l have an alert rule that triigers when it detects a web attack like XSS, SQLI.
i want my playbook to starts when the alert is triggered.
Any idea??
l have an alert rule that triigers when it detects a web attack like XSS, SQLI.
i want my playbook to starts when the alert is triggered.
Any idea??
Hi
LogPoint documentation on SOAR Playbook trigger can be found following below link.
Playbook Triggers — Playbooks latest documentation (logpoint.com)
Under ‘Trigger’ definition you can use following statement
SELECT * FROM LogPoint WHERE alertrule id LIKE %xxxxxxxxxxxxxx%
The AlertRule ID can be found clicking the “I” sign at the right side your alertrule.
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.