Autofocus - Traffic Indicators Hunting

Deprecated. No available replacement. The playbook queries the PANW Autofocus session and samples log data for traffic indicators such as URLs, IP addresses, and domains. A simple search mode queries Autofocus based on the traffic indicators specified in the playbook inputs. Advanced search mode queries can also be used with multiple query parameters, but require all field names, parameters, and operators (JSON format) to be specified. We recommended using the Autofocus UI to create an advanced query, exporting it, and pasting it into the relevant playbook inputs. Note that multiple search values should be separated by commas only (without spaces or any special characters).

Pack
AutoFocus
Tasks
20

Inputs

Outputs