ExtraHop - Ticket Tracking Deprecated Hidden
Deprecated. Use the "ExtraHop - Ticket Tracking v2" playbook instead.\ \ Links the Demisto incident back to the ExtraHop detection that created it for ticket tracking purposes.
Deprecated Content (Deprecated) · 13 tasks · 1 input · 0 outputs
Details
| ID | ExtraHop - Ticket Tracking |
|---|---|
| From Version | 5.0.0 |
| Tasks | 13 |
README
Deprecated. Use the “ExtraHop - Ticket Tracking v2” playbook instead.
Links the Demisto incident back to the ExtraHop detection that created it for ticket tracking purposes.
Dependencies
This playbook uses the following sub-playbooks, integrations, and scripts.
Sub-playbooks
This playbook does not use any sub-playbooks.
Integrations
This playbook does not use any integrations.
Scripts
- SearchIncidentsV2
- Exists
- AssignAnalystToIncident
Commands
- extrahop-track-ticket
- setIncident
Playbook Inputs
| Name | Description | Default Value | Required |
|---|---|---|---|
| OnCall | Set to true to assign only user that is currently on shift. Requires Cortex XSOAR v5.5 or later. | false | Optional |
Playbook Outputs
There are no outputs for this playbook.
Inputs
OnCall— Set to true to assign only user that is currently on shift. Requires Cortex XSOAR v5.5 or later.
Commands used
extrahop-track-ticket
setIncident
Flowchart
id: ExtraHop - Ticket Tracking version: -1 name: ExtraHop - Ticket Tracking description: Deprecated. Use the "ExtraHop - Ticket Tracking v2" playbook instead.\ \ Links the Demisto incident back to the ExtraHop detection that created it for ticket tracking purposes. starttaskid: "0" hidden: true tasks: "0": id: "0" taskid: 71394f2c-bc76-4885-8bab-b55ce0094789 type: start task: id: 71394f2c-bc76-4885-8bab-b55ce0094789 version: -1 name: "" iscommand: false brand: "" description: '' nexttasks: '#none#': - "15" separatecontext: false view: |- { "position": { "x": -10, "y": -460 } } note: false timertriggers: [] ignoreworker: false "1": id: "1" taskid: be00a185-8d20-4e46-8012-4ae44b3687fc type: regular task: id: be00a185-8d20-4e46-8012-4ae44b3687fc version: -1 name: Track the incident status in ExtraHop Reveal(x) description: Link the ExtraHop Detection to the corresponding Demisto Investigation. This uses the ExtraHop ticket tracking functionality to properly display ticket status within ExtraHop. script: '|||extrahop-track-ticket' type: regular iscommand: true brand: "" nexttasks: '#none#': - "12" scriptarguments: detection_id: complex: root: foundIncidents accessor: CustomFields.detectionid incident_close_reason: complex: root: foundIncidents accessor: closeReason incident_id: complex: root: foundIncidents accessor: id incident_owner: complex: root: foundIncidents accessor: owner incident_status: complex: root: foundIncidents accessor: status continueonerror: true separatecontext: false view: |- { "position": { "x": 170, "y": 1110 } } note: false timertriggers: [] ignoreworker: false "2": id: "2" taskid: f4953d89-2219-4d74-8acf-d819728d0ac9 type: title task: id: f4953d89-2219-4d74-8acf-d819728d0ac9 version: -1 name: Done type: title iscommand: false brand: "" description: '' separatecontext: false view: |- { "position": { "x": -100, "y": 1640 } } note: false timertriggers: [] ignoreworker: false "3": id: "3" taskid: 6f9852cc-7a6e-4d2f-8bef-86fb205e5408 type: regular task: id: 6f9852cc-7a6e-4d2f-8bef-86fb205e5408 version: -1 name: Mark the incident as tracked description: Update the incident to reflect the Detection Ticketed status. script: Builtin|||setIncident type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "4" scriptarguments: addLabels: {} affecteddata: {} affecteddatatype: {} affectedindividualscontactinformation: {} app: {} approximatenumberofaffecteddatasubjects: {} assetid: {} attachmentcount: {} attachmentextension: {} attachmenthash: {} attachmentid: {} attachmentname: {} attachmentsize: {} attachmenttype: {} bugtraq: {} city: {} closeNotes: {} closeReason: {} companyaddress: {} companycity: {} companycountry: {} companyhasinsuranceforthebreach: {} companyname: {} companypostalcode: {} contactaddress: {} contactname: {} country: {} countrywherebusinesshasitsmainestablishment: {} countrywherethebreachtookplace: {} customFields: {} cve: {} cvss: {} dataencryptionstatus: {} datetimeofthebreach: {} deleteEmptyField: {} dest: {} destntdomain: {} details: {} detectionendtime: {} detectionid: {} detectionticketed: simple: "true" detectionupdatetime: {} detectionurl: {} dpoemailaddress: {} duration: {} emailaddress: {} emailbcc: {} emailbody: {} emailbodyformat: {} emailbodyhtml: {} emailcc: {} emailclientname: {} emailfrom: {} emailhtml: {} emailinreplyto: {} emailkeywords: {} emailmessageid: {} emailreceived: {} emailreplyto: {} emailreturnpath: {} emailsenderip: {} emailsize: {} emailsource: {} emailsubject: {} emailto: {} emailtocount: {} emailurlclicked: {} extrahopapplianceid: {} extrahophostname: {} filehash: {} filename: {} filepath: {} id: simple: ${ExtraHop.TicketId} isthedatasubjecttodpia: {} labels: {} likelyimpact: {} maliciouscauseifthecauseisamaliciousattack: {} malwarefamily: {} measurestomitigate: {} name: {} occurred: {} owner: {} participants: {} phase: {} possiblecauseofthebreach: {} postalcode: {} rawparticipants: {} replacePlaybook: {} riskscore: {} roles: {} sectorofaffectedparty: {} severity: {} signature: {} sizenumberofemployees: {} sizeturnover: {} sla: {} slaField: {} src: {} srcntdomain: {} srcuser: {} systems: {} telephoneno: {} type: {} user: {} vendorid: {} vendorproduct: {} vulnerabilitycategory: {} whereisdatahosted: {} separatecontext: false view: |- { "position": { "x": 490, "y": 600 } } note: false timertriggers: [] ignoreworker: false "4": id: "4" taskid: 695438ce-bf6a-43e8-8d73-3b314c1ea1e5 type: regular task: id: 695438ce-bf6a-43e8-8d73-3b314c1ea1e5 version: -1 name: Search for any untracked ExtraHop Detections description: Searches Demisto incidents for any ExtraHop Detections that are untracked. scriptName: SearchIncidentsV2 type: regular iscommand: false brand: "" nexttasks: '#none#': - "10" scriptarguments: details: {} fromclosedate: {} fromdate: {} fromduedate: {} id: {} level: {} name: {} notstatus: {} owner: {} page: {} query: simple: type:"ExtraHop Detection" and incident.detectionticketed:F and incident.created:>="1 day ago" reason: {} size: {} sort: {} status: {} toclosedate: {} todate: {} toduedate: {} type: {} separatecontext: false view: |- { "position": { "x": 170, "y": 770 } } note: false timertriggers: [] ignoreworker: false "6": id: "6" taskid: 75eb04ec-c770-4120-8d70-56513ce2201b type: regular task: id: 75eb04ec-c770-4120-8d70-56513ce2201b version: -1 name: Mark the incident as tracked description: Update the incident to reflect the Detection Ticketed status. script: Builtin|||setIncident type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "2" scriptarguments: addLabels: {} affecteddata: {} affecteddatatype: {} affectedindividualscontactinformation: {} app: {} approximatenumberofaffecteddatasubjects: {} assetid: {} attachmentcount: {} attachmentextension: {} attachmenthash: {} attachmentid: {} attachmentname: {} attachmentsize: {} attachmenttype: {} bugtraq: {} city: {} closeNotes: {} closeReason: {} companyaddress: {} companycity: {} companycountry: {} companyhasinsuranceforthebreach: {} companyname: {} companypostalcode: {} contactaddress: {} contactname: {} country: {} countrywherebusinesshasitsmainestablishment: {} countrywherethebreachtookplace: {} customFields: {} cve: {} cvss: {} dataencryptionstatus: {} datetimeofthebreach: {} deleteEmptyField: {} dest: {} destntdomain: {} details: {} detectionendtime: {} detectionid: {} detectionticketed: simple: "true" detectionupdatetime: {} detectionurl: {} dpoemailaddress: {} duration: {} emailaddress: {} emailbcc: {} emailbody: {} emailbodyformat: {} emailbodyhtml: {} emailcc: {} emailclientname: {} emailfrom: {} emailhtml: {} emailinreplyto: {} emailkeywords: {} emailmessageid: {} emailreceived: {} emailreplyto: {} emailreturnpath: {} emailsenderip: {} emailsize: {} emailsource: {} emailsubject: {} emailto: {} emailtocount: {} emailurlclicked: {} extrahopapplianceid: {} extrahophostname: {} filehash: {} filename: {} filepath: {} id: simple: ${ExtraHop.TicketId} isthedatasubjecttodpia: {} labels: {} likelyimpact: {} maliciouscauseifthecauseisamaliciousattack: {} malwarefamily: {} measurestomitigate: {} name: {} occurred: {} owner: {} participants: {} phase: {} possiblecauseofthebreach: {} postalcode: {} rawparticipants: {} replacePlaybook: {} riskscore: {} roles: {} sectorofaffectedparty: {} severity: {} signature: {} sizenumberofemployees: {} sizeturnover: {} sla: {} slaField: {} src: {} srcntdomain: {} srcuser: {} systems: {} telephoneno: {} type: {} user: {} vendorid: {} vendorproduct: {} vulnerabilitycategory: {} whereisdatahosted: {} separatecontext: false view: |- { "position": { "x": 170, "y": 1465 } } note: false timertriggers: [] ignoreworker: false "7": id: "7" taskid: 50b89e52-0733-477b-8929-8b595f704ca4 type: regular task: id: 50b89e52-0733-477b-8929-8b595f704ca4 version: -1 name: Track the incident status in ExtraHop Reveal(x) description: Link the ExtraHop Detection to the corresponding Demisto Investigation. This uses the ExtraHop ticket tracking functionality to properly display ticket status within ExtraHop. script: '|||extrahop-track-ticket' type: regular iscommand: true brand: "" nexttasks: '#none#': - "11" scriptarguments: detection_id: simple: ${incident.detectionid} incident_close_reason: simple: ${incident.closeReason} incident_id: simple: ${incident.id} incident_owner: simple: ${incident.owner} incident_status: simple: ${incident.status} continueonerror: true separatecontext: false view: |- { "position": { "x": 490, "y": 230 } } note: false timertriggers: [] ignoreworker: false "9": id: "9" taskid: 40271f8c-840d-4e71-86c5-57a28bc24aea type: condition task: id: 40271f8c-840d-4e71-86c5-57a28bc24aea version: -1 name: Are the required fields present? description: Checks if the required detection and incident IDs are present. type: condition iscommand: false brand: "" nexttasks: '#default#': - "4" "yes": - "7" separatecontext: false conditions: - label: "yes" condition: - - operator: isNotEmpty left: value: simple: incident.id iscontext: true - - operator: isNotEmpty left: value: simple: incident.detectionid iscontext: true view: |- { "position": { "x": 170, "y": 50 } } note: false timertriggers: [] ignoreworker: false "10": id: "10" taskid: 76071ff8-9c4d-494d-8b73-aa4368199fb5 type: condition task: id: 76071ff8-9c4d-494d-8b73-aa4368199fb5 version: -1 name: Were there any incidents found? description: Checks if there were any untracked ExtraHop Detections found. type: condition iscommand: false brand: "" nexttasks: '#default#': - "2" "yes": - "1" separatecontext: false conditions: - label: "yes" condition: - - operator: isNotEmpty left: value: simple: foundIncidents.id iscontext: true view: |- { "position": { "x": 170, "y": 930 } } note: false timertriggers: [] ignoreworker: false "11": id: "11" taskid: e553a569-662c-460e-87f0-f69efaf2901a type: condition task: id: e553a569-662c-460e-87f0-f69efaf2901a version: -1 name: Was the incident successfully tracked? description: Check if the ticket tracking was successful. type: condition iscommand: false brand: "" nexttasks: '#default#': - "4" "yes": - "3" separatecontext: false conditions: - label: "yes" condition: - - operator: isNotEmpty left: value: simple: ExtraHop.TicketId iscontext: true view: |- { "position": { "x": 490, "y": 390 } } note: false timertriggers: [] ignoreworker: false "12": id: "12" taskid: 624c3b07-31d8-45ca-8f6f-332974515fef type: condition task: id: 624c3b07-31d8-45ca-8f6f-332974515fef version: -1 name: Was the incident successfully tracked? description: Check if the ticket tracking was successful. type: condition iscommand: false brand: "" nexttasks: '#default#': - "2" "yes": - "6" separatecontext: false conditions: - label: "yes" condition: - - operator: isNotEmpty left: value: simple: ExtraHop.TicketId iscontext: true view: |- { "position": { "x": 170, "y": 1275 } } note: false timertriggers: [] ignoreworker: false "13": id: "13" taskid: 1619242b-d813-4dfb-8801-cd45a61906f3 type: regular task: id: 1619242b-d813-4dfb-8801-cd45a61906f3 version: -1 name: Assign an ExtraHop analyst to the incident description: Assign an analyst randomly from the pool of users with the ExtraHop role. scriptName: AssignAnalystToIncident type: regular iscommand: false brand: "" nexttasks: '#none#': - "9" scriptarguments: assignBy: {} email: {} onCall: complex: root: inputs.OnCall roles: simple: ExtraHop username: {} continueonerror: true separatecontext: false view: |- { "position": { "x": 170, "y": -110 } } note: false timertriggers: [] ignoreworker: false "15": id: "15" taskid: dffb9228-cc49-4adf-88f5-13001f85ba70 type: condition task: id: dffb9228-cc49-4adf-88f5-13001f85ba70 version: -1 name: Is ExtraHop Reveal(x) enabled? description: Checks if there is an active instance of the ExtraHop Reveal(x) integration enabled. scriptName: Exists type: condition iscommand: false brand: "" nexttasks: '#default#': - "2" "yes": - "13" scriptarguments: value: complex: root: modules filters: - - operator: isEqualString left: value: simple: brand iscontext: true right: value: simple: ExtraHop v2 - - operator: isEqualString left: value: simple: state iscontext: true right: value: simple: active separatecontext: false view: |- { "position": { "x": -10, "y": -320 } } note: false timertriggers: [] ignoreworker: false view: |- { "linkLabelsPosition": { "10_1_yes": 0.42, "10_2_#default#": 0.2, "11_3_yes": 0.49, "11_4_#default#": 0.45, "12_2_#default#": 0.31, "12_6_yes": 0.47, "15_13_yes": 0.55, "15_2_#default#": 0.1, "9_4_#default#": 0.31, "9_7_yes": 0.44 }, "paper": { "dimensions": { "height": 2165, "width": 970, "x": -100, "y": -460 } } } inputs: - key: OnCall value: simple: "false" required: false description: Set to true to assign only user that is currently on shift. Requires Cortex XSOAR v5.5 or later. outputs: [] fromversion: 5.0.0 tests: - No test - Deprecated playbook deprecated: true