Details

This atomic belongs to the Cisco XDR: Incident atomic group.

Fetches a list of events related to an incident from Cisco XDR. This updated atomic supports using a large string for output so more events can be handled without the variable size limit being reached.

Target: Conure APIs

Steps:
[] Extract the simple incident ID
[] Check if an event limit was provided (if so, build the query string)
[] Request the incident's events from Cisco XDR
[] Check if the request was successful:
[]> If it was, set the output variable
[]> If it wasn't, return an error

About
Authorship
Cisco Managed