Skip to main content

TIM - ArcSight Add IP Indicators

This Playbook is part of the ArcSight ESM Pack.#

Supported versions

Supported Cortex XSOAR versions: 5.5.0 and later.

This playbook receives indicators from its parent playbook and provides the indicators as inputs for the sub-playbooks that push the indicators to SIEM.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

  • ArcSight ESM v2

Scripts#

This playbook does not use any scripts.

Commands#

  • appendIndicatorField
  • as-add-entries

Playbook Inputs#


NameDescriptionDefault ValueRequired
ArcSightBlackListIPActiveListIDID of the block list IP Active List resource as appears in ArcSight.Optional
ArcsightBlackListIPValueFieldNameThe name of the block list Active List field to insert the IP value to.Optional
ArcSightWhiteListIPActiveListIDID of the allow list IP Active List resource as appears in ArcSight.Optional
ArcsightWhiteListIPValueFieldNameThe name of the allow list Active List field to insert the IP value to.Optional
ArcSightWatchListIPActiveListIDID of the watch list IP Active List resource as appears in ArcSight.Optional
ArcsightWatchListIPValueFieldNameThe name of the watch list Active List field to insert the IP value to.Optional
Indicator QueryIndicators matching the indicator query will be used as playbook inputOptional

Playbook Outputs#


There are no outputs for this playbook.

Playbook Image#


Playbook Image