Palo Alto Networks · Arazzo Workflow
Cortex XSOAR Incident Response Orchestration
Version 1.0.0
Create an XSOAR incident, run a response playbook against it, then log a war room entry.
View Spec
View on GitHub
Cloud SecurityCybersecurityFirewallNetwork SecuritySASESOARThreat IntelligenceXDRArazzoWorkflows
Provider
Workflows
create-incident-and-run-playbook
Create an XSOAR incident, run a playbook, and add a war room entry.
Creates an incident with an investigation, runs the supplied playbook against it, and logs a note to the resulting investigation's war room.
1
createIncident
createIncident
Create a new incident with an investigation so a playbook and war room entries can be attached to it.
2
runPlaybook
runPlaybook
Execute the supplied playbook against the newly created incident.
3
addWarRoomEntry
addEntry
Record a work note in the incident's war room investigation.