Dispatch Incident - Vectra Detect
This playbook is called from the Process Incident - Vectra Detect playbook. It will fetch all active detections for the entity under investigation. It will then assign the entity to a user; if an assignment already exists, it will update that assignment and add a note in Vectra.
- Pack
- Vectra_AI
- Tasks
- 12
Inputs
- user_id — User ID for entity assignment.
- entity_type — Type of the entity.
- entity_id — ID of the entity.
Commands used
- vectra-account-note-add
- vectra-assignment-assign
- vectra-host-note-add
- vectra-search-assignments
- vectra-search-detections