.
| Create an event in {sn}.

a| <<slack-action-type, Slack>>
a| <<slack-action-type,Slack>>

| Send a message to a Slack channel or user.

a| <<swimlane-action-type, Swimlane>>
a| <<swimlane-action-type,{swimlane}>>

| Create an incident in Swimlane.
| Create an incident in {swimlane}.

a| <<webhook-action-type, Webhook>>
a| <<webhook-action-type, {webhook}>>

| Send a request to a web service.

a| <<cases-webhook-action-type,{webhook-cm}>>

| Send a request to a Case Management web service.

a| <<xmatters-action-type,xMatters>>

| Send actionable alerts to on-call xMatters resources.
Expand All @@ -68,7 +72,7 @@ a| <<xmatters-action-type,xMatters>>
==============================================
Some connector types are paid commercial features, while others are free.
For a comparison of the Elastic subscription levels,
see https://www.elastic.co/subscriptions[the subscription page].
see {subscriptions}[the subscription page].
==============================================

[float]
Expand Down
15 changes: 9 additions & 6 deletions docs/management/cases/add-connectors.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -6,11 +6,12 @@ preview::[]
You can add connectors to cases to push information to these external incident
management systems:

* IBM Resilient
* Jira
* ServiceNow ITSM
* ServiceNow SecOps
* {ibm-r}
* {jira}
* {sn-itsm}
* {sn-sir}
* {swimlane}
* {webhook-cm}

NOTE: To create connectors and send cases to external systems, you must have the
appropriate {kib} feature privileges. Refer to <<setup-cases>>.
Expand All @@ -34,7 +35,8 @@ image::images/cases-connectors.png[]

. Enter your required settings. Refer to <<resilient-action-type>>,
<<jira-action-type>>, <<servicenow-action-type>>, <<servicenow-sir-action-type>>,
or <<swimlane-action-type>> for connector configuration details.
<<swimlane-action-type>>, or <<cases-webhook-action-type>> for connector
configuration details.

. Click *Save*.

Expand All @@ -53,4 +55,5 @@ external system, update the case closure options.
. To change the default connector for new cases, select the connector from the
*Incident management system* list.

. To update a connector, click *Update <connector name>* and edit the connector fields as required.
. To update a connector, click *Update <connector name>* and edit the connector
fields as required.
Loading