Skip to main content

Expire Inactive Detections - Vectra RUX

This Playbook is part of the Vectra RUX Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.10.0 and later.

This playbook identifies incidents with inactive detections and updates their investigation status to "expired".

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

  • Find Detection State and Expire Inactive Detections - Vectra RUX

Integrations#

This playbook does not use any integrations.

Scripts#

  • DeleteContext

Commands#

This playbook does not use any commands.

Playbook Inputs#


NameDescriptionDefault ValueRequired
incident_typeThe XSOAR incident type to search for inactive detections. Default is 'Vectra RUX Events Detection'.Vectra RUX Events DetectionOptional

Playbook Outputs#


PathDescriptionType
Vectra.Detection.idThe detection ID.String
Vectra.Detection.investigation_statusThe detection investigation status.String

Playbook Image#


Expire Inactive Detections - Vectra RUX