Skip to main content

ExpanseAggregateAttributionDevice

This Script is part of the Cortex Xpanse by Palo Alto Networks Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.0.0 and later.

Aggregate entries from multiple sources into AttributionDevice

Script Data#


NameDescription
Script Typepython3
Tags
Cortex XSOAR Version6.0.0

Used In#


This script is used in the following playbooks and scripts.

  • Expanse Attribution Subplaybook

Inputs#


Argument NameDescription
inputInput list.
currentCurrent aggregation state.
serial_fieldsComma separated list of fields to treat as serial number.
vsys_fieldsComma separate list of field names to be used as vsys.
sightings_fieldsComma separated list of field names to be considered sighting counts.
source_ip_fieldsComma separated list of field names to be considered as source IPs.
internal_ip_networksComma separated list of IPv4 Networks to be considered internal (default to RFC private networks).

Outputs#


PathDescriptionType
Expanse.AttributionDevice.serialSerial Number of the devicestring
Expanse.AttributionDevice.vsysVSYS of the devicestring
Expanse.AttributionDevice.device-groupDevice Group inside Panoramastring
Expanse.AttributionDevice.xsoar-instanceXSOAR Panorama instance for this devicestring
Expanse.AttributionDevice.exposing_serviceIs the device exposing the asset?boolean
Expanse.AttributionDevice.sightingsNumber of sessions seen on this devicenumber