Expire Inactive Detections - Vectra RUX
This playbook identifies incidents with inactive detections and updates their investigation status to "expired".
- Pack
- VectraRUX
- Tasks
- 5
Inputs
- incident_type — The XSOAR incident type to search for inactive detections. Default is 'Vectra RUX Events Detection'.
Outputs
- Vectra.Detection.id — The detection ID.
- Vectra.Detection.investigation_status — The detection investigation status.