IBM QRadar SOAR: Handling Incident Artifacts with Playbooks
Jump to navigation
Jump to search
The app Artifacts Utils allow you to interact with IBM QRadar SOAR Artifacts for use with other automations.
More details here: Artifacts Utils
Prerequisites
- IBM QRadar SOAR configured.
- Artifacts Utils app installed.
Configuring the Playbook
In your playbook:
1) add or edit the Artifact Utils: Search Artifacts function.
Set:
- Output Name: artifact_utils_search_result
- incident_id: incident.id
- artifact_include_incident_count: Yes
2) add or edit the Get Artifacts script.
Provide the following code:
artifacts_search = playbook.functions.results.artifact_utils_search_result.get('content')
incident_artifacts = artifacts_search.get('data',[])
# Retorna o valor do artefact
def get_artifact(artifact_type):
artifact_value = ""
for artifact in incident_artifacts:
if artifact.get('type') == artifact_type:
artifact_value = artifact.get('value')
break
return artifact_value
email_rcpt = get_artifact("Email Recipient")