Add a Recommended Playbook Trigger - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM Administrator Guide

Cortex XSIAM
Creation date
Last date published
Administrator Guide

Add playbook triggers to an alert, so if the condition is met, a suitable response is issued through a playbook.

In the Playbook Triggers page, you can create a playbook trigger, add a recommended playbook trigger, view all playbook triggers, and change the order of priority. The Core - Investigation and Response content pack includes a number of recommended playbook triggers for alerts, which you can to add to relevant alerts that are ingested.

  1. Select Incident ResponseIncident ConfigurationPlaybook TriggersView Recommendations.

  2. In the Playbook Trigger Recommendations table, view and select the required recommended playbook triggers to add to the trigger table.

    You can view each playbook in detail in the Playbooks page.

  3. Click Add Selected triggers.

  4. Verify the order of the playbook triggers and change the order (if required),

  5. Save the changes to the Playbook Trigger table.