Send The Hive Security Alerts to Slack Automatically
Workflow Description
Automation monitors The Hive Project security incidents and sends real-time alerts to dedicated Slack channels, with multi-condition processing and automatic incident logging to enhance security team response efficiency.
How it works
- 1.Receive new security alert from The Hive Project via webhook
- 2.Process incident data and apply conditional logic rules
- 3.Format message and dispatch to appropriate Slack channel
- 4.Log incident details back into The Hive Project
- 5.Send webhook confirmation response
- 6.Route actions based on incident severity and type
Use cases
- Notify security team instantly when suspicious activity is detected
- Centralize security alerts from multiple sources in one Slack channel
- Automatically document security incidents with complete details
- Classify alerts by severity and route to different teams
Requirements
- The Hive Project account with API credentials
- Slack workspace with bot messaging permissions
- Webhook configured in The Hive Project
- Dedicated Slack channels for alert notifications
- Custom incident fields and identifiers in The Hive
Service Value
Ready-made workflow template for automation delivery and service execution.
Apps Used
Details
How to Use
- 1.Click "Download Template"
- 2.Open your n8n dashboard
- 3.Go to Workflows > Import from File
- 4.Select downloaded file and configure credentials
Nodes Used (63)
TheHive Trigger
Set
Sticky Note
Sticky Note
Sticky Note2
Sticky Note
Sticky Note3
Sticky Note
Edit Fields
Set
Task Modal
HTTP Request
HTTP Request
HTTP Request
Formatting Dictionaries
Set
Prep Fields For Slack
Set
Update Message with new Assignee
HTTP Request
Sticky Note4
Sticky Note
Sticky Note5
Sticky Note
Sticky Note7
Sticky Note
Check if Case Options
If
Case Slack Block Rebuild
Set
Close Case Block Rebuild
Set
Severity Case Block Rebuild1
Set
PAP Case Block Rebuild
Set
Prep Fields For PAP Slack
Set
Map Actions
Set
Build Final Block
Set
Prep Fields For TLP Slack
Set
Prep Fields For Status Slack
Set
Update Status in TheHive
Set
Close Case as False Positive
Set
Status Case Block Rebuild
Set
TLP Case Block Rebuild
Set
No Action Needed
No Op
Sticky Note11
Sticky Note
Sticky Note12
Sticky Note
Sticky Note13
Sticky Note
Sticky Note14
Sticky Note
Sticky Note15
Sticky Note
Post New Case To Slack
Slack
Prep Fields For Slack - Close
Set
Prep Fields For Slack - Assign
Set
Prep Fields For Slack - Severity
Set
Update Case Severity
Set
Update Case PAP
Set
Update Case TLP
Set
Acknowledge Close Case to Slack
Webhook
Acknowledge Severity Update to Slack
Webhook
Acknowledge PAP Update to Slack
Webhook
Acknowledge TLP Update to Slack
Webhook
Acknowledge Status Update to Slack
Webhook
Acknowledge Modal Request to Slack
Webhook
Sticky Note16
Sticky Note
Sticky Note17
Sticky Note
Parse Message Type
Switch
Sticky Note1
Sticky Note
Respond positive to Slack when someone clicks a link
Webhook
Respond 204 to Slack
Webhook
Close Modal with 204 response
Webhook
Get Slack User's Email From Slack
Slack
Update TheHive Case with new Assignee
Set
Respond to Slack with 200 response
Webhook
Sticky Note6
Sticky Note
Sticky Note8
Sticky Note
Sticky Note9
Sticky Note
Sticky Note10
Sticky Note
Get Email From Slack to assign the task to in TheHive
Slack
Add a task to TheHive
Set
Receive Button Press
Webhook