Rubrik Update Anomaly Status- Rubrik Security Cloud
This playbook updates status of the Anomaly Detection snapshot for the provided anomaly ID (or activity series ID) and workload ID (or Object ID).
- Pack
- RubrikPolaris
- Tasks
- 17
Inputs
- anomaly_type — The type of the anomaly. Note: For Anomaly Type, users can execute the "rubrik-radar-suspicious-file-list" command.
- anomaly_id — The ID of the Anomaly or Activity Series ID. Note: For Activity Series ID, users can execute the "rubrik-event-list" command with the "activity_type" argument set to "ANOMALY".
- workload_id — The workload ID (Snappable ID). Note: Users can execute the "rubrik-event-list" command with the "activity_type" argument set to "ANOMALY" and get the value of "fid" from the context.
Commands used
- closeInvestigation
- rubrik-radar-anomaly-status-update