Details

This atomic belongs to the Cisco Secure Cloud Analytics atomic group.

Gets roles from Cisco Secure Cloud Analytics for a given IP address newer than the start date provided.

Target: Secure Cloud Analytics - v3 integration target or an HTTP Endpoint for "<your tenant>.obsrvbl.com" with a path of "/api"

Account Key: None if using an integration-provided target, API key if using an HTTP Endpoint target

Steps:
[] Validate the API path
[] Build the authorization header
[] Search the for the device ID of the IP address provided
[] Check if the request was successful:
[]> If it was, attempt to extract the device ID of the first source result and get its roles
[]> If it wasn't, return an error

More information about this API: https://developer.cisco.com/docs/stealthwatch/cloud/#!stealthwatch-cloud-api-version-3

About
Authorship
Cisco Managed