Quick Overview
This workflow polls the 1Password Events API every 15 minutes for recent audit events, detects vault export activity, creates an alert in TheHive, and posts a notification to a Slack channel with the export details and a link to the alert.
How it works
- Runs every 15 minutes on a schedule.
- Requests the last 24 hours of audit events from the 1Password Events API.
- Splits the returned events into individual items and keeps only events where the object type is
vault and the action contains export.
- Extracts key details (user, email, vault name/ID, timestamp, source IP, and event UUID) and prepares a TheHive base URL for link building.
- Creates a new TheHive alert with severity/TLP/PAP settings, tags, and a description containing the vault export context.
- Posts a Slack message to the selected channel summarizing the incident and linking directly to the created TheHive alert.
Setup
- Create and configure a 1Password Events API token with access to the
auditevents feature and add it as an HTTP request credential used by the workflow.
- Add TheHive credentials in n8n and set the correct TheHive instance URL, then ensure alert creation permissions are granted.
- Add Slack OAuth2 credentials and select the destination Slack channel for the notification.
- Replace the placeholder value for the TheHive base URL in the export-details step so the Slack alert link points to your TheHive UI.