Skip to content
Notis

Flag risky IP reports in Slack

Give incoming IP reports a quick reputation check and a visible signal in the Slack message they came from.

Trigger

Webhook received

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

Action

Add reaction to message

Adds a specified emoji reaction to an existing message in a slack channel, identified by its timestamp; does not remove or retrieve reactions.

Why this helps

Suspicious IPs can get buried in busy Slack conversations before anyone checks their reputation.

  • Surface concerning IP reports where the team already discusses them.
  • Reduce manual copy and paste between threat checks and Slack.
  • Keep a human review step for interpreting reputation results.

Setup

Build it in a few focused steps.

  • 1Connect Abuselpdb and Slack once in the Notis portal.
  • 2Create an automation and describe the IP check and reaction outcome in one instruction.
  • 3Choose the Notis webhook trigger and send the IP plus the Slack channel and message timestamp in its request.
  • 4Choose where run reports go, then test with one real report and verify the reaction.

Questions about this workflow

What information must the webhook include?

Include the IP address and the Slack channel and message timestamp for the report to react to. Notis needs those message details to identify the Slack message.

Will every checked IP get a reaction?

Set the instruction to react only when the Abuselpdb result meets your stated review criteria. The reputation threshold should be supplied in your instruction.

Does this automatically report an IP as abusive?

No. This workflow checks reputation and reacts to the Slack message. It does not submit an abuse report.

When this happens · Trigger

Do this · Action

Supported Triggers and Actions

Notis builds workflows that link Abuselpdb to Slack. A trigger fires from one place; an action lands in another.

Abuselpdb triggers

Slack actions

Recurring trigger

Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.

TriggerScheduled

Set snooze duration

Deprecated: turns on do not disturb mode for the current user, or changes its duration. use `set dnd duration` instead.

ActionInstant

Webhook trigger

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

TriggerInstant

Add a custom emoji to a Slack team

Deprecated: adds a custom emoji to a slack workspace given a unique name and an image url. use `add emoji` instead.

ActionInstant

Add an emoji alias

Adds an alias for an existing custom emoji in a slack enterprise grid organization.

ActionInstant

Add a remote file

Adds a reference to an external file (e.g., google drive, dropbox) to slack for discovery and sharing, requiring a unique `external id` and an `external url` accessible by slack.

ActionInstant

Add a star to an item

Stars a channel, file, file comment, or a specific message in slack.

ActionInstant

Add call participants

Registers new participants added to a slack call.

ActionInstant

Add emoji

Adds a custom emoji to a slack workspace given a unique name and an image url; subject to workspace emoji limits.

ActionInstant

Add reaction to message

Adds a specified emoji reaction to an existing message in a slack channel, identified by its timestamp; does not remove or retrieve reactions.

ActionInstant

Connect any two apps with Notis in the middle.

Abuselpdb and Slack, or any other combination from 1,000+ integrations.

When this happens · Trigger

Do this · Action

Save your first hour today.

7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Slack.