Skip to main content

LogRhythmRestV2 - Search query

This Playbook is part of the LogRhythm Pack.#

Supported versions

Supported Cortex XSOAR versions: 5.5.0 and later.

This playbook used generic polling to get query results using the command: lr-execute-search-query.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

  • GenericPolling

Integrations#

  • LogRhythmRestV2
  • LogRhythmRest

Scripts#

This playbook does not use any scripts.

Commands#

  • lr-get-query-result
  • lr-execute-search-query

Playbook Inputs#


NameDescriptionDefault ValueRequired
number_of_daysNumber of days to search.7Required
search_nameName of the search.Optional
source_typeLog source type.Optional
host_nameImpacted host name.Optional
usernameUsername.Optional
subjectEmail subject.Optional
senderEmail sender.Optional
recipientEmail recipient.Optional
hashHash.Optional
URLURL.Optional
process_nameProcess name.Optional
objectLog object.Optional
ip_addressIP address.Optional
max_massageMaximum number of log messages to query.10Optional
query_timeoutThe query timeout in seconds.60Optional
entity_idEntity ID.Optional

Playbook Outputs#


PathDescriptionType
LogRhythm.Search.TaskStatusTask Status.string
LogRhythm.Search.TaskIdTask Id.string
LogRhythm.Search.SearchNameThe name of the search query in Cortex XSOAR.string
LogRhythm.Search.Results.originEntityIdEntity ID.number
LogRhythm.Search.Results.impactedIpImpacted IP address.string
LogRhythm.Search.Results.classificationTypeNameClassification name.string
LogRhythm.Search.Results.logSourceNameLog source name.string
LogRhythm.Search.Results.entityNameEntity name.string
LogRhythm.Search.Results.normalDateDate.date
LogRhythm.Search.Results.vendorMessageIdVendor log message.string
LogRhythm.Search.Results.priorityLog priority.number
LogRhythm.Search.Results.sequenceNumberSequence number.string
LogRhythm.Search.Results.originHostIdOrigin host ID.number
LogRhythm.Search.Results.mpeRuleIdLogRhythm rule ID.number
LogRhythm.Search.Results.originIpOrigin IP address.string
LogRhythm.Search.Results.mpeRuleNameLogRhythm rule name.string
LogRhythm.Search.Results.logSourceHostIdLog source host ID.number
LogRhythm.Search.Results.originHostOrigin host.string
LogRhythm.Search.Results.logDateLog date.date
LogRhythm.Search.Results.classificationNameLog classification name.string

Playbook Image#


LogRhythmRestV2 - Search query