Armis Alert Enrichment
Armis Pack.#
This Playbook is part of theSupported versions
Supported Cortex XSOAR versions: 6.0.0 and later.
Enrich Armis alerts with the devices in the context details.
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooksThis playbook does not use any sub-playbooks.
#
Integrations- Armis
#
ScriptsThis playbook does not use any scripts.
#
Commands- armis-search-devices
#
Playbook InputsName | Description | Default Value | Required |
---|---|---|---|
Armis_Device_Identifier | Get the device ID that is associated with the alert. | ${incident.armisdeviceidentifier} | Required |
#
Playbook OutputsPath | Description | Type |
---|---|---|
Device ID | Device ID | string |
Armis.Device.name | Device name. | string |
Armis.Device.riskLevel | Device risk level defined by Armis. | number |
Armis.Device.ipAddress | IPv4 address. | string |
Armis.Device.site | Site name | string |
Armis.Device.tags | Tags. | string |