IBM QRadar SOAR

IBM QRadar SOAR

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Trigger a Rule or Playbook when artifact is modified / tag is added to artifact? Unable to see those options

    Posted Thu December 05, 2024 06:21 AM

    Hi,

    I need to trigger a playbook whenever an artifact is modified or a tag is added to an existing artifact. I don't see any of these options in the playbook/rule conditions. How can I achieve that please?

    Thanks,



    ------------------------------
    A P
    ------------------------------


  • 2.  RE: Trigger a Rule or Playbook when artifact is modified / tag is added to artifact? Unable to see those options

    Posted Thu December 05, 2024 04:31 PM

    Hi AP 

    Sounds like you want to create an automatic playbook that runs off an artifact that is triggered when the value of the artifact is changed or a Threat Source Hit is added.  That would look like this in the UI:



    ------------------------------
    AnnMarie Norcross
    ------------------------------



  • 3.  RE: Trigger a Rule or Playbook when artifact is modified / tag is added to artifact? Unable to see those options

    Posted Fri December 06, 2024 03:07 AM

    Hi AnnMarie,

    I want the playbook to be triggered when the "Tag" of an artifact is changed. However, the "Tag" field is not available as a field option in the playbook condition neither "Artifact is changed" condition which usually is available for incidents. Only a few artifact fields are available in the playbook condition:

    I am assuming it is not possible to use the Tag or capture when the artifact is changed (based on that specific field), then?

    Thanks



    ------------------------------
    A P
    ------------------------------



  • 4.  RE: Trigger a Rule or Playbook when artifact is modified / tag is added to artifact? Unable to see those options

    Posted Sun December 08, 2024 11:35 PM
    Edited by Gilbert Liao Mon December 09, 2024 12:46 AM

    Hi A P,

    Unfortunately it is not currently doable to trigger a playbook/rule based on artifact tags. There is an existing idea here https://ideas.ibm.com/ideas/RIRP-I-1376, please add vote or your comment.

    BTW, it's possible to use artifact tags in a script, including in a playbook condition point, which might be useful in your design.

    e.g.,



    ------------------------------
    Gilbert Liao
    ------------------------------