ZTAP Alert
This playbok is triggered by fetching escalated ZTAP Alerts. The playbook fetches newly escalated alerts. Then, the playbook performs enrichment on the incident's indicators. Lastly, it adds comments/logs as Evidence.
- Pack
- ZeroTrustAnalyticsPlatform
- Tasks
- 11
Inputs
- Enrich — Determines whether to enrich all indicators in the incident.
- OnCall — Set to true to assign only user that is currently on shift. Requires Cortex XSOAR v5.5 or later.
Commands used
- extractIndicators
- ztap-get-alert-entries