Cisco Multicloud Defense User Guide

PDF

Cisco Multicloud Defense User Guide

Microsoft Teams

Want to summarize with AI?

Log in

Learn how the Microsoft Teams integration uses an alert profile and service rule to deliver Cisco Multicloud Defense alerts to a Teams incoming webhook.


Create an alert profile and then use that profile in a service alert rule to generate alerts specifically for Microsoft Teams using a uique incoming webhook from the service.


Create a Microsoft Teams Alert Profile Service

Before you begin

You must do the following items before you finalize the alert profile for your Microsoft account:

  • You must create an Incoming Webhook in the Microsoft Teams UI. See Microsoft documentation for more information.

  • You must save the unique API URL generated from creating an incoming webhook for the procedure below.

Procedure

1.

Navigate to System and Accounts > Service Alerts > Services.

2.

Click Create.

3.

Name - Enter unique name for the alert integration.

4.

(Optional) Description - Enter a description for the alert integration.

5.

Type - Using the pulldown, choose Microsoft Teams.

6.

API URL - Enter the API URL that is generated from creating an incoming webhook. Copy the URL from your Microsoft Teams UI and paste it in this text field.

7.

Click Save.

What to do next

Create an alert rule with this new profile.


Create a Microsoft Teams Service Rule

Before you begin

You must create a Microsoft Teams service profile before you create a service rule.

Procedure

1.

Navigate to System and Accounts > Service Alerts > Alert Rules.

2.

Click Create.

3.

Profile Name - Enter unique name for the integration. An example would be similar to mcd-microsoft-alert-rule.

4.

(Optional)Description - Enter a description for the aler trule.

5.

Alert Profile - Expand the drop-down menu and select a Microsoft Teams alert profile.

6.

Type - Expand the drop-down menu and select one of the following types:

  • System Logs

  • Audit Logs

  • Discovery

If you select Audit Logs, there are no other configurable items. Click Save to finalize the rule.

7.

If you select either System Logs or Discovery as your Type, then expand the Sub Type drp-down menu and select one of the following options:

  • Gateway

  • Account

  • Controller

8.

Expand the Severitydrop-down menu and select one of the following labels. Note that the options below are dependent on the Type you selected in step 7.

  • Info

  • Warning

  • Medium

  • High

  • Critical

9.

Enabled - This option is checked by default to enable and implement this alert immediately after saving. Unceck this box if you do not to immediately apply the rule to your environment.

10.

Click Save.