Actions
Create Case From Alert
Create a case from an existing alert.
Basic Parameters
Parameter | Description |
---|---|
Alert ID | The ID of the alert. |
Assignee | User to assign the case to. |
Sharing Parameters | - |
Status | - |
Title | - |
Advanced Parameters
Parameter | Description |
---|---|
Case Template | Name or id of the Case Template to use. |
Custom Fields | - |
Description | - |
End Date | - |
Flag | - |
Observable Rule | - |
PAP | Prioritized Asset Profile, the severity level that is used to indicate the importance of an asset.White: The asset is not critical.Green: The asset is important, but not critical.Amber: The asset is critical.Red: The asset is essential. |
Pages | - |
Severity | - |
Start Date | - |
Summary | - |
TLP | Traffic Light Protocol, a set of designations used to ensure that sensitive information is shared with the appropriate audience.CLEAR: unlimited formerly.GREEN: community-wide.AMBER: limited distribution.AMBER+STRICT: restricts sharing to the organization only.RED: personal for named recipients only. |
Tags | - |
Task Rule | - |
Tasks | Additional tasks to create. |
Example Output
Workflow Library Example
Create Case from Alert with Thehive and Send Results Via Email
Preview this Workflow on desktop