Skip to main content

Query Cisco Stealthwatch Flows

This Playbook is part of the Cisco Secure Network Analytics (Stealthwatch) Pack.#

Supported versions

Supported Cortex XSOAR versions: 5.5.0 and later.

This playbook runs a query on Cisco Stealthwatch flows and return its results to the context.


This playbook uses the following sub-playbooks, integrations, and scripts.


  • GenericPolling


  • Cisco Stealthwatch


This playbook does not use any scripts.


  • cisco-stealthwatch-query-flows-initialize
  • cisco-stealthwatch-query-flows-results
  • cisco-stealthwatch-query-flows-status

Playbook Inputs#

NameDescriptionDefault ValueRequired
timeoutThe amount to wait before a timeout occurs (in minutes).600Optional
intervalPolling frequency - how often the polling command should run (in minutes).1Optional
rangeRange of results to return (e.g., 0-20).0-20Optional
tenant_idTenant ID represents the domain on Cisco Stealthwatch.102Required
time_range1 month agoRequired

Playbook Outputs#

CiscoStealthwatch.FlowResultsThe results of the search.unknown

Playbook Image#

Setup Account