Skip to main content

Saas Security - Take Action on the Incident

This Playbook is part of the SaaS Security by Palo Alto Networks Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.0.0 and later.

This sub-playbook will send email notification to the Saas Security Admin for taking remediation action on the incident.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

  • SaasSecurity

Scripts#

This playbook does not use any scripts.

Commands#

  • saas-security-incident-state-update
  • saas-security-asset-remediate

Playbook Inputs#


NameDescriptionDefault ValueRequired
emailAdmin EmailOptional
incident_idPrisma Saas Incident IdOptional
asset_idPrisma Saas Asset IdOptional
asset_namePrisma Saas Asset NameOptional

Playbook Outputs#


There are no outputs for this playbook.

Playbook Image#


Saas Security - Take Action on the incident