Details

This workflow performs a volume snapshot operation on the set of volumes configured on the Flash Array (On-Premises Target) using the names provided as an input variable. This operation is triggered by Cisco XDR to safeguard the volume data as a threat response, using action scripts in response to any critical alerts or incidents.

Description

Instructions:

  1. Ensure the remote automation server is set up and configured to establish a connection between the Cisco XDR and the On-Premises Pure Storage Flash Array.

  2. Configure the HTTP target for the On-Premises Pure Storage Flash Array within the Cisco XDR.

  3. Log in to the On-Premises Pure Storage Flash Array to fetch the API token. Add this token as a static variable in the workflow to establish the successful API call between the Cisco XDR and the Flash Array.
    reference link - https://support.purestorage.com/bundle/m_purityfa_rest_api/page/FlashArray/PurityFA/Purity_FA_REST_API/topics/task/t_client_configuration.html

  4. Update the input variable to the XDR workflow with the volume names for which snapshots are to be taken
    "Enter multiple source names in comma-separated format. For example, name01, name02."

  5. Optionally, configure an automation rule to run this workflow whenever an incident is triggered by any alerts or logs.
    Ensure the workflow is validated (this should occur automatically during installation); otherwise, it will not run.

Required targets

This workflow requires the following targets to be available before it can be run.

Custom targets

  • Pure Storage Flash Array
About
Author
Pure Storage
Version
v1.0
Intent
Incident Response
Average rating
No ratings yet
Authorship
Community
Contact and support information
External links