Incident
Outputs
Incident ID
Incident Name
Appliance ID
Appliance Name
Total Incident Data
Incident Description
Incident Category
Incident OS
Incident Security Layer
Incident Status
Incident Events Count (Num)
Raw Output
Incident Data (Array of Objects)
Example:
Usernames
Often used in Each component (loops), Add notes, Add to watch list, etc.
Sources (Array of IPs)
Often used in Each component (loops), Add notes, Add to watch list, Whois IP, Threat Intel
Incident Priority
Can be one of:
High
Medium
Low
Incident Created At
Incident Correlated Values (Array of Objects)
Last updated