# Panther Integration

[Panther](https://panther.com/) is a modern security information and event management (SIEM) platform that helps teams detect, investigate, and respond to threats at cloud scale. With the ilert integration, Panther can automatically send alerts to ilert, enabling real-time incident response through multi-channel notifications and on-call scheduling.

## In ilert: Create a Panther alert source&#x20;

1. Go to **Alert sources** -> **Alert sources** and click **Create new alert source**.

   <figure><img src="https://3394882078-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M76ygPnS4HUcFSX8ulm%2Fuploads%2FjX0cS4q7woTXKajZmc1W%2FScreenshot%202023-08-28%20at%2010.21.10.png?alt=media&#x26;token=8ef3666b-84eb-4b51-abee-f07303313941" alt=""><figcaption></figcaption></figure>
2. Search for **Panther** in the search field, click the Panther tile, and then **Next**.&#x20;

   <figure><img src="https://3394882078-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M76ygPnS4HUcFSX8ulm%2Fuploads%2FlXzQlJpaTFSR49AZk0xA%2FScreenshot%202023-08-28%20at%2010.24.23.png?alt=media&#x26;token=cffeacb4-57b9-47d4-827d-b0f6b1afd914" alt=""><figcaption></figcaption></figure>
3. Give your alert source a name, optionally assign teams, and click **Next**.
4. Select an **escalation policy** by creating a new one or assigning an existing one.

   <figure><img src="https://3394882078-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M76ygPnS4HUcFSX8ulm%2Fuploads%2FNnuZqONaIhbOf6fn4OkZ%2FScreenshot%202023-08-28%20at%2011.37.47.png?alt=media&#x26;token=8a74f7b5-5bd2-4eea-97fa-1c1dbb041333" alt=""><figcaption></figcaption></figure>
5. Select your [Alert grouping](https://docs.ilert.com/alerting/configure-alerting/alert-sources#alert-grouping) preference and click **Continue setup**. You may click **Do not group alerts** for now and change it later.&#x20;

   <figure><img src="https://3394882078-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M76ygPnS4HUcFSX8ulm%2Fuploads%2FueugN4JgHn1c90ggFA6u%2FScreenshot%202023-08-28%20at%2011.38.24.png?alt=media&#x26;token=b8009daf-3ca8-4264-a6fa-e42ef7333205" alt=""><figcaption></figcaption></figure>
6. The next page shows additional settings, such as customer alert templates or notification priority. Click **Finish setup** for now.
7. On the final page, an API key and/or webhook URL will be generated. You will need it later.

<figure><img src="https://3394882078-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M76ygPnS4HUcFSX8ulm%2Fuploads%2FbmCQhFNkUioVGlcCTTG7%2Fil-1.png?alt=media&#x26;token=4d70408b-8a57-442a-828a-8676efb1e94e" alt=""><figcaption></figcaption></figure>

## In Panther: Create an Alert Destination

1. On the sidebar, click on **Configure** -> **Alert Destinations**.

<figure><img src="https://3394882078-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M76ygPnS4HUcFSX8ulm%2Fuploads%2FfjHW6gHGF84JE5fhe5wb%2F1.png?alt=media&#x26;token=04548db8-f288-49f1-8c20-8a0122662eeb" alt=""><figcaption></figcaption></figure>

2. Now select **Custom Webhook**.

<figure><img src="https://3394882078-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M76ygPnS4HUcFSX8ulm%2Fuploads%2F8LcKKGJwtq2MQSCNiKOf%2F2.png?alt=media&#x26;token=5a9886d8-7313-4f28-ab16-de78574ef393" alt=""><figcaption></figcaption></figure>

3. Enter a **Display Name**.
4. Enter the in ilert previous generated alert source url into the **Custom Webhook URL** field.
5. Click **Add Destination** to finish the setup.

<figure><img src="https://3394882078-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M76ygPnS4HUcFSX8ulm%2Fuploads%2FeAsRm9SV84HI7YFVTj5v%2F3.png?alt=media&#x26;token=71c7335c-327f-41ba-8c9b-7006a7350b1b" alt=""><figcaption></figcaption></figure>

6. Optional: Send a test alert.

<figure><img src="https://3394882078-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M76ygPnS4HUcFSX8ulm%2Fuploads%2FFPiab9zjU64Y0q42fN2H%2F4.png?alt=media&#x26;token=f6a46ea6-2d95-4ce9-b22f-e36ce3d94fcb" alt=""><figcaption></figcaption></figure>

## FAQ <a href="#faq" id="faq"></a>

**Will alerts in ilert be resolved automatically?**

No, unfortunately Panther is not compatible with ilert's resolve event.
