Skip to main content
gwaihir
Explorer II
December 18, 2023
Question

Custom Playbook to notify for any Outbreak Alert FAZ

  • December 18, 2023
  • 3 replies
  • 1829 views

Greetings.

 

Hi, I would like to create a custom PB to run a report and then notify any Outbreak Alert detection.

 

I started with:

 

1. Event trigger (basic handler name --> contains --> "Outbreak Alert")

2. Create Incident

3. Attack data to incident

4. Run report (about incidents)

 

There are a problem, when creating the PB, it seems that Event Trigger doesn't accept  "Outbreak Alert" as "basic handler name" using CONTAINS, only specific handler names.

 

How can this be achieve? 

 

Thank you!