Details

This atomic belongs to the Cisco XDR: Analytics atomic group.

This atomic ingests network security events from custom sources. Each network security event will be sent to XDR’s data ingestion pipeline as a detection finding and then processed as other detection sources. The detection will be considered for correlation with other detections and genarating XDR incidents.

Target: Custom Security Events Ingest APIs

Steps:

  • Build the workflow ID header
  • Build the payload
  • Check if the payload was generated successfully:
    • If no, end the workflow
  • Ingest XDR analytics network security event
  • Check if the request was successful:
    • If it was, set the output variable
    • If it wasn't, output an error
About
Authorship
Cisco Managed