Developer & DevOps

Send The Hive Security Alerts to Slack Automatically

63 nodes 277 139 Automatic trigger
Download

Workflow Description

Automation monitors The Hive Project security incidents and sends real-time alerts to dedicated Slack channels, with multi-condition processing and automatic incident logging to enhance security team response efficiency.

How it works

  1. 1.Receive new security alert from The Hive Project via webhook
  2. 2.Process incident data and apply conditional logic rules
  3. 3.Format message and dispatch to appropriate Slack channel
  4. 4.Log incident details back into The Hive Project
  5. 5.Send webhook confirmation response
  6. 6.Route actions based on incident severity and type

Use cases

  • Notify security team instantly when suspicious activity is detected
  • Centralize security alerts from multiple sources in one Slack channel
  • Automatically document security incidents with complete details
  • Classify alerts by severity and route to different teams

Requirements

  • The Hive Project account with API credentials
  • Slack workspace with bot messaging permissions
  • Webhook configured in The Hive Project
  • Dedicated Slack channels for alert notifications
  • Custom incident fields and identifiers in The Hive

Service Value

Ready-made workflow template for automation delivery and service execution.

Apps Used

The Hive Project Trigger The Hive Project Slack

Details

Trigger Automatic trigger
Nodes 63
Apps 3
Views 277
Downloads 139

How to Use

  1. 1.Click "Download Template"
  2. 2.Open your n8n dashboard
  3. 3.Go to Workflows > Import from File
  4. 4.Select downloaded file and configure credentials

Nodes Used (63)

/

TheHive Trigger

Set

#1

Sticky Note

Sticky Note

#2

Sticky Note2

Sticky Note

#3

Sticky Note3

Sticky Note

#4

Edit Fields

Set

#5

Task Modal

HTTP Request

#6

HTTP Request

HTTP Request

#7

Formatting Dictionaries

Set

#8

Prep Fields For Slack

Set

#9

Update Message with new Assignee

HTTP Request

#10

Sticky Note4

Sticky Note

#11

Sticky Note5

Sticky Note

#12

Sticky Note7

Sticky Note

#13

Check if Case Options

If

#14

Case Slack Block Rebuild

Set

#15

Close Case Block Rebuild

Set

#16

Severity Case Block Rebuild1

Set

#17

PAP Case Block Rebuild

Set

#18

Prep Fields For PAP Slack

Set

#19

Map Actions

Set

#20

Build Final Block

Set

#21

Prep Fields For TLP Slack

Set

#22

Prep Fields For Status Slack

Set

#23

Update Status in TheHive

Set

#24

Close Case as False Positive

Set

#25

Status Case Block Rebuild

Set

#26

TLP Case Block Rebuild

Set

#27

No Action Needed

No Op

#28

Sticky Note11

Sticky Note

#29

Sticky Note12

Sticky Note

#30

Sticky Note13

Sticky Note

#31

Sticky Note14

Sticky Note

#32

Sticky Note15

Sticky Note

#33

Post New Case To Slack

Slack

#34

Prep Fields For Slack - Close

Set

#35

Prep Fields For Slack - Assign

Set

#36

Prep Fields For Slack - Severity

Set

#37

Update Case Severity

Set

#38

Update Case PAP

Set

#39

Update Case TLP

Set

#40

Acknowledge Close Case to Slack

Webhook

#41

Acknowledge Severity Update to Slack

Webhook

#42

Acknowledge PAP Update to Slack

Webhook

#43

Acknowledge TLP Update to Slack

Webhook

#44

Acknowledge Status Update to Slack

Webhook

#45

Acknowledge Modal Request to Slack

Webhook

#46

Sticky Note16

Sticky Note

#47

Sticky Note17

Sticky Note

#48

Parse Message Type

Switch

#49

Sticky Note1

Sticky Note

#50

Respond positive to Slack when someone clicks a link

Webhook

#51

Respond 204 to Slack

Webhook

#52

Close Modal with 204 response

Webhook

#53

Get Slack User's Email From Slack

Slack

#54

Update TheHive Case with new Assignee

Set

#55

Respond to Slack with 200 response

Webhook

#56

Sticky Note6

Sticky Note

#57

Sticky Note8

Sticky Note

#58

Sticky Note9

Sticky Note

#59

Sticky Note10

Sticky Note

#60

Get Email From Slack to assign the task to in TheHive

Slack

#61

Add a task to TheHive

Set

#62

Receive Button Press

Webhook

#63