FortiSOAR Discussions
mohamed44
New Contributor II

FortiSOAR Update Record Step in Correlation

Hi Team

I have an alert and I have investigated the destination Ip of that alert and I want to update the record correlations to change the indicator description

thanks, on advance

FortiSOAR 

#Update Record Correlations

Muhammed
Muhammed
1 Solution
Jtamboli
Staff
Staff

Hi Muhammed,

As per your question, I assume you have an alert with a destination IP, and the indicators are already extracted and linked to this alert. In this case, there will be an indicator linked to the alert.

Based on your investigation of that IP, you can update the correlated indicator's description in the following way:

  1. Create a Manual Trigger Step: Add a manual trigger step on the alert record (as shown in screenshot 1).
  2. Get IP Reputation: Use a VirusTotal Premium connector to get the IP reputation.(as shown in screenshot 2)
  3. Find the Linked Indicator: Use the 'Find Record' step to locate the indicator linked to the alert record.(as shown in screenshot 3)
  4. Update the Indicator Description: Use the 'Update Record' step to update the description of the indicator with the new information from your investigation.(as shown in screenshot 4 and screenshot 5)
  5. ( Screenshot 6 ) shows the indicator record got updated.

     

    Thanks :)

Junaid

View solution in original post

3 REPLIES 3
Jtamboli
Staff
Staff

Hi Muhammed,

As per your question, I assume you have an alert with a destination IP, and the indicators are already extracted and linked to this alert. In this case, there will be an indicator linked to the alert.

Based on your investigation of that IP, you can update the correlated indicator's description in the following way:

  1. Create a Manual Trigger Step: Add a manual trigger step on the alert record (as shown in screenshot 1).
  2. Get IP Reputation: Use a VirusTotal Premium connector to get the IP reputation.(as shown in screenshot 2)
  3. Find the Linked Indicator: Use the 'Find Record' step to locate the indicator linked to the alert record.(as shown in screenshot 3)
  4. Update the Indicator Description: Use the 'Update Record' step to update the description of the indicator with the new information from your investigation.(as shown in screenshot 4 and screenshot 5)
  5. ( Screenshot 6 ) shows the indicator record got updated.

     

    Thanks :)

Junaid
Jtamboli

.

Junaid
Ravi01
New Contributor

thanks