Running a playbook of event records
To run a playbook of event records:
-
Go to t Investigations > Investigate.
-
Select an investigation from the list.
-
Click View Results to view the investigation results.
-
Right click on an entity to open the context menu and select Playbooks.
- Select a playbook from the list.
If the event record has matching variables in the playbook, then the variables will be populated with values from the event record.
-
Add or modify the values for the variables. For information see, Facet Search.
- Create a new investigation or add the playbook to an investigation.
Create a New Investigation Select this option to create a new investigation. Enter the Investigation Name and Description.
The default name for new investigations is the first and last name of the user creating the investigation as well as a date stamp of when the investigation was created.
Add to Existing Investigation
From the Choose Investigation dropdown, select and investigation.
-
Click Run Playbook.