Skip to content
Notis

Get context on suspicious login IPs shared in Slack DMs

Turn a login concern sent directly to you into one organized IP profile for your next step.

Trigger

Direct Message Received

Triggered when a new direct message (DM) is sent to a user in Slack. Catches all DMs across all DM channels.

Action

IPData Lookup IP V1

Tool to lookup comprehensive IP information (geolocation, network, company, and threat data) in one call. Use when you need all IP insights together.

Why this helps

A security concern in a DM can be easy to lose among unrelated messages and follow-ups.

  • Collect geolocation, network, company, and threat context in one lookup.
  • Keep the original concern as the trigger for investigation.
  • Spend less time reopening the same message to find the reported IP.

Setup

Build it in a few focused steps.

  • 1Connect Slack and Ipdata co to Notis once through the portal.
  • 2Create a portal automation or tell Notis in plain language to investigate suspicious login IPs sent by DM.
  • 3Write one instruction asking Notis to recognize a suspicious-login report containing an IP, run a comprehensive Ipdata lookup, and report the result.
  • 4Choose Direct Message Received as the trigger and select a channel for run reports.
  • 5Test with a real DM-style example containing a login concern and an IP.

Questions about this workflow

Will it act on ordinary DMs?

The instruction should focus on DMs that describe a suspicious login and include an IP. You choose the Direct Message Received event as the trigger.

What information does the comprehensive lookup provide?

The Ipdata co action can return geolocation, network, company, and threat information for the supplied IP.

When this happens · Trigger

Do this · Action

Supported Triggers and Actions

Notis builds workflows that link Slack to Ipdata co. A trigger fires from one place; an action lands in another.

Slack triggers

Ipdata co actions

Recurring trigger

Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.

TriggerScheduled

Advanced ASN Lookup

Tool to perform advanced ASN lookup returning prefixes, peers, and registry details. Use after confirming ASN number when detailed ASN info is required.

ActionInstant

Webhook trigger

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

TriggerInstant

Get Carrier Data for an IP

Tool to return mobile carrier data for a specific IP. Use when you need carrier name, MCC, and MNC for an IP address.

ActionInstant

New Channel Created Trigger

Triggered when a new channel is created in Slack.

TriggerInstant

EU-specific IP lookup

Tool to lookup a specific IP address via the EU-only data residency endpoint. Use when you need IP lookup processed and stored within the EU.

ActionInstant

Channel Message Received

Triggered when a message is posted in a Slack channel (public, private, or multi-party IM). Does NOT match direct messages.

TriggerInstant

IPData: Calling Code

Tool to fetch the international calling_code for an IP's country. Use when you need only the calling code field from ipdata_co.

ActionInstant

Direct Message Received

Triggered when a new direct message (DM) is sent to a user in Slack. Catches all DMs across all DM channels.

TriggerInstant

IPDATA Field Carrier

Tool to return only the carrier object for the calling IP. Use when you need mobile carrier details of a specific IP.

ActionInstant

Message Reaction Added

Triggered when a reaction is added to a message in Slack. Supports optional filtering by channel and emoji name.

TriggerInstant

Get City from IP

Tool to return only city for an IP. Use when only the city name is required.

ActionInstant

Message Reaction Removed

Triggered when a reaction is removed from a message in Slack. Supports optional filtering by channel and emoji name.

TriggerInstant

IPData: Continent Code

Tool to return only continent_code for an IP. Use when only the continent code is required.

ActionInstant

Reaction Added Trigger

DEPRECATED: use `SLACK_MESSAGE_REACTION_ADDED` instead. Triggered when a reaction is added to a message in Slack.

TriggerInstant

Get Continent Name from IP

Tool to return only continent name for an IP. Use when only the continent name is required.

ActionInstant

Connect any two apps with Notis in the middle.

Slack and Ipdata co, or any other combination from 1,000+ integrations.

When this happens · Trigger

Do this · Action

Save your first hour today.

7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Ipdata co.