Find Detection State and Expire Inactive Detections - Vectra RUX
This playbook identifies the detection states of incidents and updates the investigation status of inactive detections to "expired".
- Pack
- VectraRUX
- Tasks
- 12
Inputs
- incident_type — The XSOAR incident type to search for inactive detections. Default is 'Vectra RUX Events Detection'.
Commands used
- vectra-detection-describe
- vectra-detection-investigation-status-update