Slack event alert types

Chronicle provides over 25 event types that can be configured on the Events page in the Chronicle dashboard. Here's an overview of the available events and why customers find them useful.

Apps

App Added / Updated / Granted Rights
Triggered when an app is added to your workspace, updated, or granted new permissions by a user — typically as a result of adding an app to Slack.

  • Who uses this? Security-conscious teams of any size with several users who have permission to add apps to Slack.
  • Why set up this alert? Knowing when a new app is added or granted unexpected permissions is key to mitigating the risk apps can pose to your workspace.

App Removed / Disabled
Triggered when an app is removed or disabled in your workspace.

  • Who uses this? Security-conscious teams of any size with several users who have permission to remove apps from Slack.
  • Why set up this alert? Keep an exact log of when apps are removed or disabled, and get alerted if a widely used app is unexpectedly disabled or removed.

Channels

Channel Archived / Unarchived
Triggered when a channel is archived or unarchived by a user.

  • Who uses this? Teams who rarely create or archive channels.
  • Why set up this alert? A centralized log of channel archives and unarchives helps admins spot unusual behavior and notice when an old channel is brought back into use.

Channel Created
Triggered when a channel is created.

  • Who uses this? Teams that create channels for specific circumstances, such as customer inquiries or escalating internal issues.
  • Why set up this alert? Maintain a log of exactly when and by whom a channel was created, to understand where discussions are happening.

Channel Deleted
Triggered when a channel is deleted.

  • Who uses this? Teams that want channels only archived, never deleted, to prevent messages from being lost.
  • Why set up this alert? Get alerted when a channel is deleted, and track when and how often deletions occur.

Channel Renamed
Triggered when a channel is renamed.

  • Who uses this? Teams that maintain specific channel naming conventions.
  • Why set up this alert? Keep an eye on channel names so admins are quickly alerted to changes and can enforce naming requirements.

Emojis

Emoji Deleted / Uploaded
Triggered when a user adds a new emoji or removes an existing one.

  • Who uses this? Teams that want to monitor emojis for workplace appropriateness.
  • Why set up this alert? Let admins review new emojis as they're added to ensure they're appropriate.

Files

File Public Link Created / Restricted
Triggered when a user shares a file publicly or removes a file's public link.

  • Who uses this? Teams that use public links to share files from Slack.
  • Why set up this alert? Monitor users sharing files that shouldn't be public, or restricting access to files that need to stay public.

File Shared / Unshared
Triggered when a user shares a file in a channel, or deletes the message sharing that file.

  • Who uses this? Teams that treat files in Slack as sensitive.
  • Why set up this alert? Lets admins monitor when files are shared in other channels, helping prevent sensitive files from reaching users who shouldn't have access.

File Created
Triggered when a file is created in your Slack workspace.

  • Who uses this? Teams that upload files only in specific circumstances, or that want a log of file creation.
  • Why set up this alert? Get a single place to see when files are created and by whom.

File Deleted
Triggered when a file is deleted from Slack by a user.

  • Who uses this? Teams that discourage deleting files from Slack to preserve data.
  • Why set up this alert? Alert admins when a user deletes a file that can't be recovered.

Guests

Guest Enabled / Joined
Triggered when a guest is re-enabled or joins a workspace for the first time.

  • Who uses this? Teams that invite many guests, such as contractors, to collaborate in specific channels.
  • Why set up this alert? Monitor guests as they're added to confirm they have only the necessary privileges and aren't unexpectedly enabled.

Guest Disabled
Triggered when a guest is disabled.

  • Who uses this? Teams that invite many guests, such as contractors, to collaborate in specific channels.
  • Why set up this alert? Ensure guests are properly disabled once they should no longer have access to your workspace.

Users

User Enabled / Joined
Triggered when a user is re-enabled or joins your workspace.

  • Who uses this? Teams of any size that want to know when a user gains access to their Slack workspace.
  • Why set up this alert? Slack has had past exploits allowing users to invite themselves to a workspace — alerts here are vital for preventing unauthorized access.

User Deleted
Triggered when a user is deleted from your workspace.

  • Who uses this? Teams that offboard users often and want a record of account removals.
  • Why set up this alert? Know exactly when a user has been removed from Slack and no longer has access.

Username Changed
Triggered when a user changes their Slack username.

  • Who uses this? Teams that treat usernames as fixed and discourage users from changing them.
  • Why set up this alert? Know exactly when and who changed a username, to address any effects that change might cause.

Admins

Admin Added / Owner Added
Triggered when a new admin or owner is promoted in a Slack workspace.

  • Who uses this? Teams of any size that carefully control who manages their Slack workspace.
  • Why set up this alert? Knowing when a user gains the highest level of access is crucial to ensuring only those who need those privileges have them.

Admin Removed / Owner Removed
Triggered when an admin or owner is demoted in a Slack workspace.

  • Who uses this? Teams of any size that carefully control who manages their Slack workspace.
  • Why set up this alert? Ensuring users who should retain privileged access don't lose it helps prevent access control issues before they start.