Links

PagerDuty Destination

Configuring PagerDuty as an alert destination in your Panther Console
Destinations are integrations that receive alerts from rules, policies, system health notifications, and rule errors. Panther supports configuring PagerDuty as the destination where you will receive alerts.
PagerDuty is a service to manage on-call rotations for critical systems. You can use the PagerDuty alert destination to page an on-call team. We typically only recommend this Destination for High and Critical severity issues that need to be addressed immediately.

How to set up PagerDuty alert destinations in Panther

Configure the integration in PagerDuty

  1. 1.
    Log in to your PagerDuty account.
  2. 2.
    Navigate to the Service Directory configuration page then click +New Service.
  3. 3.
    Fill out the form on the service configuration page.
    • For Integration Type, choose Use our API directly.
  4. 4.
    You will be redirected to the Integrations page for that service. On this page, copy out the Integration Key and store it in a secure location. You will need this in the next steps.
To ensure that you receive alerts from this integration, make sure you have assigned a user to be on-call in PagerDuty. For more information about setting on-call schedules, see PagerDuty's schedule basics documentation

Configure the PagerDuty alert destination in Panther

  1. 1.
    Log in to the Panther Console.
  2. 2.
    In the left sidebar, click Configure > Alert Destinations.
  3. 3.
    Click +Add your first Destination.
    • If you have already created Destinations, click Create New in the upper right side of the page to add a new Destination.
  4. 4.
    Click PagerDuty.
  5. 5.
    Fill out the form to configure the Destination:
    • Display Name: Enter a descriptive name.
    • Integration Key: Enter the PagerDuty Integration Key you generated in the earlier steps of this documentation.
    • Severity: Select the severity level of alerts to send to this Destination.
    • Alert Types: Select the alert types to send to this Destination.
    • Log Type: By default, we will send alerts from all log types. Specify log types here if you want to only send alerts from specific log types.
  6. 6.
    Click Add Destination.
  7. 7.
    On the final page, optionally click Send Test Alert to test the integration. When you are finished, click Finish Setup.

Additional Information on Destinations

For more information on alert routing order, modifying or deleting destinations, and workflow automation, please see the Panther docs: Destinations.