Integration: Kaseya SIEM and Slack

The Kaseya SIEM and Slack integration enables organizations to connect a Slack workspace to Kaseya SIEM through Slack's authentication workflow. Once connected, Slack becomes available as an application within the organization and can be used for security monitoring and analysis.

Prerequisites

Before configuring the integration, make sure the following requirements are met:

  • A Slack workspace

  • A paid Slack plan (Pro, Business+, or Enterprise Grid)

  • A Slack account with Workspace Owner or Workspace Admin permissions

  • Administrative access to Kaseya SIEM

NOTE  If your organization has specific Slack permission requirements, consult your Slack administrator before connecting the integration.

How to...

Monitored events

The Slack integration supports six alert types. Default severities are assigned by Kaseya SIEM and can be used to help prioritize investigation and response activities.

Alert type Alert description Default severity
app.connection.failed An Application API connection has failed Critical
application.event.saas.integration Application Event - SaaS Integration Critical
login.success IAM Event - Authentication Success Low
multiple.login.diff.ip IAM Event - Multiple Login Connections From Different IP Addresses Low
new.device Device Event - New Device Medium
outside.own.location IAM Event - User Location - Outside approved location Critical

FAQ