Slack automation
Workflow Description
Advanced automation template connecting The Hive Project and Slack to monitor security incidents and send instant alerts. Processes incoming incident data and automatically routes notifications to appropriate Slack channels with conditional logic handling.
How it works
- 1.Receive incident from The Hive Project via webhook trigger
- 2.Process incident data and apply conditional logic rules
- 3.Route notification to the appropriate Slack channel
- 4.Log operation details and call additional APIs if needed
- 5.Send webhook response confirmation
Use cases
- Alert security teams immediately when new incidents are created in The Hive
- Automatically categorize and distribute incidents to specialized Slack channels
- Execute multi-step actions upon detection of critical-level incidents
Requirements
- The Hive Project account with incident access permissions
- Slack workspace with messaging and integration capabilities
- One or more Slack channels configured for alert delivery
Service Value
Ready-made workflow template for automation delivery and service execution.
Apps Used
Details
How to Use
- 1.Click "Download Template"
- 2.Open your n8n dashboard
- 3.Go to Workflows > Import from File
- 4.Select downloaded file and configure credentials
Nodes Used (63)
TheHive Trigger
Set
Sticky Note
Sticky Note
Sticky Note2
Sticky Note
Sticky Note3
Sticky Note
Edit Fields
Set
Task Modal
HTTP Request
HTTP Request
HTTP Request
Formatting Dictionaries
Set
Prep Fields For Slack
Set
Update Message with new Assignee
HTTP Request
Sticky Note4
Sticky Note
Sticky Note5
Sticky Note
Sticky Note7
Sticky Note
Check if Case Options
If
Case Slack Block Rebuild
Set
Close Case Block Rebuild
Set
Severity Case Block Rebuild1
Set
PAP Case Block Rebuild
Set
Prep Fields For PAP Slack
Set
Map Actions
Set
Build Final Block
Set
Prep Fields For TLP Slack
Set
Prep Fields For Status Slack
Set
Update Status in TheHive
Set
Close Case as False Positive
Set
Status Case Block Rebuild
Set
TLP Case Block Rebuild
Set
No Action Needed
No Op
Sticky Note11
Sticky Note
Sticky Note12
Sticky Note
Sticky Note13
Sticky Note
Sticky Note14
Sticky Note
Sticky Note15
Sticky Note
Post New Case To Slack
Slack
Prep Fields For Slack - Close
Set
Prep Fields For Slack - Assign
Set
Prep Fields For Slack - Severity
Set
Update Case Severity
Set
Update Case PAP
Set
Update Case TLP
Set
Acknowledge Close Case to Slack
Webhook
Acknowledge Severity Update to Slack
Webhook
Acknowledge PAP Update to Slack
Webhook
Acknowledge TLP Update to Slack
Webhook
Acknowledge Status Update to Slack
Webhook
Acknowledge Modal Request to Slack
Webhook
Sticky Note16
Sticky Note
Sticky Note17
Sticky Note
Parse Message Type
Switch
Sticky Note1
Sticky Note
Respond positive to Slack when someone clicks a link
Webhook
Respond 204 to Slack
Webhook
Close Modal with 204 response
Webhook
Get Slack User's Email From Slack
Slack
Update TheHive Case with new Assignee
Set
Respond to Slack with 200 response
Webhook
Sticky Note6
Sticky Note
Sticky Note8
Sticky Note
Sticky Note9
Sticky Note
Sticky Note10
Sticky Note
Get Email From Slack to assign the task to in TheHive
Slack
Add a task to TheHive
Set
Receive Button Press
Webhook