Skip to main content

Query Cisco Stealthwatch Flows

This Playbook is part of the Cisco Secure Network Analytics (Stealthwatch) Pack.#

Supported versions

Supported Cortex XSOAR versions: 5.5.0 and later.

This playbook runs a query on Cisco Stealthwatch flows and return its results to the context.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

  • GenericPolling

Integrations#

  • Cisco Stealthwatch

Scripts#

This playbook does not use any scripts.

Commands#

  • cisco-stealthwatch-query-flows-initialize
  • cisco-stealthwatch-query-flows-results
  • cisco-stealthwatch-query-flows-status

Playbook Inputs#


NameDescriptionDefault ValueRequired
timeoutThe amount to wait before a timeout occurs (in minutes).600Optional
intervalPolling frequency - how often the polling command should run (in minutes).1Optional
rangeRange of results to return (e.g., 0-20).0-20Optional
tenant_idTenant ID represents the domain on Cisco Stealthwatch.102Required
time_range1 month agoRequired

Playbook Outputs#


PathDescriptionType
CiscoStealthwatch.FlowResultsThe results of the search.unknown

Playbook Image#

Setup Account