TIM - QRadar Add Url Indicators
This playbook queries indicators based on a pre-defined query or results from a parent playbook, and adds the resulting indicators to a QRadar Reference Set. The Reference Set name must be defined in the playbook inputs.
- Pack
- QRadar
- Tasks
- 16
Inputs
- QRadarBlackListUrlReferenceSetName — The name of the QRadar block list Url reference set to insert the data in to.
- QRadarWhiteListUrlReferenceSetName — The name of the QRadar white list Url reference set to insert the data in to.
- QRadarWatchListUrlReferenceSetName — The name of the QRadar watch list Url reference set to insert the data in to.
Commands used
- appendIndicatorField
- qradar-update-reference-set-value