Details

This atomic belongs to the Cisco XDR: Analytics atomic group.

Searches for findings in Cisco XDR. Returns a list of finding IDs.

Target: Query APIs

Steps:

  • Search findings
  • Check if the search was successful (if not, end the workflow)
  • Extract the search results
  • Check if there's a next page (if there is, update the output variable)
  • Set the output variables

More information about this API: https://queryservice.us.security.cisco.com/swagger-ui#/Findings/get-findings-search

About
Authorship
Cisco Managed