IBM QRadar SOAR

IBM QRadar SOAR

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  How to use SOAR functions for Outbound Email App

    Posted Thu June 22, 2023 10:32 AM
      |   view attached

    Hello,

    Members, need your help as a beginner.

    I have downloaded IBM SOAR app "Outbound email" and I want to use its function " Send Email" and I have gone through readme pd of this app but I'm still confused. 

    The function has different inputs like "mail_to" , "mail_cc" and readme file also tell about pre-process script but I dont know how can I connect all these things?

    Do I have to manually enter "mail_to" fields or how i give inputs to the function. I have attached screenshots.

    Please guide



    ------------------------------
    Zain Zafar
    ------------------------------


  • 2.  RE: How to use SOAR functions for Outbound Email App

    Posted Mon June 26, 2023 11:13 AM

    @Zain Zafar I think once you have app.config configured correctly, this page works like if you would sending out an e-mail. If you are trying to create an rule/workflow from the existing function, you can refer to the example rule/workflow that comes with the app install.



    ------------------------------
    HENRY CHUANG
    ------------------------------



  • 3.  RE: How to use SOAR functions for Outbound Email App

    Posted Tue August 01, 2023 02:04 PM

    For required fields, you'll just use the inputs.<field_api_name> in a pre-processor of the function on the workflow/playbook. We typically have our actions automatically fill those inputs out using incident fields and activity fields from an input field presented to the analyst (rule.properties.<activity_field_api_name>)

    This GUI you've shown is the stock primarily for testing / seeing how it works.



    ------------------------------
    Jared Fagel
    Cyber Security Analyst
    ALLETE Inc.
    ------------------------------