Hello,
I'm configuring Resilient on a test environment to achieve some automation along with QRadar.
I configured an MSSP enviroment and I've imported a couple of offenses from Qradar to see how I can automate things on both sides.
I configured some integrations, from X-Force to IP info to see if I can Automatically lookup IP addresses against botent/Command and Control servers.
I'm encountering some issues, everytime I perform an action or a Workflow, they just simply get stuck, even the rules does.
If I click on "actions" on the top-right corner and then "Action Status" or "Wokflow status", every action, workflow or rule is on a "Suspended" status.
With that being said, how can I check what's wrong with this actions?
What is the best path to follow in order to achieve what I'm looking for? I just want to configure a function that: given an offense from QRadar, if one of the Ip's is related to some botnet, notify me, if not close the offense and the incident. Is that possible?
------------------------------
Alessandro Di Liberto
------------------------------