Hi everyone,
I'm working on customizing an outbound email template in IBM SOAR and need help with extracting specific offense-related data from QRadar.
I want to display the Top 10 Event Names that are part of a QRadar offense (as shown under the "QRadar Offense Details" tab in the SOAR incident) within the email body.
Has anyone done this before or can guide me on how to extract and format these event names in the email template?
Any script examples, extension tips, or documentation references would be highly appreciated.
Thanks in advance!
Best regards,
Abdlrahman
------------------------------
Abdlrahman moghazy
------------------------------