List Device Events - Chronicle
This playbook receives ChronicleAsset identifier information and provides a list of events related to each one of them. Supported integration: - Chronicle - Google SecOps.
- Pack
- GoogleChronicleBackstory
- Tasks
- 12
Inputs
- chronicleasset_hostname — The hostname associated with the ChronicleAsset.
- chronicleasset_ip — The IP address associated with the ChronicleAsset.
- chronicleasset_mac — The MAC address associated with the ChronicleAsset.
- chronicleasset_product_id — The product ID associated with the ChronicleAsset.
Outputs
- GoogleChronicleBackstory.Events — List of events associated with the ChronicleAsset.
Commands used
- gcb-list-events