Links

OpsGenie Destination

Configuring OpsGenie as an alert destination in your Panther Console

Overview

Destinations are integrations that receive alerts from rules, policies, system health notifications, and rule errors. Panther supports configuring OpsGenie as the destination where you will receive alerts.
The OpsGenie Destination requires an Opsgenie API key. When an alert is forwarded to an OpsGenie Destination, it creates an incident using the specified API key.

How to set up OpsGenie alert destinations in Panther

Configure the integration in OpsGenie

  1. 1.
    Log in to your OpsGenie dashboard. Navigate to the Teams tab and select the team to receive alerts.
  2. 2.
    Click Integrations on the left, then click Add integration.
    The image shows the OpsGenie dashboard. On the left sidebar, Integrations is highlighted. The page lists integrations, and there is a button in the upper right labeled "Add integration."
  3. 3.
    In the Integrations list, click API.
    The image shows the integrations list in OpsGenie. There is a search bar at the top to search for a specific integration.
  4. 4.
    Configure the name, settings, and permissions for the integration. Check the boxes next to the Enabled and Create and Update Access permissions.
    The OpsGenie settings page is displayed. There are fields for Name and API Key. The permissions are enabled for Read Access, Create and update access, delete access, and enabled.
  5. 5.
    Copy the API Key from the configuration settings and store it in a secure location. You will need this in the next steps.
  6. 6.
    Click Save Integration.

Configure the OpsGenie alert destination in Panther

  1. 1.
    Log in to the Panther Console.
  2. 2.
    In the left sidebar, click Configure > Alert Destinations.
  3. 3.
    Click +Add your first Destination.
    • If you have already created Destinations, click Create New in the upper right side of the page to add a new Destination.
  4. 4.
    Click OpsGenie.
  5. 5.
    Fill out the form to configure the Destination:
    • Display Name: Enter a descriptive name.
    • API Key: Enter the OpsGenie API Key you generated in previous steps of this documentation.
    • Region: Select your region based on where your OpsGenie account is registered.
    • Severity: Select the severity level of alerts to send to this Destination.
    • Alert Types: Select the alert types to send to this Destination.
    • Log Type: By default, we will send alerts from all log types. Specify log types here if you want to only send alerts from specific log types.
      In the Panther Console, the "Configure your OpsGenie Destination" page is displayed. It contains fields for Display Name, OpsGenie API Key, Severity, Alert Types, and Log Types.
  6. 6.
    Click Add Destination.
  7. 7.
    On the final page, optionally click Send Test Alert to test the integration. When you are finished, click Finish Setup.

Additional Information on Destinations

For more information on alert routing order, modifying or deleting destinations, and workflow automation, please see the Panther docs: Destinations.