| 1 | --- |
| 2 | title: Alerting → Shuffle (notifications & automation) |
| 3 | description: How CoPilot triggers Shuffle workflows for alert/case notifications and automation. |
| 4 | --- |
| 5 | |
| 6 | # Alerting → Shuffle (notifications & automation) |
| 7 | |
| 8 | CoPilot integrates with **Shuffle** to run automation/playbooks and send notifications (Teams/Slack/Jira/email/webhooks) when: |
| 9 | |
| 10 | - a new **Alert** is ingested into **Incident Management**, or |
| 11 | - an analyst manually triggers a **Case** workflow. |
| 12 | |
| 13 | This is the recommended way to extend CoPilot alerting into external systems without needing a custom integration inside CoPilot for every downstream tool. |
| 14 | |
| 15 | ## Video walkthrough |
| 16 | |
| 17 | <iframe width="560" height="315" src="https://www.youtube.com/embed/Ko5jLfkSCrk?si=YHEv-wHYhY3FuRUe" title="Revolutionize Your SIEM Alerts: Integrate CoPilot & Shuffle" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen></iframe> |
| 18 | |
| 19 | > 🎥 [Revolutionize Your SIEM Alerts: Integrate CoPilot & Shuffle](https://youtu.be/Ko5jLfkSCrk?si=YHEv-wHYhY3FuRUe) |
| 20 | |
| 21 | ## Read the full guide |
| 22 | |
| 23 | - **CoPilot ↔ Shuffle Integration (Admin/Operator)**: ../../shuffle-integration.md |
| 24 | |
| 25 | ## Related alerting pages |
| 26 | |
| 27 | - Graylog management (detections): ./graylog-management.md |
| 28 | - Incident sources (mapping context): ./incident-sources.md |
| 29 | - Alerts (SIEM view): ./alerts-siem.md |