Alert IP Metric Labeling (Add the IP indicator tag to the alert)
Playbook Overview
When a new alert added to SecMaster met the following conditions, the Add the IP indicator tag to the alert playbook synchronizes the label in the IP indicator to the label of the new alert.
- Condition 1: There are attack source IP addresses or target IP addresses in new alerts.
- Condition 2: The attack source IP address or destination IP address in new alerts is the same as the IP address in an existing IP indicator.
This playbook is applied to alerts only. Attacks cannot trigger it. For details about the differences between alerts and attacks, see Overview.
You need to enable this playbook manually.
Prerequisites
Your SecMaster professional edition is available.
Enabling a Playbook
In SecMaster, the initial version (V1) of the Add the IP indicator tag to the alert workflow is enabled by default. You do not need to manually enable it. The initial version (V1) of the Add the IP indicator tag to the alert playbook is also activated by default. To use it, you only need to enable it.
- Log in to the SecMaster console.
- In the navigation pane on the left, choose Workspaces > Management. In the workspace list, click the name of the target workspace. Figure 1 Workspace management page
- In the navigation pane on the left, choose Security Orchestration > Playbooks.
- On the Playbooks page, locate the row that contains the Add the IP indicator tag to the alert playbook and click Enable in the Operation column.
- In the dialog box displayed, select the initial playbook version v1 and click OK.
Implementation Effect
If the attack source IP address or destination IP address in a new alert is the same as the IP address in an existing IP indicator, the Add the IP indicator tag to the alert playbook synchronizes the label in the IP indicator to the label in the new alert.
- View the label of the IP indicator.
- For details about how to view indicators, see Viewing Indicators. In the navigation pane on the left in a specific workspace, choose to go to the indicator management page.
- On the Indicators page, click
in the upper right corner of the indicator list, select Labels to view the labels of an indicator in the indicator list.
- View the label of the new alert.
- For details about how to view alerts, see Viewing Alert Details. In the navigation pane on the left in a specific workspace, choose to go to the Alerts page.
- On the Alerts page, click
in the upper right corner of the alert list to customize the list items. Select Labels to view the label information of the alert in the list.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot