ASM Alert Layout

A layout used for ASM alerts in XSIAM.

Cortex Attack Surface Management Incident

Details

IDASM Alert Layout
Groupincident
Version-1
From Version6.10.0

Layout Structure

Legacy Summary 0 sections

No sections defined.

Alert Info 11 sections

Alert Details

Field IDPosition
severity Col 0-2, Height: 26
owner Col 0-2, Height: 26
occurred Col 0-2, Height: 26
asmassetid Col 0-2, Height: 26
asmserviceid Col 0-2, Height: 26
asmassethierarchy Col 0-2, Height: 26
alert_sub_type Col 2-4, Height: 26
playbookid Col 2-4, Height: 26

Work Plan

Closing Information

Field IDPosition
closereason Col 0-2, Height: 26
closenotes Col 0-2, Height: 52

System IDs

Field IDPosition
asmsystemids Col 0-6, Height: 106

Tags

Field IDPosition
asmtags Col 0-6, Height: 106

Development or Production

Field IDPosition
asmdevcheckdetails Col 0-6, Height: 106
asmprivateip Col 0-6, Height: 106

Alert Summary

Field IDPosition
asmalertsummary Col 0-6, Height: 106

Service Owners

Field IDPosition
asmserviceowner Col 0-6, Height: 106

AttackSurface Rule Information

Field IDPosition
asmattacksurfaceruledescription Col 0-4, Height: 106
asmattacksurfaceruleremediationguidance Col 0-4, Height: 106
asmattacksurfacerulecategory Col 0-2, Height: 53
asmattacksurfacerulepriority Col 0-2, Height: 53

Playbook Stage Completion Times

Field IDPosition
asmplaybookstage Col 0-2, Height: 106

RCS Scan

Field IDPosition
Col 0-2, Height: 44
Col 0-2, Height: 26
War Room 0 sections

No sections defined.

Work Plan 0 sections

No sections defined.

Canvas 0 sections

No sections defined.

{
    "detailsV2": {
        "tabs": [
            {
                "id": "summary",
                "name": "Legacy Summary",
                "type": "summary"
            },
            {
                "id": "caseinfoid",
                "name": "Alert Info",
                "sections": [
                    {
                        "displayType": "ROW",
                        "h": 2,
                        "i": "caseinfoid-fce71720-98b0-11e9-97d7-ed26ef9e46c8",
                        "isVisible": true,
                        "items": [
                            {
                                "endCol": 2,
                                "fieldId": "severity",
                                "height": 26,
                                "id": "incident-severity-field",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "owner",
                                "height": 26,
                                "id": "incident-owner-field",
                                "index": 1,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "occurred",
                                "height": 26,
                                "id": "incident-occurred-field",
                                "index": 2,
                                "listId": "caseinfoid-ac32f620-a0b0-11e9-b27f-13ae1773d289",
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "asmassetid",
                                "height": 26,
                                "id": "8c56d510-533f-11ee-820c-45f1b5d5b555",
                                "index": 3,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "asmserviceid",
                                "height": 26,
                                "id": "93118cb0-533f-11ee-820c-45f1b5d5b555",
                                "index": 4,
                                "listId": "caseinfoid-fce71720-98b0-11e9-97d7-ed26ef9e46c8",
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "asmassethierarchy",
                                "height": 26,
                                "id": "09a096e0-82a8-11ee-86b2-33ec75417734",
                                "index": 5,
                                "listId": "caseinfoid-fce71720-98b0-11e9-97d7-ed26ef9e46c8",
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 4,
                                "fieldId": "alert_sub_type",
                                "height": 26,
                                "id": "d54fa3d0-5341-11ee-820c-45f1b5d5b555",
                                "index": 0,
                                "listId": "caseinfoid-fce71720-98b0-11e9-97d7-ed26ef9e46c8",
                                "sectionItemType": "field",
                                "startCol": 2
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 4,
                                "fieldId": "playbookid",
                                "height": 26,
                                "id": "incident-playbookId-field",
                                "index": 1,
                                "listId": "caseinfoid-fce71720-98b0-11e9-97d7-ed26ef9e46c8",
                                "sectionItemType": "field",
                                "startCol": 2
                            }
                        ],
                        "maxW": 3,
                        "moved": false,
                        "name": "Alert Details",
                        "static": false,
                        "w": 2,
                        "x": 0,
                        "y": 0
                    },
                    {
                        "displayType": "ROW",
                        "h": 3,
                        "i": "caseinfoid-6aabad20-98b1-11e9-97d7-ed26ef9e46c8",
                        "maxW": 3,
                        "moved": false,
                        "name": "Work Plan",
                        "static": false,
                        "type": "workplan",
                        "w": 1,
                        "x": 2,
                        "y": 2
                    },
                    {
                        "displayType": "ROW",
                        "h": 1,
                        "i": "caseinfoid-88e6bf70-a0b1-11e9-b27f-13ae1773d289",
                        "isVisible": true,
                        "items": [
                            {
                                "endCol": 2,
                                "fieldId": "closereason",
                                "height": 26,
                                "id": "incident-closeReason-field",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "closenotes",
                                "height": 52,
                                "id": "incident-closeNotes-field",
                                "index": 1,
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "moved": false,
                        "name": "Closing Information",
                        "static": false,
                        "w": 1,
                        "x": 2,
                        "y": 5
                    },
                    {
                        "displayType": "ROW",
                        "h": 2,
                        "hideName": true,
                        "i": "caseinfoid-183f7b90-5340-11ee-820c-45f1b5d5b555",
                        "items": [
                            {
                                "endCol": 6,
                                "fieldId": "asmsystemids",
                                "height": 106,
                                "id": "f24e63a0-5340-11ee-820c-45f1b5d5b555",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "System IDs",
                        "static": false,
                        "w": 3,
                        "x": 0,
                        "y": 12
                    },
                    {
                        "displayType": "ROW",
                        "h": 2,
                        "hideName": true,
                        "i": "caseinfoid-cdd82151-5340-11ee-820c-45f1b5d5b555",
                        "items": [
                            {
                                "endCol": 6,
                                "fieldId": "asmtags",
                                "height": 106,
                                "id": "cdd82150-5340-11ee-820c-45f1b5d5b555",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Tags",
                        "static": false,
                        "w": 3,
                        "x": 0,
                        "y": 14
                    },
                    {
                        "columns": [
                            {
                                "displayName": "IP",
                                "fieldCalcScript": "",
                                "isDefault": true,
                                "isReadOnly": false,
                                "key": "ip",
                                "orgType": "shortText",
                                "required": false,
                                "script": "",
                                "selectValues": null,
                                "type": "shortText",
                                "width": 210
                            },
                            {
                                "displayName": "Source",
                                "fieldCalcScript": "",
                                "isDefault": true,
                                "isReadOnly": false,
                                "key": "source",
                                "orgType": "shortText",
                                "required": false,
                                "script": "",
                                "selectValues": null,
                                "type": "shortText",
                                "width": 150
                            }
                        ],
                        "displayType": "ROW",
                        "h": 2,
                        "hideName": true,
                        "i": "caseinfoid-6dc300e2-5341-11ee-820c-45f1b5d5b555",
                        "items": [
                            {
                                "dropEffect": "move",
                                "endCol": 6,
                                "fieldId": "asmdevcheckdetails",
                                "height": 106,
                                "id": "6dc300e1-5341-11ee-820c-45f1b5d5b555",
                                "index": 0,
                                "listId": "caseinfoid-fbb3ecc0-533c-11ee-a9fe-dd4972c4236a",
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 6,
                                "fieldId": "asmprivateip",
                                "height": 106,
                                "id": "33ca32f0-82a8-11ee-86b2-33ec75417734",
                                "index": 1,
                                "listId": "caseinfoid-6dc300e2-5341-11ee-820c-45f1b5d5b555",
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Development or Production",
                        "static": false,
                        "w": 3,
                        "x": 0,
                        "y": 16
                    },
                    {
                        "columns": [
                            {
                                "displayName": "Link",
                                "fieldCalcScript": "",
                                "isDefault": true,
                                "isReadOnly": false,
                                "key": "link",
                                "orgType": "shortText",
                                "required": false,
                                "script": "",
                                "selectValues": null,
                                "type": "shortText",
                                "width": 973
                            },
                            {
                                "displayName": "EntryID",
                                "fieldCalcScript": "",
                                "isDefault": true,
                                "isReadOnly": false,
                                "key": "entryid",
                                "orgType": "shortText",
                                "required": false,
                                "script": "",
                                "selectValues": null,
                                "type": "shortText",
                                "width": 150
                            }
                        ],
                        "displayType": "ROW",
                        "h": 2,
                        "hideName": true,
                        "i": "caseinfoid-02eb57d0-7f16-11ee-808c-b59d0762257e",
                        "items": [
                            {
                                "endCol": 6,
                                "fieldId": "asmalertsummary",
                                "height": 106,
                                "id": "bd65fd90-7f16-11ee-808c-b59d0762257e",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Alert Summary",
                        "static": false,
                        "w": 3,
                        "x": 0,
                        "y": 10
                    },
                    {
                        "displayType": "ROW",
                        "h": 2,
                        "hideName": true,
                        "i": "caseinfoid-6a26a670-7f16-11ee-808c-b59d0762257e",
                        "items": [
                            {
                                "endCol": 6,
                                "fieldId": "asmserviceowner",
                                "height": 106,
                                "id": "89be6b30-7f16-11ee-808c-b59d0762257e",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Service Owners",
                        "static": false,
                        "w": 3,
                        "x": 0,
                        "y": 8
                    },
                    {
                        "displayType": "CARD",
                        "h": 4,
                        "hideName": false,
                        "i": "caseinfoid-e272fa30-84bf-11ee-9fdb-a150b092ebe5",
                        "items": [
                            {
                                "dropEffect": "move",
                                "endCol": 4,
                                "fieldId": "asmattacksurfaceruledescription",
                                "height": 106,
                                "id": "f0c95390-84bf-11ee-9fdb-a150b092ebe5",
                                "index": 0,
                                "listId": "caseinfoid-e272fa30-84bf-11ee-9fdb-a150b092ebe5",
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 4,
                                "fieldId": "asmattacksurfaceruleremediationguidance",
                                "height": 106,
                                "id": "1e16e490-84c3-11ee-9fdb-a150b092ebe5",
                                "index": 1,
                                "listId": "caseinfoid-e272fa30-84bf-11ee-9fdb-a150b092ebe5",
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "asmattacksurfacerulecategory",
                                "height": 53,
                                "id": "ee88b260-84bf-11ee-9fdb-a150b092ebe5",
                                "index": 2,
                                "listId": "caseinfoid-e272fa30-84bf-11ee-9fdb-a150b092ebe5",
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "asmattacksurfacerulepriority",
                                "height": 53,
                                "id": "ef984da0-84bf-11ee-9fdb-a150b092ebe5",
                                "index": 3,
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "AttackSurface Rule Information",
                        "static": false,
                        "w": 2,
                        "x": 0,
                        "y": 2
                    },
                    {
                        "displayType": "ROW",
                        "h": 2,
                        "hideName": false,
                        "i": "caseinfoid-f5adcaa0-889b-11ee-97f0-7be991a43669",
                        "items": [
                            {
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "asmplaybookstage",
                                "height": 106,
                                "id": "52d4d2e0-82a8-11ee-86b2-33ec75417734",
                                "index": 0,
                                "listId": "caseinfoid-fce71720-98b0-11e9-97d7-ed26ef9e46c8",
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Playbook Stage Completion Times",
                        "static": false,
                        "w": 1,
                        "x": 2,
                        "y": 6
                    },
                    {
                        "displayType": "ROW",
                        "h": 2,
                        "hideName": false,
                        "i": "caseinfoid-b2f782f0-eb15-11ee-9523-d3c564a4bc8a",
                        "items": [
                            {
                                "args": {
                                    "alert_internal_id": {
                                        "simple": "${alert.id}"
                                    },
                                    "attack_surface_rule_id": {
                                        "simple": "${alert.asmattacksurfaceruleid}"
                                    },
                                    "service_id": {
                                        "simple": "${alert.asmserviceid}"
                                    }
                                },
                                "endCol": 2,
                                "fieldId": "",
                                "height": 44,
                                "id": "c7508e90-eb15-11ee-9523-d3c564a4bc8a",
                                "index": 0,
                                "name": "RCS Scan Start",
                                "scriptId": "RCSScan",
                                "sectionItemType": "button",
                                "startCol": 0
                            },
                            {
                                "args": {
                                    "scan_id": {
                                        "simple": "${RCSScanId}"
                                    }
                                },
                                "endCol": 2,
                                "fieldId": "",
                                "height": 26,
                                "id": "f527de70-eb17-11ee-9523-d3c564a4bc8a",
                                "index": 1,
                                "name": "RCS Scan Status",
                                "scriptId": "Cortex Attack Surface Management|||asm-get-remediation-confirmation-scan-status",
                                "sectionItemType": "button",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "RCS Scan",
                        "static": false,
                        "w": 1,
                        "x": 2,
                        "y": 0
                    }
                ],
                "type": "custom"
            },
            {
                "id": "warRoom",
                "name": "War Room",
                "type": "warRoom"
            },
            {
                "id": "workPlan",
                "name": "Work Plan",
                "type": "workPlan"
            },
            {
                "id": "canvas",
                "name": "Canvas",
                "type": "canvas",
                "hidden": false
            }
        ]
    },
    "group": "incident",
    "id": "ASM Alert Layout",
    "name": "ASM Alert Layout",
    "system": false,
    "version": -1,
    "fromVersion": "6.10.0",
    "description": "A layout used for ASM alerts in XSIAM."
}