Pure-Storage-Volume-Snapshot
This workflow performs a volume snapshot operation on the set of volumes configured on the Flash Array (On-Premises Target) using the names provided as an input variable. This operation is triggered by Cisco XDR to safeguard the volume data as a threat response, using action scripts in response to any critical alerts or incidents.
Description
Instructions:
-
Ensure the remote automation server is set up and configured to establish a connection between the Cisco XDR and the On-Premises Pure Storage Flash Array.
-
Configure the HTTP target for the On-Premises Pure Storage Flash Array within the Cisco XDR.
-
Log in to the On-Premises Pure Storage Flash Array to fetch the API token. Add this token as a static variable in the workflow to establish the successful API call between the Cisco XDR and the Flash Array.
reference link - https://support.purestorage.com/bundle/m_purityfa_rest_api/page/FlashArray/PurityFA/Purity_FA_REST_API/topics/task/t_client_configuration.html -
Update the input variable to the XDR workflow with the volume names for which snapshots are to be taken
"Enter multiple source names in comma-separated format. For example, name01, name02." -
Optionally, configure an automation rule to run this workflow whenever an incident is triggered by any alerts or logs.
Ensure the workflow is validated (this should occur automatically during installation); otherwise, it will not run.
This workflow requires the following targets to be available before it can be run.
Custom targets
- Pure Storage Flash Array
- Author
- Pure Storage
- Version
- v1.0
- Intent
- Incident Response
- Average rating
- No ratings yet
- Authorship
- Community