IBM QRadar SOAR: Handling Incident Artifacts with Playbooks

From Wiki
Jump to navigation Jump to search

The app Artifacts Utils allow you to interact with IBM QRadar SOAR Artifacts for use with other automations.

More details here: Artifacts Utils


Prerequisites

  • IBM QRadar SOAR configured.
  • Artifacts Utils app installed.


Configuring the Playbook

In your playbook:

1) add or edit the Artifact Utils: Search Artifacts function.

Set:

  • Output Name: artifact_utils_search_result
  • incident_id: incident.id
  • artifact_include_incident_count: Yes


2) add or edit the Get Artifacts script.

Provide the following code:

artifacts_search = playbook.functions.results.artifact_utils_search_result.get('content')

incident_artifacts = artifacts_search.get('data',[])

# Retorna o valor do artefact
def get_artifact(artifact_type):
  artifact_value = ""
  
  for artifact in incident_artifacts:
    if artifact.get('type') == artifact_type:
        artifact_value = artifact.get('value')
        break
  
  return artifact_value
  
email_rcpt = get_artifact("Email Recipient")

Ver também