Skip to content
Notis

Add location context to Slack IP incident reports

When a channel report includes one or more IPs, get their geolocation details together so your team can focus on the response.

Trigger

Channel Message Received

Triggered when a message is posted in a Slack channel (public, private, or multi-party IM). Does NOT match direct messages.

Action

Bulk IP Geolocation

Tool to retrieve geolocation information for multiple IP addresses in bulk. Use when processing up to 1000 IPs at once.

Why this helps

Incident details arrive amid channel chatter, and manually checking each IP interrupts response work.

  • Enriches incident reports with location context
  • Handles multiple reported IPs in one lookup
  • Reduces manual context switching during triage

Setup

Build it in a few focused steps.

  • 1Connect Slack and Ip2location io to Notis once in the portal.
  • 2Open Automations and create a new automation, or ask Notis conversationally.
  • 3Use one plain-language instruction: when a Slack channel incident report includes IP addresses, look them up in bulk and summarize the location details in the run report.
  • 4Pick Channel Message Received as the trigger and choose where Notis should report runs.
  • 5Test with a real incident message containing an IP address.

Questions about this workflow

Does this trigger on direct messages?

No. Channel Message Received does not match direct messages.

Do I need to map IP fields?

No. Describe in plain language how Notis should find IP addresses in the message.

When this happens · Trigger

Do this · Action

Supported Triggers and Actions

Notis builds workflows that link Slack to Ip2location io. A trigger fires from one place; an action lands in another.

Slack triggers

Ip2location io actions

Recurring trigger

Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.

TriggerScheduled

Bulk IP Geolocation

Tool to retrieve geolocation information for multiple IP addresses in bulk. Use when processing up to 1000 IPs at once.

ActionInstant

Webhook trigger

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

TriggerInstant

Domain WHOIS Lookup

Tool to retrieve WHOIS information for a given domain. Use when you need domain registration and contact details via IP2WHOIS API.

ActionInstant

New Channel Created Trigger

Triggered when a new channel is created in Slack.

TriggerInstant

Get API Key

Tool to retrieve the configured API key. Use when authentication is needed for IP2Location.io requests.

ActionInstant

Channel Message Received

Triggered when a message is posted in a Slack channel (public, private, or multi-party IM). Does NOT match direct messages.

TriggerInstant

IP2WHOIS Hosted Domain

Tool to retrieve hosted domain names by IP address. Use when you need to list domains hosted on a given IP. Call after confirming the IP.

ActionInstant

Direct Message Received

Triggered when a new direct message (DM) is sent to a user in Slack. Catches all DMs across all DM channels.

TriggerInstant

Message Reaction Added

Triggered when a reaction is added to a message in Slack. Supports optional filtering by channel and emoji name.

TriggerInstant

Message Reaction Removed

Triggered when a reaction is removed from a message in Slack. Supports optional filtering by channel and emoji name.

TriggerInstant

Reaction Added Trigger

DEPRECATED: use `SLACK_MESSAGE_REACTION_ADDED` instead. Triggered when a reaction is added to a message in Slack.

TriggerInstant

Connect any two apps with Notis in the middle.

Slack and Ip2location io, or any other combination from 1,000+ integrations.

When this happens · Trigger

Do this · Action

Save your first hour today.

7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Ip2location io.