- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Incident Notifications via Microsoft team/Telegram
Dear Team,
I would like to any possible way or guide for configuring FortiSIEM to send notification via Telegram or Microsoft team. Appreciate for every answer.
Thank You
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Lyyiheang,
As of version 7.1.x, there is no integrated solution.
In MS Teams, you can get/view email addresses for each channel and simply send notifications via mail to these channels.
The only other way to send notifications is pushing an xml to a webserver (https), where you then need to have a script that can work with that.
I'd assume services like IFTTT could handle that but I don't think you'd like to do that from a data privacy perspective.
Best
Christian
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
while there is no easy way included, it can be done via a python (remediation) script which uses a teams webhook. Same should work for telegram...
or sending a notification to my awtrix clock
Regards
Manuel
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Lyyiheang,
As of version 7.1.x, there is no integrated solution.
In MS Teams, you can get/view email addresses for each channel and simply send notifications via mail to these channels.
The only other way to send notifications is pushing an xml to a webserver (https), where you then need to have a script that can work with that.
I'd assume services like IFTTT could handle that but I don't think you'd like to do that from a data privacy perspective.
Best
Christian
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
while there is no easy way included, it can be done via a python (remediation) script which uses a teams webhook. Same should work for telegram...
or sending a notification to my awtrix clock
Regards
Manuel
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Manuel,
Great point (love the awtrix clock and note that down for our SOC :) )!
Just one thing to note: The incident then is considered as remediated. Depending on how your analysts work, this might become irritating.
Best,
Christian
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@marod1981 Can you please share me script for testing? You idea is very great
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
HI @marod1981 can you provide your step-by-step configuration on python (remediation) script for microsoft teams.
