mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
33 lines
1.4 KiB
YAML
33 lines
1.4 KiB
YAML
name: Risk Notable Import Data
|
|
id: 020edc96-ff2b-48b0-9f6f-23da3783fd63
|
|
version: 2
|
|
creation_date: '2021-11-10'
|
|
modification_date: '2026-05-19'
|
|
author: Kelby Shelton, Splunk
|
|
type: Investigation
|
|
description: This playbook gathers all of the events associated with the risk notable and imports them as artifacts. It also generates a custom markdown formatted note.
|
|
playbook: risk_notable_import_data
|
|
how_to_implement: For detailed implementation see https://help.splunk.com/en/splunk-enterprise-security-8/security-content-update/how-to-use-splunk-security-content/5.8/use-splunk-soar-playbooks-and-workbooks-from-the-risk-notable-playbook-pack/get-started-with-the-risk-notable-playbook-pack-for-splunk-soar
|
|
references:
|
|
- https://help.splunk.com/en/splunk-enterprise-security-8/security-content-update/how-to-use-splunk-security-content/5.8/use-splunk-soar-playbooks-and-workbooks-from-the-risk-notable-playbook-pack/get-started-with-the-risk-notable-playbook-pack-for-splunk-soar
|
|
- http://docs.splunk.com/Documentation/ES/6.6.2/Admin/Configurecorrelationsearches#Use_security_framework_annotations_in_correlation_searches
|
|
app_list:
|
|
- Splunk
|
|
labels:
|
|
- risk_notable
|
|
playbook_outputs:
|
|
- note_title
|
|
- note_content
|
|
platform_tags:
|
|
- Risk Notable
|
|
playbook_type: Automation
|
|
vpe_type: Modern
|
|
playbook_fields:
|
|
- event_id
|
|
- info_min_time
|
|
- info_max_time
|
|
- risk_object
|
|
- risk_object_type
|
|
product:
|
|
- Splunk SOAR
|