Process Incident - Vectra XDR
This playbook is used to initiate the processing of an incident. This playbook runs when a pending incident is selected for investigation. It will change the state from pending to active and it will list the available users in Vectra and request the user ID to use for assignment. Once the data collection is complete, it will call the Dispatch Incident - Vectra XDR playbook.
Vectra XDR · 8 tasks · 0 inputs · 0 outputs
Details
| ID | Process Incident - Vectra XDR |
|---|---|
| From Version | 6.8.0 |
| Tasks | 8 |
README
This playbook is used to initiate the processing of an incident. This playbook runs when a pending incident is selected for investigation. It will change the state from pending to active and it will list the available users in Vectra and request the user ID to use for assignment. Once the data collection is complete, it will call the Dispatch Incident - Vectra XDR playbook.
Dependencies
This playbook uses the following sub-playbooks, integrations, and scripts.
Sub-playbooks
- Dispatch Incident - Vectra XDR
- Add Note - Vectra XDR
Integrations
- VectraXDR
Scripts
- VectraXDRAddNotesInLayout
- DeleteContext
Commands
- vectra-user-list
Playbook Inputs
There are no inputs for this playbook.
Playbook Outputs
There are no outputs for this playbook.
Playbook Image

Commands used
vectra-user-list
Flowchart
id: Process Incident - Vectra XDR version: -1 name: Process Incident - Vectra XDR description: This playbook is used to initiate the processing of an incident. This playbook runs when a pending incident is selected for investigation. It will change the state from pending to active and it will list the available users in Vectra and request the user ID to use for assignment. Once the data collection is complete, it will call the Dispatch Incident - Vectra XDR playbook. starttaskid: "0" tasks: "0": id: "0" taskid: 3c98d2d3-b434-4946-8366-b4dfddb80a29 type: start task: id: 3c98d2d3-b434-4946-8366-b4dfddb80a29 version: -1 name: "" iscommand: false brand: "" description: '' nexttasks: '#none#': - "12" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 50, "y": 50 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "4": id: "4" taskid: eb0627e1-fd16-48a9-8a73-b06a5d0d0cfa type: title task: id: eb0627e1-fd16-48a9-8a73-b06a5d0d0cfa version: -1 name: Done type: title iscommand: false brand: "" description: '' separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 50, "y": 1245 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "7": id: "7" taskid: 4b15e9c2-436f-41e3-8d2e-cd60c9ecc09c type: collection task: id: 4b15e9c2-436f-41e3-8d2e-cd60c9ecc09c version: -1 name: Get the Vectra UserID to assign the current entity. description: Provide the Vectra User ID to assign the current entity in Vectra. type: collection iscommand: false brand: "" nexttasks: '#none#': - "11" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 50, "y": 720 } } note: false timertriggers: [] ignoreworker: false message: to: subject: body: simple: Provide the Vectra User ID to assign the current entity in Vectra. methods: [] format: "" bcc: cc: timings: retriescount: 2 retriesinterval: 360 completeafterreplies: 1 completeafterv2: true completeaftersla: false form: questions: - id: "0" label: "" labelarg: simple: 'Enter the Vectra User ID to assign the current entity: ' required: false gridcolumns: [] defaultrows: [] type: shortText options: [] optionsarg: [] fieldassociated: "" placeholder: "" tooltip: "" readonly: false title: GetUserID description: "" sender: "" expired: false totalanswers: 0 skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "8": id: "8" taskid: e2d22193-588a-4dc0-88d8-abde5bce3375 type: regular task: id: e2d22193-588a-4dc0-88d8-abde5bce3375 version: -1 name: Delete the context of GetUserID description: |- Delete field from context. This automation runs using the default Limited User role, unless you explicitly change the permissions. For more information, see the section about permissions here: - For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations - For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script - For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script scriptName: DeleteContext type: regular iscommand: false brand: "" nexttasks: '#none#': - "9" scriptarguments: key: simple: GetUserID separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 50, "y": 370 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "9": id: "9" taskid: 344ff522-06bc-4a6a-847e-850c73d4f655 type: regular task: id: 344ff522-06bc-4a6a-847e-850c73d4f655 version: -1 name: List Available Users for Assignment description: Returns a list of users. script: '|||vectra-user-list' type: regular iscommand: true brand: "" nexttasks: '#none#': - "7" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 50, "y": 545 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "10": id: "10" taskid: 0cc1a518-e1e9-4773-851d-41cf98477437 type: playbook task: id: 0cc1a518-e1e9-4773-851d-41cf98477437 version: -1 name: Dispatch Incident - Vectra XDR playbookName: Dispatch Incident - Vectra XDR type: playbook iscommand: false brand: "" description: '' nexttasks: '#none#': - "4" scriptarguments: UserID: complex: root: GetUserID.Answers accessor: "0" transformers: - operator: LastArrayElement separatecontext: true continueonerrortype: "" loop: iscommand: false exitCondition: "" wait: 1 max: 0 view: |- { "position": { "x": 50, "y": 1070 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "11": id: "11" taskid: 67172383-99f8-454c-88af-0eff8ceba2d9 type: playbook task: id: 67172383-99f8-454c-88af-0eff8ceba2d9 version: -1 name: Add Note - Vectra XDR playbookName: Add Note - Vectra XDR type: playbook iscommand: false brand: "" description: '' nexttasks: '#none#': - "10" separatecontext: true continueonerrortype: "" view: |- { "position": { "x": 50, "y": 895 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "12": id: "12" taskid: 819e40bf-1a4d-4892-82dd-04b1739b76f0 type: regular task: id: 819e40bf-1a4d-4892-82dd-04b1739b76f0 version: -1 name: Add entity notes to the layout. description: This script allows to add Entity notes in the layout. scriptName: VectraXDRAddNotesInLayout type: regular iscommand: false brand: "" nexttasks: '#none#': - "8" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 50, "y": 195 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false view: |- { "linkLabelsPosition": {}, "paper": { "dimensions": { "height": 1260, "width": 380, "x": 50, "y": 50 } } } inputs: [] outputs: [] tests: - No tests (auto formatted) fromversion: 6.8.0