Skip to main content

Armis Alert Enrichment

This Playbook is part of the Armis Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.0.0 and later.

Enrich Armis alerts with the devices in the context details.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

  • Armis

Scripts#

This playbook does not use any scripts.

Commands#

  • armis-search-devices

Playbook Inputs#


NameDescriptionDefault ValueRequired
Armis_Device_IdentifierGet the device ID that is associated with the alert.${incident.armisdeviceidentifier}Required

Playbook Outputs#


PathDescriptionType
Device IDDevice IDstring
Armis.Device.nameDevice name.string
Armis.Device.riskLevelDevice risk level defined by Armis.number
Armis.Device.ipAddressIPv4 address.string
Armis.Device.siteSite namestring
Armis.Device.tagsTags.string

Playbook Image#


Armis Alert Enrichment