You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/cloud-soar/introduction.md
+5-5Lines changed: 5 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -602,12 +602,12 @@ Let’s create a playbook for use in Cloud SIEM.
602
602
1. For the **IP** field, click the cog icon on the right, and select the **Get Insight Details** action. Then find the **output.entity.ip.address** field and select it.
603
603
1. Click **Create** to save the new action.
604
604
1. Add another action to the playbook by clicking the **+** icon on the **Get VirusTotal Info** node you just created and selecting **Action**. Use the parameters outlined below:
1.**Entity ID**: Click the cog icon on the right, and select the **Get Insight Details** action. Then find the **output.entity.id** field and select it.
610
-
1.**Enrichment Name**: “VirusTotal IP Reputation”
610
+
1.**Enrichment Name**: "VirusTotal IP Reputation".
611
611
1.**Raw JSON**: Click the cog icon, select **Get VirusTotal Info**, then select **output.raw**.
612
612
1. You can leave the other fields blank. Click **Create** to save the action.
613
613
1. Playbooks also allow condition nodes that can switch execution branches depending on the true/false results of a given expression. Let’s add a condition node to our playbook that will differentiate the execution branch depending on the severity of the insight.
0 commit comments