Arcsight - Get events related to the Case
Get the Case's Arcsight ResourceID from the FetchID field, or the "ID" label. If neither is there, ask user for the ID. Use the resource ID to get full data for the case, the correlated/aggregate events underneath it, and all base events underneath them.
- Pack
- ArcSightESM
- Tasks
- 14
Commands used
- as-get-all-cases
- as-get-case-event-ids
- as-get-security-events
- setIncident