Arcsight - Get events related to the Case
ArcSight ESM Pack.#
This Playbook is part of theGets the case's Arcsight ResourceID
from the FetchID
field, or the "ID" label. If neither are there, it will ask the user for the ID.
Uses the resource ID to get full data for the case, the correlated/aggregate events underneath it, and all base events underneath them.
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooksThis playbook does not use any sub-playbooks.
#
Integrations- Builtin
#
Scripts- Exists
- Set
#
Commands- as-get-case-event-ids
- as-get-all-cases
- setIncident
- as-get-security-events
#
Playbook InputsThere are no inputs for this playbook.
#
Playbook OutputsThere are no outputs for this playbook.