TIM - ArcSight Add IP Indicators
This playbook receives indicators from its parent playbook and provides the indicators as inputs for the sub-playbooks that push the indicators to SIEM.
- Pack
- ArcSightESM
- Tasks
- 13
Inputs
- ArcSightBlackListIPActiveListID — ID of the block list IP Active List resource as appears in ArcSight.
- ArcsightBlackListIPValueFieldName — The name of the block list Active List field to insert the IP value to.
- ArcSightWhiteListIPActiveListID — ID of the allow list IP Active List resource as appears in ArcSight.
- ArcsightWhiteListIPValueFieldName — The name of the allow list Active List field to insert the IP value to.
- ArcSightWatchListIPActiveListID — ID of the watch list IP Active List resource as appears in ArcSight.
- ArcsightWatchListIPValueFieldName — The name of the watch list Active List field to insert the IP value to.
Commands used
- appendIndicatorField
- as-add-entries