Modify EDL
Generic Export Indicators Service Pack.#
This Playbook is part of theSupported versions
Supported Cortex XSOAR versions: 6.6.0 and later.
Adds indicators to or removes indicators from an external dynamic list (EDL) by adding or removing an indicator tag. The EDL itself is generated by using the Cortex XSOAR Generic Export Indicators Service integration and querying on tag in the Indicator Query parameter.
Incident fields that control the behavior of this playbook:
- EDL Action: Whether to add or remove EDL indicators/
- EDL Indicators List: Input list of indicators to add to or remove from EDL (according to the value of EDL Action).
- EDL Tag: Tag value in the Generic Export Indicators Service integration instance Indicator Query, which controls which indicators are on the EDL.
- EDL Indicator Type: (Only relevant if adding to EDL) Type of indicators to add to EDL.
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooksThis playbook does not use any sub-playbooks.
#
IntegrationsThis playbook does not use any integrations.
#
ScriptsSet
#
Commands- createNewIndicator
- findIndicators
- removeIndicatorField
- closeInvestigation
- appendIndicatorField
#
Playbook InputsThere are no inputs for this playbook.
#
Playbook OutputsThere are no outputs for this playbook.