Prisma Cloud Correlate Alerts

Supported versions

Supported Cortex XSOAR versions: 6.0.0 and later.

Search alerts in Prisma Cloud for a specific asset ID and, if present in XSOAR, link them. Supported Cortex XSOAR versions: 6.0.0 and later.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

This playbook does not use any sub-playbooks.

Integrations

  • RedLock

Scripts

  • SearchIncidentsV2
  • ToTable

Commands

  • linkIncidents
  • redlock-search-alerts

Playbook Inputs


NameDescriptionDefault ValueRequired
Prisma Cloud AttributionAttribution information from Prisma Cloud.PrismaCloud.AttributionOptional
Link IncidentsLink found Prisma Cloud incidents to current one?TrueOptional

Playbook Outputs


PathDescriptionType
foundIncidentsFound Prisma Cloud Incidentsunknown
Redlock.AlertPrisma Cloud Alertunknown

Playbook Image


Prisma Cloud Correlate Alerts