> For the complete documentation index, see [llms.txt](https://docs.panther.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.panther.com/alerts/alert-management/slack.md).

# Managing Alerts in Slack

## Overview

Panther's [Slack Bot Alert Destination](/alerts/destinations/slack-bot.md) enables you to view and manage alerts directly from Slack. This includes using the Slack Bot Boomerang to discuss alerts with other Slack users and using Threat Intel to analyze an IP address for threat intelligence.

## Managing alerts in Slack

<div align="left"><figure><img src="/files/XLbmVjW19zY5P2k7Mefi" alt="Under a &#x22;Panther&#x22; title is a red dot next to &#x22;High.&#x22; Below is the text, &#x22;User reported a fraudulent Duo 2FA request,&#x22; as well as buttons like &#x22;View in Panther&#x22; and a boomerang icon."><figcaption></figcaption></figure></div>

A Slack Bot alert contains an Alert Summary, Runbook, and Severity. If you've enabled [Panther AI in Slack](#ai-alert-triage-sync), it may contain an [AI alert triage summary](/alerts.md#panther-ai-alert-triage), an **AI Triage** button, and support for [@mentioning Panther AI](#slack-ai-mention) directly in the thread.

The Slack Bot alert also has the following options:

* **View in Panther**: Open a direct link to the alert in the Panther Console.
* **Set Assignee**: Change the assignee of the alert.
* **Update Status**: Change the status of the alert to `Open`, `Triaged`, `Resolved`, or `Invalid`.
* **Show Alert Details**: Retrieve detailed information about the alert.
  * See [Show Alert Details](#show-alert-details) below for more information.
* **See Threat Intel**: View threat intelligence for specific attributes on an alert.
  * See [Slack Bot Threat Intel](#slack-bot-threat-intel) below for more information.
* **Boomerang** (🪃): Prompt a designated person to provide more information about an alert.
  * See [Send Boomerang](#send-boomerang) below for more information.
* **AI Triage**: Ask Panther AI to triage the alert directly from Slack. Only shown if [Panther AI in Slack](#ai-alert-triage-sync) is enabled and the alert hasn't already been triaged.
  * See [AI Triage button](#ai-triage-button) below for more information.

When you set an assignee or update the status, the Slack thread will update with a new reply indicating the change.

<div align="center"><img src="/files/Yy9N6U4Bfd0kDDn2TZuS" alt="Under &#x22;View in Panther&#x22; and &#x22;See Threat Intel&#x22; buttons is the text &#x22;@Linus assigned the alert to @Auston&#x22;"></div>

Interactions with the alert within Slack, such as updating the status, setting the assignee, and sending Boomerang messages, will sync back to the Panther Console. The resolution comment when marking an alert as "Resolved" will sync to the alert's **Activity** thread in the Panther Console.

You can also enable two-way sync for alert status, assignee, and [comments](#two-way-comment-syncing). This means that when an alert's status or assignee is changed or a comment is left in the Panther Console (or the Panther API), the changes will sync to the relevant Slack Bot alert(s). Similarly, when alert comments are added from external destinations like Jira, they will also be synced to Slack if two-way comment syncing is enabled.

<figure><img src="/files/YenPRyK8zXVjWV3LLIWS" alt="Three toggles are shown: Two-Way Status Syncing, Two-Way Assignee Syncing, and Two-Way Comment Syncing" width="375"><figcaption></figcaption></figure>

### Send Boomerang (🪃)

Use the Boomerang feature within a Panther Slack Bot alert to prompt another Slack user for information about the alert, such as justification for activity involving their account.

All Boomerang communications, including questions and responses, will be recorded in a thread on the original alert message in Slack, as well as in the **Activity** feed on the alert's Details page in the Panther Console.

#### How to use Slack Bot Boomerang

1. Within a Panther Slack Bot alert, click 🪃 .\
   ![](/files/rpwR1OmRmyHj74g1HXVp)
2. In the Boomerang modal, select a recipient and write a message.\
   ![The boomerang modal contains a dropdown field for the recipient, and a text field for the message. There are cancel and send buttons.](/files/AtnWjOAK9JRG1xQSrCNa)
   * For certain alert types, it's possible to include the JSON of the first event that triggered the alert by selecting **Share Event Details with Recipient**.\
     ![There is a checkbox for Share Event Details with Recipient. The beginning of an event's JSON, including an additionalFields key, is shown.](/files/4rON80ccYm20jYfrXhwn)
3. Click 🪃 **Send**.
   * The recipient will receive your message from the Panther Slack Bot.\
     ![A Panther Slack Bot message says "Your help has been requested!" The requestor's Slack handle is provided, along with the message or question they sent. There is a textfield for the recipient to write a response. There are two buttons: "Confirm" and "Report Suspicious Activity"](/files/gpJuMtw7uyaKv0KPMKVz)

### Show Alert Details

{% hint style="info" %}
Geolocation information (e.g. 🇺🇸 California, USA) for IP Addresses requires the [IPInfo Location](/enrichment/ipinfo.md) enrichment provider to be enabled.
{% endhint %}

* Click **Show Alert Details** to view additional details about the alert, including Summary Fields, Event Details, and First Event.

![](/files/i8ltOGmyGuuC1dlCNMEG)

After the information is retrieved, the associated Slack thread is updated:

![](/files/ZKx3Rm4VCjfYGV0A0NZB)

### Slack Bot Threat Intel

The option to **See Threat Intel** is shown on an alert in Slack if one or more Summary Attribute associated with the alert can be analyzed for threat intelligence (e.g. geographic location, ASN, etc.)

The threat intelligence options shown are dependent on which [Enrichment](/enrichment.md) datasets are enabled in your Panther deployment.

#### How to use Threat Intel

1. In a Slack alert, click **See Threat Intel**.\
   ![](/files/HIvmWvgoy0xOGc951Lt1)
2. In the prompt that appears, select a value to analyze.\
   ![](/files/rIg0wjw8WNYLWyoaDPJX)
   * After you select a value, the value is automatically analyzed and the available threat intelligence is returned:\
     ![](/files/5LXgkJ0H142XwqneNUWz)

### Slack Bot Threat Intelligence supported datasets

Slack Bot Threat Intelligence supports utilizing the following datasets:

* [IPInfo](/enrichment/ipinfo.md)
  * Location
  * ASN
* [TOR Exit Nodes](/enrichment/tor-exit-nodes.md)

### Two-way comment syncing

{% hint style="warning" %}
If you set up a Slack Bot destination before Panther version 1.115 and you'd like to enable two-way comment syncing, you'll need to [update your Slack app with a new manifest that includes the necessary permissions](/alerts/destinations/slack-bot.md#updating-an-existing-slack-bot-installation-for-new-features).
{% endhint %}

When **Two-Way Comment Syncing** is set to **ON**:

* When you leave a comment within the the alert's Activity section in the Panther Console, the message is synced to the Slack Bot alert's thread.
* When you send a message in the thread of a Slack Bot alert, the message is synced as a comment within the alert's **Activity** section in the Panther Console.
  * Comments from both registered Panther users and external Slack users are synced.
    * Comments include the name of the Slack user who posted them.
    * Comments from Slack users not registered in Panther are attributed to the system user, with the original poster's name included.
  * When a comment is edited in Slack, the change syncs to Panther, replacing the previous version.
  * When a message is deleted in Slack, no action is taken in Panther (the comment remains visible).
  * When a file is shared in the Slack Bot thread, the Panther **Activity** section will display the comment text plus a notification about the attached file.
  * Message formatting from Slack (except code blocks, which are converted to plain text) is preserved in Panther.
  * User mentions and channel links are displayed as raw identifiers (e.g., `<@U0949SWJQ6B>`) in Panther.

## Panther AI in Slack <a href="#ai-alert-triage-sync" id="ai-alert-triage-sync"></a>

{% hint style="info" %}
Panther AI in Slack is in open beta and available to all customers: AI alert triage syncing started in Panther version 1.114; the **AI Triage** button, @mention support, and Slack tool approval started in version 1.128. Please share any bug reports and feature requests with your Panther support team.
{% endhint %}

If [Panther AI](/ai.md) is enabled in your Panther deployment, you can bring Panther AI into your Slack Bot alerts:

* Automatically sync AI-generated alert triage into the alert's Slack thread ([AI alert triage sync](#ai-alert-triage-sync-beta)).
* Trigger AI triage for an alert on demand, without leaving Slack ([AI Triage button](#ai-triage-button)).
* Ask Panther AI follow-up questions or request an action by @mentioning it in an alert thread ([@mention Panther AI](#slack-ai-mention)).
* Approve or deny, from the same thread, any action Panther AI needs your permission to take ([Human-in-the-loop tool approval in Slack](#human-in-the-loop-tool-approval-in-slack)).

To enable these features, toggle **Enable Panther AI in Slack** `ON` in the Slack Bot Alert Destination configuration page in the Panther Console.

<figure><img src="/files/pCKmF4GXWeau6ZuAQ8hv" alt="To the right of &#x22;Enable Panther AI in Slack&#x22; text is a toggle set to ON." width="375"><figcaption></figcaption></figure>

{% hint style="info" %}
Panther users need the **Run Panther AI** and **View Alerts** permissions to use the **AI Triage** button or @mention Panther AI in Slack. As with other Slack Bot interactions, the Slack user's email address must match the email address of their Panther user profile.
{% endhint %}

### AI alert triage sync (Beta)

If [auto-run AI alert triage](/ai/using-panther-ai/panther-ai-and-alerts.md#auto-run-ai-alert-triage) generates a triage for an alert, that triage is automatically added as a reply within the Slack thread associated with the alert. Only the initial AI alert triage, not any follow-up responses, are synced to the Slack Bot thread.

The synced AI triage will contain the following sections:

* **Summary**: A concise overview of the alert.
* **Key Findings**: Notable patterns, behaviors, or anomalies identified by the AI.
* **Security Implications**: Analysis of the potential risk and impact.
* **Recommended Actions**: Suggested next steps or mitigations based on the AI's assessment.
* **Panther Console Link**: A direct link to view the full AI triage report in the Panther Console.

<div align="center" data-full-width="true"><figure><img src="/files/gZAVLrlP3br18wh8lvKz" alt="Under an &#x22;AI Analysis&#x22; header are &#x22;Summary&#x22;  and &#x22;Key Findings&#x22; sub-headers." width="375"><figcaption></figcaption></figure></div>

### AI Triage button <a href="#ai-triage-button" id="ai-triage-button"></a>

If an alert hasn't already been triaged by auto-run AI alert triage, its Slack Bot alert message shows an **AI Triage** button. Click it to trigger Panther AI triage for that alert directly from Slack — you don't need to open the Panther Console.

While Panther AI triage is running, the alert message shows "Panther AI is analyzing this alert…" in place of the button. Once triage completes, the AI's findings post as a reply in the alert's thread, and the alert message updates to show the resulting risk classification.

{% hint style="info" %}
The **AI Triage** button works on existing Slack Bot destinations as soon as you toggle **Enable Panther AI in Slack** `ON` — no Slack app update is required.
{% endhint %}

### @mention Panther AI in alert threads (Beta) <a href="#slack-ai-mention" id="slack-ai-mention"></a>

Within the thread of a Slack Bot alert, @mention Panther AI to ask a follow-up question or request an action — for example, `@Panther why did this fire?` or `@Panther mark this alert as resolved`. Panther AI replies in the same thread, and you can continue the conversation with further replies without @mentioning it again.

Panther AI only responds to @mentions inside a Slack Bot alert's own thread. @mentioning it in a channel, a DM, or outside an alert thread gets a reply directing you to an alert thread instead.

{% hint style="warning" %}
@mention support requires a Slack app manifest update for Slack Bot destinations set up before Panther version 1.128. See [Updating an existing Slack Bot installation for new features](/alerts/destinations/slack-bot.md#updating-an-existing-slack-bot-installation-for-new-features).
{% endhint %}

### Human-in-the-loop tool approval in Slack

When Panther AI needs to take an action that requires [human approval](/ai.md#tool-approval) during an **AI Triage** button or @mention conversation, it posts an approval card in the same Slack thread instead of running the action automatically.

The card describes the action Panther AI wants to take and shows **Approve** and **Deny** buttons. Only the Slack user who clicked **AI Triage** or sent the @mention can approve or deny the request — anyone else who clicks sees a message that they aren't able to decide. If no one responds within about two minutes, the request expires and Panther AI continues without taking the action.

This works the same way as [tool approval](/ai.md#tool-approval) in the Panther Console, except the approval card and decision happen entirely in Slack.

## Sending an alert to multiple Slack Bot destinations

If you have configured multiple Slack channels as Slack Bot alert destinations for the same alert, when you interact with one Slack Bot alert (e.g., you set an assignee or send a Boomerang message), the other Slack bot alert will be updated (in addition to the change being synced to the Panther Console).

For example, say an alert ID 12345 is sent to both `#channel-one` and `#channel-two`. On alert ID 12345 in `#channel-one`, you update the alert status from `Open` to `Triaged`. The following actions will result:

* In both `#channel-one` and `#channel-two`, alert ID 12345 shows the status as `Triaged`, and the thread on both alerts is updated to indicate the status change.
* In the Panther Console, the status of alert ID 12345 is changed to `Triaged`.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.panther.com/alerts/alert-management/slack.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
