Playbook properties

Every playbook has common properties. All properties except GUID can be viewed and changed in the properties panel.

Adding a playbook

GUID

The GUID is a unique playbook property that is not visible in the properties panel. It is automatically assigned when the playbook is created and appears in the web browser's address bar in the format /playbook/<GUID>.

GUIDs are unique values. Playbooks with the same GUID are considered identical, even if they have different names. Playbooks provided through Apps have pre-defined GUIDs assigned.

Name

A playbook name is a required property.

Description

A playbook description cannot exceed 2,000 characters.

Start type

The start type specifies when the playbook runs. Regardless of the start type, users can always run a playbook manually.

Playbook start type

Start typeRelated propertiesDescription
ManualInput/output parametersThe user runs the playbook directly, or it is called by another playbook
TicketScenario listRuns the playbook when a ticket is created by one or more specified scenarios
EventScenario listRuns the playbook when an event occurs in one or more specified scenarios
IndicatorStart conditionRuns the playbook when a specific indicator is added

Scenario list

The scenario list is a property defined when the Start Type is Ticket or Event. Select the scenarios that should trigger the playbook.

Scenario list

Input/output parameters

Playbook Input Parameter and Playbook Output Parameter play important roles in the task flow.

  • Playbook Input Parameter: Used as input to the task flow.
  • Playbook Output Parameter: Used to return values after all tasks complete.
Input parameters

When the start type is Ticket, Event, or Indicator, the input parameters are as follows:

Input parameterNameTicketEventIndicator
guidGUIDOO
titleTitleO
first_seenFirst seenOO
last_seenLast seenOO
priorityPriorityOO
src_ipSource IPOO
src_portSource portOO
dst_ipDestination IPOO
dst_portDestination portOO
protocolProtocolOO
useruserOO
host_ipHostOO
mail_fromMail senderOO
mail_toMail receiverOO
mail_ccMail CCOO
urlURLOO
md5MD5OO
URLURL O
MD5MD5 O
IPIP O
DomainDomain O
EmailEmail O

When the start type is Manual, you must define input parameters yourself. To add an input parameter, click the add (+) icon in the playbook input parameters section of the properties panel.

Adding an input parameter

  • Required: Select to mark the parameter as required.
  • Type: Data type (options: String, Date, Integer, Double, IP address, Boolean)
  • Parameter: The field name to use as the parameter.
  • Name: Display name of the parameter.
  • Description: A description of the parameter.

To edit an input parameter, click its Name.

To reorder input parameters, click the up or down arrow button in the parameter row in the desired direction.

To delete an input parameter, select the checkbox in the parameter row you want to delete and click the delete (trash can) icon.

Changing the input parameter order

Output parameters

Output parameters are chosen from the output variables of tasks in the playbook (if the playbook has no tasks, the selection list is empty). To add an output parameter, click the add (+) icon in the playbook output parameters section of the properties panel.

Adding an output parameter

Output parameters cannot be edited—they can only be deleted. To delete an output parameter, select the checkbox in the parameter row you want to delete and click the delete (trash can) icon.

Start condition

The start condition is a property defined when the Start Type is Indicator. Select one of the indicator types from the list (URL, MD5, IP, Domain, Email). The playbook runs automatically when an indicator of the matching type is registered.

Start condition