IBM QRadar SOAR

IBM QRadar SOAR

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Common question

    Posted Mon June 20, 2022 05:36 AM
    Hello,

    I have few common questions and don't know this is an issue or I do something wrong. I have latest version - 45.1.42

    1 Issue. When I try to add some Notes with a file hyperlink it doesn't work:

    file_hyperlink = 'file://///some_network_share_path/file.txt'
    note_text = u'Some {0} notes: <a target="blank" href="{1}">{2}</a>'.format(x, file_hyperlink, y)
    incident.addNote(helper.createRichText(note_text))

    2 Issue. I have few Incident activated playbook.
    My condition for playbook 1:
    IF incident.name contains "Rule_X"
    AND incident.workspace is equal to "X"

    My condition for playbook 2:
    Advance: 1 AND (2 OR 3)
    1 incident.workspace is equal to "X"
    2 incident.name dos not contains "Rule_X"
    3 incident.name dos not contains "Rule_Y"

    If incident with name Rule_X activated both playbook triggered.

    ------------------------------
    Alexey Fedorov
    ------------------------------


  • 2.  RE: Common question

    Posted Tue June 21, 2022 05:28 AM
    Hi Alexey

    Regarding question 2, I think the name Rule_X satisfies the condition "incident.name does not contains Rule_Y"

    Maybe the condition for playbook 2 should be 1 AND 2 AND 3, right?

    TIA

    Leo



    ------------------------------
    []

    Leonardo Kenji Shikida
    ------------------------------



  • 3.  RE: Common question

    Posted Tue June 21, 2022 07:27 AM
    Hello Leonardo,

    You are right! My mistake.

    ------------------------------
    Alexey Fedorov
    ------------------------------