Alert automation - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM Documentation

Product
Cortex XSIAM
Creation date
2024-03-06
Last date published
2025-02-12
Category
Administrator Guide
Abstract

Save time and expense by using playbooks to automatically investigate and taking remedial action on alerts.

You can automate alert investigation and remediation by running a playbook. Playbooks can help you to improve efficiency by automating and standardizing your workflows, promoting consistent and effective incident response and management. For example, playbooks can include automation tasks to automatically remediate an incident by interacting with a third-party integration, open tickets in a ticketing system such as Jira, or detonate a file using a sandbox. Some content packs include out-of-the-box playbooks that run when a new alert is created, or you can create your own playbooks.

You can view the playbook that is running on an alert, or the playbooks that have already run in the Work Plan for an alert. When a playbook runs on an alert, some playbooks will prompt the analyst for input (in a task) to keep the remediation moving forward and to enable them to make remediation decisions while still getting the benefits of automation.

You can run playbooks in the following ways:

  • Run a playbook automatically

    You can configure a playbook to run automatically, as soon as an alert is created, by creating playbook triggers. When an alert is created that matches the trigger criteria, the playbook runs. You can create your own playbook triggers, add recommended playbook triggers (from a content pack in the Marketplace), or after resolving an incident, accept the recommended playbook triggers. For more information about triggers, see Add a playbook trigger to an alert.

  • Select a playbook to run (the alert did not trigger a playbook)

    If a playbook doesn't run automatically, you can select a recommended playbook. If there is no recommendation, you can select a different playbook to run. Before running a recommended playbook, you can preview the playbook and decide whether to accept the recommendation.

    Note

    If you do not see a relevant playbook, ensure that you have installed the relevant content pack from Marketplace.

For more information about Playbooks, see What is a playbook?.