Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Does opsgenie support custom action scripts that are triggered by alert content?

Amit Moses June 17, 2021

Hey guys how are you doing? if possible, i would like the help of a technical support assistant to understand if our use case is possible on your platform. this has high impact for us since if it is not possible, we are afraid that in the near future we will have to look for an alternative for opsgenie.We just started digging into this, so i am afraid i have to share our vision, and not go into the little details as i simply don't have enough information yet.We are scaling in size and as a consequense we have alot of manual work to be done. we would like to automated the vast majority of the action we need to do. Most of our work is verifying the actions of users (we are a SOC), and we will need to automate that.An example: A user has performed a sensitive action on their Google Workspace environment. we get this alert via mail integration to Opsgenie.What we do at the moment: We read the content of the alert, and send to the performing user a message on slack to make sure it was made by him (and not a malicious actor that took over the account for example).What we would like to have eventually: an alert is receieved by the email integration. the alert is receieved by X and allows by python scripts to send via slack an automated message to the specific user.the vision is complex, i know. but the question is, does opsgenie support such scenario?

 

P.S

I dont expect Opsgenie to have such a solution out of the box, but for example, does marid support custom scripts like that?

1 answer

0 votes
Samir
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
June 17, 2021

Hi @Amit Moses !

 

Yes this is certainly possible with Opsgenie Edge Connector (OEC) which is the successor to Marid.

 

You can install/configure the OEC service on a server, and setup an OEC integration to trigger alerts to be sent to this OEC service, and the OEC service can be configured to execute custom scripts. 

 

So you could create the custom python script that OEC will execute to send the message to slack via API.

 

Hope this helps! Let us know if you have anymore questions.

 

Thanks,

Samir

A.G. Rappe August 5, 2021

<deleted>

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PERMISSIONS LEVEL
Site Admin
TAGS
AUG Leaders

Atlassian Community Events