Configure the Data Connector
To use enable the Infoblox SOC to Slack integration, you’ll need both a source and destination for the data connector is required. Perform the following steps to configure the Data Connector destination and a traffic flow. After deploying the integration from the Ecosystem Portal, these components are automatically populated.
Steps to Deploy the Slack Integration
Access the Ecosystem Portal:
Log in to the Infoblox CSP.Navigate to the Integration Marketplace:
Go to Configure in the top menu.
Click on Administration.
From the list, select Integration Marketplace.
Deploy the Integration:
You will be redirected to the Infoblox Marketplace. Locate the Slack integration, and click Deploy to add it to your Infoblox portal.
...
Once deployed, the integration script will appear in the Automation tab of the Data Connector.
Review and Configure the Destination Parameters:
Although the destination is automatically created, you’ll need to review and configure specific destination parameters to match your Slack environment settings. This ensures seamless communication between Infoblox SOC and Slack.
On the Infoblox CSP highlight on
...
Configure, click on Administration and select Data Connector
...
from the revealed list
...
On the Data Connector tab, use BloxOne Cloud Source as the Source Type.
...
On the Data Connector tab, click on the
...
Automation tab on the top of the Data Connector Page where you can see the Integration script.
...
Create destination configuration based on the following steps.
...
Enter a Name for the configuration.
...
...
Although the destination is automatically created, you’ll need to review and configure specific destination parameters to match your Slack environment settings.
...
Edit the Application Script for Slack Integration and configure the desired Variables for Authentication and Integration.
Variables
cspInstance : csp.infoblox.com
cspApiKey
slackWebhook
...
Enable the destination by changing State to Enabled.
...
...
Verify the Traffic Flow
...
In the Create Traffic Flow Configuration screen, the details below are to be filled out.
...
Enter the Name and description of the configuration. Enable the configuration by toggling the State to Enabled.
...
...
Select BloxOne Cloud Source as the Source of Log Source Configuration and select Internal Notifications Log as the Log Type for Source Configuration.
...
...
Expand the Destination Configuration list by clicking on the Destination Configuration header. Then, select the destination that was created earlier in this guide from the drop-down list.
...
:
The traffic flow is also auto-populated upon deployment. It’s recommended to verify the traffic flow settings to confirm that the data is correctly directed from Infoblox SOC to Slack.
Edit the Traffic Flow:
Go to the General tab.
Set the State to Enable.
Configure the Source:
Under Log Source Configuration, set Source to Infoblox Cloud Source.
Set Log Type to SOC Insights.
...
Select the Service Instance:
Expand the Service Instance list by clicking on the Service Instance header.
...
From the list, select the created Data Connector service
...
.
Finalize the Setup:
Click Finish to confirm the creation of the Traffic Flow.