Skip to main content

Armis Alert Enrichment

Supported versions

Supported Cortex XSOAR versions: 6.0.0 and later.

Enrich Armis alerts with the devices in the context details.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

Armis

Scripts#

This playbook does not use any scripts.

Commands#

armis-search-devices

Playbook Inputs#


NameDescriptionDefault ValueRequired
Armis_Device_IDGet the device ID that is associated with the alert.${incident.armisdeviceid}Required

Playbook Outputs#


PathDescriptionType
Device IDDevice ID.string
Armis.SearchDevices.nameDevice name.string
Armis.SearchDevices.riskLevelDevice risk level defined by Armis.number
Armis.SearchDevices.ipaddressIPv4 address.string
Armis.SearchDevices.siteSite namestring
Armis.SearchDevices.tagsTags.string

Playbook Image#


Armis Alert Enrichment