Use the LogicMonitor Edwin AI Microsoft Teams (MS Teams) Integration to send notifications to your MS Teams environment from Edwin AI. Creating an MS Teams messaging workflow, and configuring Edwin AI actions and rules to trigger a message, provides automated response and cross-platform incident correlation in real time using a custom MS Teams workflow.

Requirements for Configuring Edwin AI MS Teams Integration

To configure the Edwin AI MS Teams Integration, you need the following:

Configuring the Edwin AI MS Teams Integration in MS Teams

  1. Create a webhook workflow in MS Teams.
    For more information, see Creating Microsoft Teams Workflows for Integration from Microsoft.
  2. Save the webhook URL from the completed workflow in a secure location.

MS Teams can now receive notification details from Edwin AI.

Configuring MS Teams Integration Credentials in Edwin AI

  1. In LogicMonitor, navigate to Edwin AI and select Settings > Integrations.
  2. Select Configure for Microsoft Teams.
  3. Enter a Name and Description for your MS Teams integration.
  4. Copy and paste the MS Teams webhook URL into the URL field.
  5. Select Save.
MS teams integration configuration

Edwin AI includes MS Teams API credentials as part of outgoing payloads. Verify and manage integrations by selecting your configured integrations from the Integrations settings.

Configuring an MS Teams Alert Action

  1. Create a new Edwin AI Action.
    For more information, see Creating and Editing Action in Edwin AI.
  2. From the Source dropdown menu, select “alerts.”
  3. From the Add Action dropdown menu, select “Send message to a Microsoft Teams Channel.”
  4. In the Mapped Fields section, add mapped fields to specify what information to include in the MS Teams notification.
    You can use the following supported fields:
ValueDescription
CIThe configuration item (host or monitored resource) associated with the alert, such as a hostname or IP address.
Maps to eventCi in Edwin AI CEF.
SeverityThe numeric severity of the event (0 = Clear, 1 = Information, 2 = Warning, 3 = Minor, 4 = Major, 5 = Critical).
Maps to eventSeverity in Edwin AI CEF.
DetailsA description of the event.
Maps to eventDetails in Edwin AI CEF.
TitleThe title of the the alert condition.
Maps to eventName in Edwin AI CEF.
URLA hyperlink back to the source alert or Edwin AI insight for quick reference.
Maps to a CEF *_link field or the Edwin AI permanent URL.
  1. Select Submit.

Edwin AI now sends content from Mapped Fields to an MS Teams channel when the conditions are met.

Create MS Teams Action

Configure the conditions for this action in a new Edwin AI Rule. For more information, see Configuring an MS Teams Alert Rule.

Configuring an MS Teams Alert Rule

  1. Create a new Edwin AI Rule.
    For more information, see Edwin AI Rules.
  2. From the Add Interactive Action dropdown menu, select the action created to send MS team messages.
    For more information, see Configuring an MS Teams Alert Action.
  3. In the Filters section, configure the rule conditions that send an MS Teams message.
    For example, to send a message for any Edwin alert that is still open, do the following:
    1. Select Add Condition
    2. In the Field dropdown menu, select “Escalation.”
    3. In the Operator dropdown menu, Select “Not equals.”
    4. In the Value field, enter “closed.”

Note: The Value field is case sensitive

  1. Select Submit.
  2. To trigger the rule and action from an alert record, do the following:
    1. Navigate to Edwin AI > Explore.
    2. Find an alert record that has not been closed.
    3. On the Actions record, select the action you created.

The MS Teams channel receives the automated alert message any time you trigger the alert.

Note: You must manually trigger the rule from an alert record any time you want to send an MS Teams message.