
Trend Vision One - Remove Endpoint from Isolation
Details
This workflow appears in the pivot menu and allows a user to remove an endpoint from isolation in Trend Vision One.
Description
This workflow appears in the pivot menu and allows a user to remove an endpoint from isolation in Trend Vision One. Supported observables: hostname, IP address, MAC address, Trend Vision One Agent ID
Target: Trend Vision One - v3.0
Steps:
- Determine which observable type was provided:
- If a Trend Agent ID, set the local ID variable
- If a hostname, IP address, or MAC address, search for the endpoint and set the local ID variable (if an endpoint isn't found, end the workflow)
- Request the endpoint be removed from isolation
Required targets
This workflow requires the following targets to be available before it can be run.
Integration targets
- Trend Vision One
About
- Author
- Cisco
- Version
- v1.1
- Integration
- Average rating
- No ratings yet
- Authorship
- Cisco Managed
Contact and support information
External links
Related workflows
Cisco Managed
This workflow appears in the pivot menu and allows a user to add an IOC to the suspicious object list in Trend Vision One.
Cisco Managed
This workflow appears in the pivot menu and allows a user to isolate an endpoint in Trend Vision One.
Cisco Managed
This workflow appears in the pivot menu and allows a user to remove an IOC from the suspicious object list in Trend Vision One.