IBM QRadar SOAR: Closing Incident with Playbooks

From Wiki
Revision as of 18:42, 11 June 2025 by Ebasso (talk | contribs)

Simple playbook to close a Incident

Configuring the Playbook

In your playbook:

1) add or edit the Close Incident script.

Provide the following code:

incident.resolution_id = "Resolved"

if incident.confirmed: 
  incident.resolution_summary = "Incident was closed with CONFIRMED."
else: 
  incident.resolution_summary = "Incident was closed with Unconfirmed."

incident.plan_status = "C"

incident.addNote("O Incidente foi finalizado.")

Ver também