TIM - ArcSight Add IP Indicators
ArcSight ESM Pack.#
This Playbook is part of theSupported versions
Supported Cortex XSOAR versions: 5.5.0 and later.
This playbook receives indicators from its parent playbook and provides the indicators as inputs for the sub-playbooks that push the indicators to SIEM.
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooksThis playbook does not use any sub-playbooks.
#
Integrations- ArcSight ESM v2
#
ScriptsThis playbook does not use any scripts.
#
Commands- appendIndicatorField
- as-add-entries
#
Playbook InputsName | Description | Default Value | Required |
---|---|---|---|
ArcSightBlackListIPActiveListID | ID of the block list IP Active List resource as appears in ArcSight. | Optional | |
ArcsightBlackListIPValueFieldName | The name of the block list Active List field to insert the IP value to. | Optional | |
ArcSightWhiteListIPActiveListID | ID of the allow list IP Active List resource as appears in ArcSight. | Optional | |
ArcsightWhiteListIPValueFieldName | The name of the allow list Active List field to insert the IP value to. | Optional | |
ArcSightWatchListIPActiveListID | ID of the watch list IP Active List resource as appears in ArcSight. | Optional | |
ArcsightWatchListIPValueFieldName | The name of the watch list Active List field to insert the IP value to. | Optional | |
Indicator Query | Indicators matching the indicator query will be used as playbook input | Optional |
#
Playbook OutputsThere are no outputs for this playbook.