Skip to main content

Find Detection State and Expire Inactive Detections - Vectra RUX

This Playbook is part of the Vectra RUX Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.10.0 and later.

This playbook identifies the detection states of incidents and updates the investigation status of inactive detections to "expired".

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

This playbook does not use any integrations.

Scripts#

  • DeleteContext
  • Set
  • VectraRUXGetIncidents

Commands#

  • vectra-detection-describe
  • vectra-detection-investigation-status-update

Playbook Inputs#


NameDescriptionDefault ValueRequired
incident_typeThe XSOAR incident type to search for inactive detections. Default is 'Vectra RUX Events Detection'.Vectra RUX Events DetectionOptional

Playbook Outputs#


There are no outputs for this playbook.

Playbook Image#


Find Detection State and Expire Inactive Detections - Vectra RUX