IBM Security QRadar SOAR

 View Only
  • 1.  Changing playbook tasks

    Posted Fri November 06, 2020 08:04 AM
    Hi,

    I have a scenario in my environment that if for some reason I need to change the "incident type" of an incident, I need the playbook tasks to be replaced, but this does not happen. Following are prints.

    Is there any way I can do this?

    ------------------------------
    Vítor Fagundes Alves Nogueira
    ------------------------------


  • 2.  RE: Changing playbook tasks

    Posted Mon November 09, 2020 08:52 AM
    The adding/removing of tasks is typically accomplished by configuration of Rules based on incident type conditions. Can you post the screenshots of the Rule configurations that control this?

    Ben

    ------------------------------
    Ben Lurie
    ------------------------------



  • 3.  RE: Changing playbook tasks

    Posted Tue November 10, 2020 08:28 AM


    ------------------------------
    Vítor Fagundes Alves Nogueira
    ------------------------------



  • 4.  RE: Changing playbook tasks

    Posted Tue November 10, 2020 01:03 PM
    I see that you are not "adding tasks" via the "ordered acrtivities" but by triggering a workflow.
    When an automatic rule creates a task, that task is an "auto-activated" task. This means that if the rule is re-evaluated and the rule condition is false, then its tasks are deactivated and hidden. However, this apparently does not apply to workflows, only to adding tasks via the "ordered activities"

    With "ordered activities" used to asdd tasks, this does work.  (that is the idea and concept of these rules) 
    • a rule, condition "Incident Type = DDos3 ==> action : add task(s) related to "DDoS"
    • a rule, condition "Incident Type = Geral V2" ==> action : add task(s) related to "Geral V2"

    Changing incident type to "DDoS" will remove all tasks created by a rule that was based on any other incident type and add those from DDoS rule 
    Changing incident type to "Geral V2" will remove all tasks created by a rule that was based on any other incident type and add those from Geral V2


     



    ------------------------------
    Guido Janssens
    ------------------------------