mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
1195 lines
57 KiB
JSON
1195 lines
57 KiB
JSON
{
|
|
"blockly": false,
|
|
"blockly_xml": "<xml></xml>",
|
|
"category": "Risk Notable",
|
|
"coa": {
|
|
"data": {
|
|
"description": "This playbook checks for the presence of the Risk Investigation workbook and updates tasks or leaves generic notes.",
|
|
"edges": [
|
|
{
|
|
"conditions": [
|
|
{
|
|
"index": 1
|
|
}
|
|
],
|
|
"id": "port_2_to_port_20",
|
|
"sourceNode": "2",
|
|
"sourcePort": "2_out",
|
|
"targetNode": "20",
|
|
"targetPort": "20_in"
|
|
},
|
|
{
|
|
"id": "port_20_to_port_21",
|
|
"sourceNode": "20",
|
|
"sourcePort": "20_out",
|
|
"targetNode": "21",
|
|
"targetPort": "21_in"
|
|
},
|
|
{
|
|
"conditions": [
|
|
{
|
|
"index": 0
|
|
}
|
|
],
|
|
"id": "port_21_to_port_23",
|
|
"sourceNode": "21",
|
|
"sourcePort": "21_out",
|
|
"targetNode": "23",
|
|
"targetPort": "23_in"
|
|
},
|
|
{
|
|
"id": "port_23_to_port_25",
|
|
"sourceNode": "23",
|
|
"sourcePort": "23_out",
|
|
"targetNode": "25",
|
|
"targetPort": "25_in"
|
|
},
|
|
{
|
|
"id": "port_17_to_port_26",
|
|
"sourceNode": "17",
|
|
"sourcePort": "17_out",
|
|
"targetNode": "26",
|
|
"targetPort": "26_in"
|
|
},
|
|
{
|
|
"conditions": [
|
|
{
|
|
"index": 0
|
|
}
|
|
],
|
|
"id": "port_26_to_port_27",
|
|
"sourceNode": "26",
|
|
"sourcePort": "26_out",
|
|
"targetNode": "27",
|
|
"targetPort": "27_in"
|
|
},
|
|
{
|
|
"id": "port_27_to_port_29",
|
|
"sourceNode": "27",
|
|
"sourcePort": "27_out",
|
|
"targetNode": "29",
|
|
"targetPort": "29_in"
|
|
},
|
|
{
|
|
"id": "port_29_to_port_19",
|
|
"sourceNode": "29",
|
|
"sourcePort": "29_out",
|
|
"targetNode": "19",
|
|
"targetPort": "19_in"
|
|
},
|
|
{
|
|
"id": "port_19_to_port_30",
|
|
"sourceNode": "19",
|
|
"sourcePort": "19_out",
|
|
"targetNode": "30",
|
|
"targetPort": "30_in"
|
|
},
|
|
{
|
|
"id": "port_25_to_port_32",
|
|
"sourceNode": "25",
|
|
"sourcePort": "25_out",
|
|
"targetNode": "32",
|
|
"targetPort": "32_in"
|
|
},
|
|
{
|
|
"id": "port_32_to_port_17",
|
|
"sourceNode": "32",
|
|
"sourcePort": "32_out",
|
|
"targetNode": "17",
|
|
"targetPort": "17_in"
|
|
},
|
|
{
|
|
"conditions": [
|
|
{
|
|
"index": 1
|
|
}
|
|
],
|
|
"id": "port_21_to_port_32",
|
|
"sourceNode": "21",
|
|
"sourcePort": "21_out",
|
|
"targetNode": "32",
|
|
"targetPort": "32_in"
|
|
},
|
|
{
|
|
"conditions": [
|
|
{
|
|
"index": 0
|
|
}
|
|
],
|
|
"id": "port_30_to_port_31",
|
|
"sourceNode": "30",
|
|
"sourcePort": "30_out",
|
|
"targetNode": "31",
|
|
"targetPort": "31_in"
|
|
},
|
|
{
|
|
"id": "port_31_to_port_1",
|
|
"sourceNode": "31",
|
|
"sourcePort": "31_out",
|
|
"targetNode": "1",
|
|
"targetPort": "1_in"
|
|
},
|
|
{
|
|
"id": "port_0_to_port_2",
|
|
"sourceNode": "0",
|
|
"sourcePort": "0_out",
|
|
"targetNode": "2",
|
|
"targetPort": "2_in"
|
|
},
|
|
{
|
|
"conditions": [
|
|
{
|
|
"index": 1
|
|
}
|
|
],
|
|
"id": "port_26_to_port_40",
|
|
"sourceNode": "26",
|
|
"sourcePort": "26_out",
|
|
"targetNode": "40",
|
|
"targetPort": "40_in"
|
|
},
|
|
{
|
|
"id": "port_40_to_port_19",
|
|
"sourceNode": "40",
|
|
"sourcePort": "40_out",
|
|
"targetNode": "19",
|
|
"targetPort": "19_in"
|
|
},
|
|
{
|
|
"id": "port_41_to_port_1",
|
|
"sourceNode": "41",
|
|
"sourcePort": "41_out",
|
|
"targetNode": "1",
|
|
"targetPort": "1_in"
|
|
},
|
|
{
|
|
"conditions": [
|
|
{
|
|
"index": 1
|
|
}
|
|
],
|
|
"id": "port_30_to_port_41",
|
|
"sourceNode": "30",
|
|
"sourcePort": "30_out",
|
|
"targetNode": "41",
|
|
"targetPort": "41_in"
|
|
}
|
|
],
|
|
"hash": "f7539a36e12299694b3cf882f6d345b19c2664b2",
|
|
"nodes": {
|
|
"0": {
|
|
"data": {
|
|
"advanced": {
|
|
"join": []
|
|
},
|
|
"functionName": "on_start",
|
|
"id": "0",
|
|
"type": "start"
|
|
},
|
|
"errors": {},
|
|
"id": "0",
|
|
"type": "start",
|
|
"x": 200,
|
|
"y": 39.99999999999932
|
|
},
|
|
"1": {
|
|
"data": {
|
|
"advanced": {
|
|
"join": []
|
|
},
|
|
"functionId": 1,
|
|
"functionName": "on_finish",
|
|
"id": "1",
|
|
"type": "end"
|
|
},
|
|
"errors": {},
|
|
"id": "1",
|
|
"type": "end",
|
|
"userCode": "\n # This function is called after all actions are completed.\n # summary of all the action and/or all details of actions\n # can be collected here.\n\n # summary_json = phantom.get_summary()\n # if 'result' in summary_json:\n # for action_result in summary_json['result']:\n # if 'action_run_id' in action_result:\n # action_results = phantom.get_action_results(action_run_id=action_result['action_run_id'], result_data=False, flatten=False)\n # phantom.debug(action_results)\n\n",
|
|
"x": 180,
|
|
"y": 1840
|
|
},
|
|
"17": {
|
|
"data": {
|
|
"advanced": {
|
|
"customName": "Risk Notable Import Data",
|
|
"customNameId": 0,
|
|
"join": [],
|
|
"notRequiredJoins": [
|
|
"start_task",
|
|
"workbook_list"
|
|
]
|
|
},
|
|
"functionId": 1,
|
|
"functionName": "risk_notable_import_data",
|
|
"id": "17",
|
|
"inputs": {},
|
|
"playbookName": "risk_notable_import_data",
|
|
"playbookRepo": 1,
|
|
"playbookRepoName": "community",
|
|
"playbookType": "automation",
|
|
"synchronous": true,
|
|
"type": "playbook"
|
|
},
|
|
"errors": {},
|
|
"id": "17",
|
|
"type": "playbook",
|
|
"x": 160,
|
|
"y": 900
|
|
},
|
|
"19": {
|
|
"data": {
|
|
"advanced": {
|
|
"customName": "Risk Notable Enrich",
|
|
"customNameId": 0,
|
|
"join": [],
|
|
"notRequiredJoins": [
|
|
"start_investigate_task"
|
|
]
|
|
},
|
|
"functionId": 1,
|
|
"functionName": "risk_notable_enrich",
|
|
"id": "19",
|
|
"inputs": {},
|
|
"playbookName": "risk_notable_enrich",
|
|
"playbookRepo": 1,
|
|
"playbookRepoName": "community",
|
|
"playbookType": "automation",
|
|
"synchronous": true,
|
|
"type": "playbook"
|
|
},
|
|
"errors": {},
|
|
"id": "19",
|
|
"type": "playbook",
|
|
"x": 160,
|
|
"y": 1420
|
|
},
|
|
"2": {
|
|
"data": {
|
|
"advanced": {
|
|
"customName": "risk rule decision",
|
|
"customNameId": 0,
|
|
"description": "Only proceeds if an artifact with the label \"risk_rule\" is not present. ",
|
|
"join": [],
|
|
"note": "Only proceeds if an artifact with the label \"risk_rule\" is not present. Artifacts with the \"risk_rule\" label are imported during the \"Import Data\" Playbook. These artifacts indicate that the \"Import Data\" Playbook has already run and thus this preprocess playbook no longer needs to execute.",
|
|
"scope": "all"
|
|
},
|
|
"conditions": [
|
|
{
|
|
"comparisons": [
|
|
{
|
|
"conditionIndex": 0,
|
|
"op": "==",
|
|
"param": "artifact:*.label",
|
|
"value": "risk_rule"
|
|
}
|
|
],
|
|
"conditionIndex": 0,
|
|
"customName": "Playbook Ends",
|
|
"display": "If",
|
|
"logic": "and",
|
|
"type": "if"
|
|
},
|
|
{
|
|
"comparisons": [
|
|
{
|
|
"conditionIndex": 1,
|
|
"op": "==",
|
|
"param": "",
|
|
"value": ""
|
|
}
|
|
],
|
|
"conditionIndex": 1,
|
|
"customName": "Playbook Continues",
|
|
"display": "Else",
|
|
"logic": "and",
|
|
"type": "else"
|
|
}
|
|
],
|
|
"functionId": 1,
|
|
"functionName": "risk_rule_decision",
|
|
"id": "2",
|
|
"type": "decision"
|
|
},
|
|
"errors": {},
|
|
"id": "2",
|
|
"type": "decision",
|
|
"x": 260,
|
|
"y": 140
|
|
},
|
|
"20": {
|
|
"data": {
|
|
"advanced": {
|
|
"customName": "workbook list",
|
|
"customNameId": 0,
|
|
"join": []
|
|
},
|
|
"customFunction": {
|
|
"draftMode": false,
|
|
"name": "workbook_list",
|
|
"repoName": "community"
|
|
},
|
|
"functionId": 8,
|
|
"functionName": "workbook_list",
|
|
"id": "20",
|
|
"selectMore": false,
|
|
"type": "utility",
|
|
"utilities": {
|
|
"workbook_list": {
|
|
"description": "Return a list of all the workbooks on this Phantom instance. This might be useful to display possible options for workbooks to add to this event.",
|
|
"fields": [],
|
|
"label": "workbook_list",
|
|
"name": "workbook_list"
|
|
}
|
|
},
|
|
"utilityType": "custom_function",
|
|
"values": {
|
|
"workbook_list": {}
|
|
}
|
|
},
|
|
"errors": {},
|
|
"id": "20",
|
|
"type": "utility",
|
|
"x": 180,
|
|
"y": 280
|
|
},
|
|
"21": {
|
|
"data": {
|
|
"advanced": {
|
|
"customName": "workbook decision",
|
|
"customNameId": 0,
|
|
"description": "Determine if workbook Risk Investigation exists.",
|
|
"join": [],
|
|
"note": "Determine if workbook Risk Investigation exists."
|
|
},
|
|
"conditions": [
|
|
{
|
|
"comparisons": [
|
|
{
|
|
"conditionIndex": 0,
|
|
"op": "==",
|
|
"param": "workbook_list:custom_function_result.data.*.name",
|
|
"value": "Risk Investigation"
|
|
}
|
|
],
|
|
"conditionIndex": 0,
|
|
"customName": "use workbook",
|
|
"display": "If",
|
|
"logic": "and",
|
|
"type": "if"
|
|
},
|
|
{
|
|
"comparisons": [
|
|
{
|
|
"conditionIndex": 1,
|
|
"op": "==",
|
|
"param": "",
|
|
"value": ""
|
|
}
|
|
],
|
|
"conditionIndex": 1,
|
|
"customName": "do not use workbook",
|
|
"display": "Else",
|
|
"logic": "and",
|
|
"type": "else"
|
|
}
|
|
],
|
|
"functionId": 2,
|
|
"functionName": "workbook_decision",
|
|
"id": "21",
|
|
"type": "decision"
|
|
},
|
|
"errors": {},
|
|
"id": "21",
|
|
"type": "decision",
|
|
"x": 260,
|
|
"y": 400
|
|
},
|
|
"23": {
|
|
"data": {
|
|
"advanced": {
|
|
"customName": "workbook add",
|
|
"customNameId": 0,
|
|
"join": []
|
|
},
|
|
"customFunction": {
|
|
"draftMode": false,
|
|
"name": "workbook_add",
|
|
"repoName": "community"
|
|
},
|
|
"functionId": 10,
|
|
"functionName": "workbook_add",
|
|
"id": "23",
|
|
"selectMore": false,
|
|
"type": "utility",
|
|
"utilities": {
|
|
"workbook_add": {
|
|
"description": "Add a workbook to a container. Provide a container id and a workbook name or id",
|
|
"fields": [
|
|
{
|
|
"dataTypes": [
|
|
"phantom container id"
|
|
],
|
|
"description": "A phantom container id",
|
|
"inputType": "item",
|
|
"label": "container",
|
|
"name": "container",
|
|
"placeholder": "container:id",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "A workbook name or id",
|
|
"inputType": "item",
|
|
"label": "workbook",
|
|
"name": "workbook",
|
|
"placeholder": "my_workbook",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [],
|
|
"description": "Defaults to True. Check to see if workbook already exists in container before adding.",
|
|
"inputType": "item",
|
|
"label": "check_for_existing_workbook",
|
|
"name": "check_for_existing_workbook",
|
|
"placeholder": "True or False",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [],
|
|
"description": "Defaults to True. Sets the added workbook to the current phase.",
|
|
"inputType": "item",
|
|
"label": "start_workbook",
|
|
"name": "start_workbook",
|
|
"placeholder": "True or False",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
}
|
|
],
|
|
"label": "workbook_add",
|
|
"name": "workbook_add"
|
|
}
|
|
},
|
|
"utilityType": "custom_function",
|
|
"values": {
|
|
"workbook_add": {
|
|
"check_for_existing_workbook": "true",
|
|
"container": "container:id",
|
|
"start_workbook": "true",
|
|
"workbook": "Risk Investigation"
|
|
}
|
|
}
|
|
},
|
|
"errors": {},
|
|
"id": "23",
|
|
"type": "utility",
|
|
"x": 60,
|
|
"y": 560
|
|
},
|
|
"25": {
|
|
"data": {
|
|
"advanced": {
|
|
"customName": "start preprocess task",
|
|
"customNameId": 0,
|
|
"join": []
|
|
},
|
|
"customFunction": {
|
|
"draftMode": false,
|
|
"name": "workbook_task_update",
|
|
"repoName": "community"
|
|
},
|
|
"functionId": 11,
|
|
"functionName": "start_preprocess_task",
|
|
"id": "25",
|
|
"selectMore": false,
|
|
"type": "utility",
|
|
"utilities": {
|
|
"workbook_task_update": {
|
|
"description": "Update a workbook task by task name",
|
|
"fields": [
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "Name of a workbook task (Required)",
|
|
"inputType": "item",
|
|
"label": "task_name",
|
|
"name": "task_name",
|
|
"placeholder": "my_task",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "Note title goes here (Optional)",
|
|
"inputType": "item",
|
|
"label": "note_title",
|
|
"name": "note_title",
|
|
"placeholder": "My Title",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "Body of note goes here (Optional)",
|
|
"inputType": "item",
|
|
"label": "note_content",
|
|
"name": "note_content",
|
|
"placeholder": "My notes",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "One of: incomplete, in_progress, complete (Optional)",
|
|
"inputType": "item",
|
|
"label": "status",
|
|
"name": "status",
|
|
"placeholder": "in_progress",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "Assigns task to provided owner. Accepts keyword 'current\" to assign task to currently running playbook user. (Optional)",
|
|
"inputType": "item",
|
|
"label": "owner",
|
|
"name": "owner",
|
|
"placeholder": "username",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"phantom container id"
|
|
],
|
|
"description": "ID of Phantom Container (Required)",
|
|
"inputType": "item",
|
|
"label": "container",
|
|
"name": "container",
|
|
"placeholder": "container:id",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
}
|
|
],
|
|
"label": "workbook_task_update",
|
|
"name": "workbook_task_update"
|
|
}
|
|
},
|
|
"utilityType": "custom_function",
|
|
"values": {
|
|
"workbook_task_update": {
|
|
"container": "container:id",
|
|
"note_content": null,
|
|
"note_title": null,
|
|
"owner": null,
|
|
"status": "in_progress",
|
|
"task_name": "Preprocess"
|
|
}
|
|
}
|
|
},
|
|
"errors": {},
|
|
"id": "25",
|
|
"type": "utility",
|
|
"x": 60,
|
|
"y": 660
|
|
},
|
|
"26": {
|
|
"data": {
|
|
"advanced": {
|
|
"customName": "note decision 1",
|
|
"customNameId": 0,
|
|
"description": "Determine if a note was left by the previous playbook and if the Risk Investigation workbook should be used.",
|
|
"join": [],
|
|
"note": "Determine if a note was left by the previous playbook and if the Risk Investigation workbook should be used."
|
|
},
|
|
"conditions": [
|
|
{
|
|
"comparisons": [
|
|
{
|
|
"conditionIndex": 0,
|
|
"op": "!=",
|
|
"param": "risk_notable_import_data:playbook_output:note_title",
|
|
"value": ""
|
|
},
|
|
{
|
|
"conditionIndex": 0,
|
|
"op": "!=",
|
|
"param": "risk_notable_import_data:playbook_output:note_content",
|
|
"value": ""
|
|
},
|
|
{
|
|
"conditionIndex": 0,
|
|
"op": "==",
|
|
"param": "workbook_list:custom_function_result.data.*.name",
|
|
"value": "Risk Investigation"
|
|
}
|
|
],
|
|
"conditionIndex": 0,
|
|
"customName": "update workbook task",
|
|
"display": "If",
|
|
"logic": "and",
|
|
"type": "if"
|
|
},
|
|
{
|
|
"comparisons": [
|
|
{
|
|
"conditionIndex": 1,
|
|
"op": "!=",
|
|
"param": "risk_notable_import_data:playbook_output:note_title",
|
|
"value": ""
|
|
},
|
|
{
|
|
"conditionIndex": 1,
|
|
"op": "!=",
|
|
"param": "risk_notable_import_data:playbook_output:note_content",
|
|
"value": ""
|
|
}
|
|
],
|
|
"conditionIndex": 1,
|
|
"customName": " leave general note",
|
|
"display": "Else If",
|
|
"logic": "and",
|
|
"type": "elif"
|
|
}
|
|
],
|
|
"functionId": 4,
|
|
"functionName": "note_decision_1",
|
|
"id": "26",
|
|
"type": "decision"
|
|
},
|
|
"errors": {},
|
|
"id": "26",
|
|
"type": "decision",
|
|
"x": 240,
|
|
"y": 1020
|
|
},
|
|
"27": {
|
|
"data": {
|
|
"advanced": {
|
|
"customName": "update preprocess task",
|
|
"customNameId": 0,
|
|
"join": []
|
|
},
|
|
"customFunction": {
|
|
"draftMode": false,
|
|
"name": "workbook_task_update",
|
|
"repoName": "community"
|
|
},
|
|
"functionId": 12,
|
|
"functionName": "update_preprocess_task",
|
|
"id": "27",
|
|
"selectMore": false,
|
|
"type": "utility",
|
|
"utilities": {
|
|
"workbook_task_update": {
|
|
"description": "Update a workbook task by task name",
|
|
"fields": [
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "Name of a workbook task (Required)",
|
|
"inputType": "item",
|
|
"label": "task_name",
|
|
"name": "task_name",
|
|
"placeholder": "my_task",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "Note title goes here (Optional)",
|
|
"inputType": "item",
|
|
"label": "note_title",
|
|
"name": "note_title",
|
|
"placeholder": "My Title",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "Body of note goes here (Optional)",
|
|
"inputType": "item",
|
|
"label": "note_content",
|
|
"name": "note_content",
|
|
"placeholder": "My notes",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "One of: incomplete, in_progress, complete (Optional)",
|
|
"inputType": "item",
|
|
"label": "status",
|
|
"name": "status",
|
|
"placeholder": "in_progress",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "Assigns task to provided owner. Accepts keyword 'current\" to assign task to currently running playbook user. (Optional)",
|
|
"inputType": "item",
|
|
"label": "owner",
|
|
"name": "owner",
|
|
"placeholder": "username",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"phantom container id"
|
|
],
|
|
"description": "ID of Phantom Container (Required)",
|
|
"inputType": "item",
|
|
"label": "container",
|
|
"name": "container",
|
|
"placeholder": "container:id",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
}
|
|
],
|
|
"label": "workbook_task_update",
|
|
"name": "workbook_task_update"
|
|
}
|
|
},
|
|
"utilityType": "custom_function",
|
|
"values": {
|
|
"workbook_task_update": {
|
|
"container": "container:id",
|
|
"note_content": "risk_notable_import_data:playbook_output:note_content",
|
|
"note_title": "risk_notable_import_data:playbook_output:note_title",
|
|
"owner": null,
|
|
"status": "",
|
|
"task_name": "Preprocess"
|
|
}
|
|
}
|
|
},
|
|
"errors": {},
|
|
"id": "27",
|
|
"type": "utility",
|
|
"x": 60,
|
|
"y": 1180
|
|
},
|
|
"29": {
|
|
"data": {
|
|
"advanced": {
|
|
"customName": "start investigate task",
|
|
"customNameId": 0,
|
|
"join": []
|
|
},
|
|
"customFunction": {
|
|
"draftMode": false,
|
|
"name": "workbook_task_update",
|
|
"repoName": "community"
|
|
},
|
|
"functionId": 14,
|
|
"functionName": "start_investigate_task",
|
|
"id": "29",
|
|
"selectMore": false,
|
|
"type": "utility",
|
|
"utilities": {
|
|
"workbook_task_update": {
|
|
"description": "Update a workbook task by task name",
|
|
"fields": [
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "Name of a workbook task (Required)",
|
|
"inputType": "item",
|
|
"label": "task_name",
|
|
"name": "task_name",
|
|
"placeholder": "my_task",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "Note title goes here (Optional)",
|
|
"inputType": "item",
|
|
"label": "note_title",
|
|
"name": "note_title",
|
|
"placeholder": "My Title",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "Body of note goes here (Optional)",
|
|
"inputType": "item",
|
|
"label": "note_content",
|
|
"name": "note_content",
|
|
"placeholder": "My notes",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "One of: incomplete, in_progress, complete (Optional)",
|
|
"inputType": "item",
|
|
"label": "status",
|
|
"name": "status",
|
|
"placeholder": "in_progress",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "Assigns task to provided owner. Accepts keyword 'current\" to assign task to currently running playbook user. (Optional)",
|
|
"inputType": "item",
|
|
"label": "owner",
|
|
"name": "owner",
|
|
"placeholder": "username",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"phantom container id"
|
|
],
|
|
"description": "ID of Phantom Container (Required)",
|
|
"inputType": "item",
|
|
"label": "container",
|
|
"name": "container",
|
|
"placeholder": "container:id",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
}
|
|
],
|
|
"label": "workbook_task_update",
|
|
"name": "workbook_task_update"
|
|
}
|
|
},
|
|
"utilityType": "custom_function",
|
|
"values": {
|
|
"workbook_task_update": {
|
|
"container": "container:id",
|
|
"note_content": null,
|
|
"note_title": null,
|
|
"owner": null,
|
|
"status": "in_progress",
|
|
"task_name": "Investigate"
|
|
}
|
|
}
|
|
},
|
|
"errors": {},
|
|
"id": "29",
|
|
"type": "utility",
|
|
"x": 60,
|
|
"y": 1300
|
|
},
|
|
"30": {
|
|
"data": {
|
|
"advanced": {
|
|
"customName": "note decision 2",
|
|
"customNameId": 0,
|
|
"description": "Determine if a note was left by the previous playbook and if the Risk Investigation workbook should be used.",
|
|
"join": [],
|
|
"note": "Determine if a note was left by the previous playbook and if the Risk Investigation workbook should be used."
|
|
},
|
|
"conditions": [
|
|
{
|
|
"comparisons": [
|
|
{
|
|
"conditionIndex": 0,
|
|
"op": "!=",
|
|
"param": "risk_notable_enrich:playbook_output:note_title",
|
|
"value": ""
|
|
},
|
|
{
|
|
"conditionIndex": 0,
|
|
"op": "!=",
|
|
"param": "risk_notable_enrich:playbook_output:note_content",
|
|
"value": ""
|
|
},
|
|
{
|
|
"conditionIndex": 0,
|
|
"op": "==",
|
|
"param": "workbook_list:custom_function_result.data.*.name",
|
|
"value": "Risk Investigation"
|
|
}
|
|
],
|
|
"conditionIndex": 0,
|
|
"customName": "update workbook task",
|
|
"display": "If",
|
|
"logic": "and",
|
|
"type": "if"
|
|
},
|
|
{
|
|
"comparisons": [
|
|
{
|
|
"conditionIndex": 1,
|
|
"op": "!=",
|
|
"param": "risk_notable_enrich:playbook_output:note_title",
|
|
"value": ""
|
|
},
|
|
{
|
|
"conditionIndex": 1,
|
|
"op": "!=",
|
|
"param": "risk_notable_enrich:playbook_output:note_content",
|
|
"value": ""
|
|
}
|
|
],
|
|
"conditionIndex": 1,
|
|
"customName": "leave general note",
|
|
"display": "Else If",
|
|
"logic": "and",
|
|
"type": "elif"
|
|
}
|
|
],
|
|
"functionId": 5,
|
|
"functionName": "note_decision_2",
|
|
"id": "30",
|
|
"type": "decision"
|
|
},
|
|
"errors": {},
|
|
"id": "30",
|
|
"type": "decision",
|
|
"x": 240,
|
|
"y": 1520
|
|
},
|
|
"31": {
|
|
"data": {
|
|
"advanced": {
|
|
"customName": "update investigate task",
|
|
"customNameId": 0,
|
|
"join": []
|
|
},
|
|
"customFunction": {
|
|
"draftMode": false,
|
|
"name": "workbook_task_update",
|
|
"repoName": "community"
|
|
},
|
|
"functionId": 15,
|
|
"functionName": "update_investigate_task",
|
|
"id": "31",
|
|
"selectMore": false,
|
|
"type": "utility",
|
|
"utilities": {
|
|
"workbook_task_update": {
|
|
"description": "Update a workbook task by task name",
|
|
"fields": [
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "Name of a workbook task (Required)",
|
|
"inputType": "item",
|
|
"label": "task_name",
|
|
"name": "task_name",
|
|
"placeholder": "my_task",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "Note title goes here (Optional)",
|
|
"inputType": "item",
|
|
"label": "note_title",
|
|
"name": "note_title",
|
|
"placeholder": "My Title",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "Body of note goes here (Optional)",
|
|
"inputType": "item",
|
|
"label": "note_content",
|
|
"name": "note_content",
|
|
"placeholder": "My notes",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "One of: incomplete, in_progress, complete (Optional)",
|
|
"inputType": "item",
|
|
"label": "status",
|
|
"name": "status",
|
|
"placeholder": "in_progress",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "Assigns task to provided owner. Accepts keyword 'current\" to assign task to currently running playbook user. (Optional)",
|
|
"inputType": "item",
|
|
"label": "owner",
|
|
"name": "owner",
|
|
"placeholder": "username",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"phantom container id"
|
|
],
|
|
"description": "ID of Phantom Container (Required)",
|
|
"inputType": "item",
|
|
"label": "container",
|
|
"name": "container",
|
|
"placeholder": "container:id",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
}
|
|
],
|
|
"label": "workbook_task_update",
|
|
"name": "workbook_task_update"
|
|
}
|
|
},
|
|
"utilityType": "custom_function",
|
|
"values": {
|
|
"workbook_task_update": {
|
|
"container": "container:id",
|
|
"note_content": "risk_notable_enrich:playbook_output:note_content",
|
|
"note_title": "risk_notable_enrich:playbook_output:note_title",
|
|
"owner": null,
|
|
"status": null,
|
|
"task_name": "Investigate"
|
|
}
|
|
}
|
|
},
|
|
"errors": {},
|
|
"id": "31",
|
|
"type": "utility",
|
|
"userCode": "\n parameters = []\n for idx, title_item in enumerate(risk_notable_enrich_output_note_title):\n parameters.append({\n \"owner\": None,\n \"status\": None,\n \"container\": id_value,\n \"task_name\": \"Investigate\",\n \"note_title\": risk_notable_enrich_output_note_title[idx][0],\n \"note_content\": risk_notable_enrich_output_note_content[idx][0],\n })\n\n\n",
|
|
"x": 0,
|
|
"y": 1700
|
|
},
|
|
"32": {
|
|
"data": {
|
|
"advanced": {
|
|
"customName": "Risk Notable Preprocess",
|
|
"customNameId": 0,
|
|
"join": [],
|
|
"notRequiredJoins": [
|
|
"start_preprocess_task",
|
|
"workbook_list"
|
|
]
|
|
},
|
|
"functionId": 1,
|
|
"functionName": "risk_notable_preprocess",
|
|
"id": "32",
|
|
"inputs": {},
|
|
"playbookName": "risk_notable_preprocess",
|
|
"playbookRepo": 1,
|
|
"playbookRepoName": "community",
|
|
"playbookType": "automation",
|
|
"synchronous": true,
|
|
"type": "playbook"
|
|
},
|
|
"errors": {},
|
|
"id": "32",
|
|
"type": "playbook",
|
|
"x": 160,
|
|
"y": 780
|
|
},
|
|
"40": {
|
|
"data": {
|
|
"advanced": {
|
|
"customName": "add import data note",
|
|
"customNameId": 1,
|
|
"description": "Custom code to handle leaving a note with a dynamic title and content when the Risk Investigation workbook is not present.",
|
|
"join": [],
|
|
"note": "Custom code to handle leaving a note with a dynamic title and content when the Risk Investigation workbook is not present."
|
|
},
|
|
"functionId": 1,
|
|
"functionName": "add_import_data_note_1",
|
|
"id": "40",
|
|
"inputParameters": [
|
|
"risk_notable_import_data:playbook_output:note_title",
|
|
"risk_notable_import_data:playbook_output:note_content"
|
|
],
|
|
"outputVariables": [],
|
|
"type": "code"
|
|
},
|
|
"errors": {},
|
|
"id": "40",
|
|
"type": "code",
|
|
"userCode": "\t\n for title, content in zip(risk_notable_import_data_output_note_title_values, risk_notable_import_data_output_note_content_values):\n\n \tphantom.add_note(container=container, content=content, note_format=\"markdown\", note_type=\"general\", title=title)\n\n\n",
|
|
"x": 340,
|
|
"y": 1220
|
|
},
|
|
"41": {
|
|
"data": {
|
|
"advanced": {
|
|
"customName": "add enrich note",
|
|
"customNameId": 1,
|
|
"description": "Custom code to handle leaving a note with a dynamic title and content when the Risk Investigation workbook is not present.",
|
|
"join": [],
|
|
"note": "Custom code to handle leaving a note with a dynamic title and content when the Risk Investigation workbook is not present."
|
|
},
|
|
"functionId": 2,
|
|
"functionName": "add_enrich_note_1",
|
|
"id": "41",
|
|
"inputParameters": [
|
|
"risk_notable_enrich:playbook_output:note_title",
|
|
"risk_notable_enrich:playbook_output:note_content"
|
|
],
|
|
"outputVariables": [],
|
|
"type": "code"
|
|
},
|
|
"errors": {},
|
|
"id": "41",
|
|
"type": "code",
|
|
"userCode": "\n for title, content in zip(risk_notable_enrich_output_note_title_values, risk_notable_enrich_output_note_content_values):\n \n phantom.add_note(container=container, content=content, note_format=\"markdown\", note_type=\"general\", title=title)\n\n",
|
|
"x": 340,
|
|
"y": 1700
|
|
}
|
|
},
|
|
"notes": "For detailed implementation see https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack"
|
|
},
|
|
"input_spec": null,
|
|
"output_spec": null,
|
|
"playbook_type": "automation",
|
|
"python_version": "3",
|
|
"schema": "5.0.3",
|
|
"version": "5.0.1.66250"
|
|
},
|
|
"create_time": "2021-10-19T20:23:12.581560+00:00",
|
|
"draft_mode": false,
|
|
"labels": [
|
|
"risk_notable"
|
|
],
|
|
"tags": []
|
|
} |