XDR - Analytics - Get Events by Finding ID
Details
This atomic belongs to the Cisco XDR: Analytics atomic group.
Fetches events for a specific finding from Cisco XDR.
Target: Query APIs
Steps:
- Fetch the finding's events
- Check if the request was successful (if not, end the workflow)
- Extract the event list
- Set the output variables
More information about this API: https://queryservice.us.security.cisco.com/swagger-ui#/Findings/get-finding
About
Authorship
Cisco Managed