Skip to content

Commit df570e1

Browse files
stephmiloviclcawl
authored andcommitted
[Security Solution] Webhook - Case Management Connector Documentation (elastic#137726)
Co-authored-by: lcawl <[email protected]>
1 parent afb0335 commit df570e1

13 files changed

+423
-25
lines changed

docs/management/action-types.asciidoc

Lines changed: 23 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -7,58 +7,62 @@ Connectors provide a central place to store connection information for services
77
[cols="2"]
88
|===
99

10-
a| <<email-action-type, Email>>
10+
a| <<email-action-type,Email>>
1111

1212
| Send email from your server.
1313

14-
a| <<resilient-action-type, IBM Resilient>>
14+
a| <<resilient-action-type,{ibm-r}>>
1515

16-
| Create an incident in IBM Resilient.
16+
| Create an incident in {ibm-r}.
1717

18-
a| <<index-action-type, Index>>
18+
a| <<index-action-type,Index>>
1919

2020
| Index data into Elasticsearch.
2121

22-
a| <<jira-action-type, Jira>>
22+
a| <<jira-action-type,Jira>>
2323

2424
| Create an incident in Jira.
2525

26-
a| <<teams-action-type, Microsoft Teams>>
26+
a| <<teams-action-type,Microsoft Teams>>
2727

2828
| Send a message to a Microsoft Teams channel.
2929

30-
a| <<pagerduty-action-type, PagerDuty>>
30+
a| <<pagerduty-action-type,PagerDuty>>
3131

3232
| Send an event in PagerDuty.
3333

34-
a| <<server-log-action-type, ServerLog>>
34+
a| <<server-log-action-type,ServerLog>>
3535

3636
| Add a message to a Kibana log.
3737

38-
a| <<servicenow-action-type, ServiceNow ITSM>>
38+
a| <<servicenow-action-type,{sn-itsm}>>
3939

40-
| Create an incident in ServiceNow.
40+
| Create an incident in {sn}.
4141

42-
a| <<servicenow-sir-action-type, ServiceNow SecOps>>
42+
a| <<servicenow-sir-action-type,{sn-sir}>>
4343

44-
| Create a security incident in ServiceNow.
44+
| Create a security incident in {sn}.
4545

46-
a| <<servicenow-itom-action-type, ServiceNow ITOM>>
46+
a| <<servicenow-itom-action-type,{sn-itom}>>
4747

48-
| Create an event in ServiceNow.
48+
| Create an event in {sn}.
4949

50-
a| <<slack-action-type, Slack>>
50+
a| <<slack-action-type,Slack>>
5151

5252
| Send a message to a Slack channel or user.
5353

54-
a| <<swimlane-action-type, Swimlane>>
54+
a| <<swimlane-action-type,{swimlane}>>
5555

56-
| Create an incident in Swimlane.
56+
| Create an incident in {swimlane}.
5757

58-
a| <<webhook-action-type, Webhook>>
58+
a| <<webhook-action-type, {webhook}>>
5959

6060
| Send a request to a web service.
6161

62+
a| <<cases-webhook-action-type,{webhook-cm}>>
63+
64+
| Send a request to a Case Management web service.
65+
6266
a| <<xmatters-action-type,xMatters>>
6367

6468
| Send actionable alerts to on-call xMatters resources.
@@ -68,7 +72,7 @@ a| <<xmatters-action-type,xMatters>>
6872
==============================================
6973
Some connector types are paid commercial features, while others are free.
7074
For a comparison of the Elastic subscription levels,
71-
see https://www.elastic.co/subscriptions[the subscription page].
75+
see {subscriptions}[the subscription page].
7276
==============================================
7377

7478
[float]

docs/management/cases/add-connectors.asciidoc

Lines changed: 9 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -6,11 +6,12 @@ preview::[]
66
You can add connectors to cases to push information to these external incident
77
management systems:
88

9-
* IBM Resilient
10-
* Jira
11-
* ServiceNow ITSM
12-
* ServiceNow SecOps
9+
* {ibm-r}
10+
* {jira}
11+
* {sn-itsm}
12+
* {sn-sir}
1313
* {swimlane}
14+
* {webhook-cm}
1415

1516
NOTE: To create connectors and send cases to external systems, you must have the
1617
appropriate {kib} feature privileges. Refer to <<setup-cases>>.
@@ -34,7 +35,8 @@ image::images/cases-connectors.png[]
3435

3536
. Enter your required settings. Refer to <<resilient-action-type>>,
3637
<<jira-action-type>>, <<servicenow-action-type>>, <<servicenow-sir-action-type>>,
37-
or <<swimlane-action-type>> for connector configuration details.
38+
<<swimlane-action-type>>, or <<cases-webhook-action-type>> for connector
39+
configuration details.
3840

3941
. Click *Save*.
4042

@@ -53,4 +55,5 @@ external system, update the case closure options.
5355
. To change the default connector for new cases, select the connector from the
5456
*Incident management system* list.
5557

56-
. To update a connector, click *Update <connector name>* and edit the connector fields as required.
58+
. To update a connector, click *Update <connector name>* and edit the connector
59+
fields as required.

0 commit comments

Comments
 (0)