TIM - QRadar Add Domain Indicators
This playbook queries indicators based on a pre-defined query or results from a parent playbook, and adds the resulting indicators to a QRadar Reference Set. The Reference Set name must be defined in the playbook inputs.
- Pack
- QRadar
- Tasks
- 16
Inputs
- QRadarBlackListDomainReferenceSetName — The name of the QRadar block list Domain reference set to insert the data to.
- QRadarWhiteListDomainReferenceSetName — The name of the QRadar allow list Domain reference set to insert the data in to.
- QRadarWatchListDomainReferenceSetName — The name of the QRadar watch list Domain reference set to insert the data in to.
Commands used
- appendIndicatorField
- qradar-update-reference-set-value