QRadarCorrelationLog
Deprecated. Use the "QRadar - Get Offense Logs"\ \ playbook instead. This playbook retrieves the correlation logs of multiple QIDs.
- Pack
- QRadar
- Tasks
- 7
Inputs
- QID — The correlation QID.
- OffenseStartTime — The offense start time.
- OffenseID — The offense ID.
- additionalQueryFields — Add more fields for basic query (a list with comma separators)
- GetOnlyCREEvents — If value "OnlyCRE" get only events made by CRE. Values can be "OnlyCRE", "OnlyNotCRE", "All".
- MaxLogsCount — Maximum number of log entires to query from QRadar (default: 20)
Outputs
- QRadar.Log — Logs of QRadar correlations