XDR - Analytics - Ingest Network Security Event
Details
This atomic belongs to the Cisco XDR: Analytics atomic group.
This atomic ingests network security events from custom sources. Each network security event will be sent to XDR’s data ingestion pipeline as a detection finding and then processed as other detection sources. The detection will be considered for correlation with other detections and genarating XDR incidents.
Target: Custom Security Events Ingest APIs
Steps:
- Build the workflow ID header
- Build the payload
- Check if the payload was generated successfully:
- If no, end the workflow
- Ingest XDR analytics network security event
- Check if the request was successful:
- If it was, set the output variable
- If it wasn't, output an error
About
Authorship
Cisco Managed