Investigate Result

This task executes a query and adds the results as an investigation result to a ticket. Use it to attach relevant logs or data to a ticket so you can record and analyze an incident when a security incident or anomaly is discovered. For example, you can add logs of suspicious activity originating from a specific IP address.

Add investigation result

Command
The only available command is Add Investigate Result.
Input parameters
The input parameters for the Investigate Result task are as follows:
Ticket GUID*

Select or enter a parameter that holds the GUID of the ticket to add the investigation result to.

Subject*

Select String and specify the subject of the investigation result, or select a parameter from the Parameter list to use as the subject.

Query*

Enter the query that returns the investigation result to add. To use parameters from the Variables in the query, use the $("variable") format.

Description

Select String and enter a description of the investigation result, or select a parameter containing the description string from the Parameter list.

Variables

Click Add and select variables from the parameter list to use in the query. The parameter list shows parameters passed by preceding tasks or playbook input parameters. To use a variable value in the Query, use the $("variable") format.

To delete a variable from the variable list, select the checkbox in the variable row and click Delete.

When this task completes, the GUID of the created investigation result is returned in the output parameter guid.