<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple Question realted to assign owner from playbook in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/multiple-question-realted-to-assign-owner-from-playbook/m-p/528124#M1684</link>
    <description>&lt;P&gt;For&amp;nbsp;&lt;SPAN&gt;step "Analyst to categorize",&amp;nbsp;its conditional task not Data collection&amp;nbsp;&lt;/SPAN&gt;Task.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kindly need advice, when Iam running the script "AssignAnalystToIncident"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;and I specify a specific User like Nadeema, I get all the Analysts with L2 Role as participant, although none of them was participated or added.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;find the screenshot below.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="users.JPG" style="width: 398px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47319i680C9F60120711E0/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="users.JPG" alt="users.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 23 Jan 2023 05:26:58 GMT</pubDate>
    <dc:creator>oDarweesh2</dc:creator>
    <dc:date>2023-01-23T05:26:58Z</dc:date>
    <item>
      <title>Multiple Question realted to assign owner from playbook</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/multiple-question-realted-to-assign-owner-from-playbook/m-p/527666#M1654</link>
      <description>&lt;P&gt;Guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I Have Phishing Playbook consists of two big parts:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;a- L1 Phishing playbook.&lt;/P&gt;
&lt;P&gt;b- L2 Phishing playbook.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The flow starts from L1 doing the needed automation and tasks like (Extracting IOCs, Headers, Doing Enrichment, making Splunk searches, .... etc.)&lt;/P&gt;
&lt;P&gt;Then it will stop at the stopping point which ask the Analyst to categorize which type this alert should it be.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then if L1 Categorized the alert as phishing, L2 will start with its tasks.&lt;/P&gt;
&lt;P&gt;L2 is sub playbook inside L1 only.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issues am taking about: is assigning owner from L1 to alert.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did before assign L1 automatically by using the automation script (assign owner to incident randomly)&lt;/P&gt;
&lt;P&gt;but it was getting any one from L1 to be the owner. and I tried it with other options like (assign current and online but none of them is accurate).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;because I want to assign the Incident to the user who did the categorization in the stopping point.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I used (assign to me button) inside the script. but it gives me error, as it need to be run manually and there is another option which can make the L1 to assign the task to other one. so, any idea how can I pass this issue?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was thinking if there is any idea to:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1- stop the categorization task, till L1 assign the incident to himself. but I don't know how to do it??&lt;/P&gt;
&lt;P&gt;2-make any task and based on it take the owner and assign him to the owner field, also I don't know how to do it??&lt;/P&gt;
&lt;P&gt;Any recommendations will help me a lot.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 08:59:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/multiple-question-realted-to-assign-owner-from-playbook/m-p/527666#M1654</guid>
      <dc:creator>oDarweesh2</dc:creator>
      <dc:date>2023-01-19T08:59:24Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Question realted to assign owner from playbook</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/multiple-question-realted-to-assign-owner-from-playbook/m-p/528106#M1683</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/224738"&gt;@oDarweesh2&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For step "&lt;SPAN&gt;Analyst to categorize" are you doing this with a Data Collection task? If so, the task can capture the user who completed the task the categorisation.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You can then use &lt;CODE&gt;setIncident owner=${&amp;lt;DC Task Name&amp;gt;.Answers.name}&lt;/CODE&gt; to assign the owner.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If the above is not possible. You can go via the API to grab warroom entries and check the owner for specific entries. This is more complicated and only recommended as a last resort.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 02:58:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/multiple-question-realted-to-assign-owner-from-playbook/m-p/528106#M1683</guid>
      <dc:creator>jfernandes1</dc:creator>
      <dc:date>2023-01-23T02:58:38Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Question realted to assign owner from playbook</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/multiple-question-realted-to-assign-owner-from-playbook/m-p/528124#M1684</link>
      <description>&lt;P&gt;For&amp;nbsp;&lt;SPAN&gt;step "Analyst to categorize",&amp;nbsp;its conditional task not Data collection&amp;nbsp;&lt;/SPAN&gt;Task.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kindly need advice, when Iam running the script "AssignAnalystToIncident"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;and I specify a specific User like Nadeema, I get all the Analysts with L2 Role as participant, although none of them was participated or added.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;find the screenshot below.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="users.JPG" style="width: 398px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47319i680C9F60120711E0/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="users.JPG" alt="users.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 05:26:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/multiple-question-realted-to-assign-owner-from-playbook/m-p/528124#M1684</guid>
      <dc:creator>oDarweesh2</dc:creator>
      <dc:date>2023-01-23T05:26:58Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Question realted to assign owner from playbook</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/multiple-question-realted-to-assign-owner-from-playbook/m-p/528145#M1685</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/224738"&gt;@oDarweesh2&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Running the&amp;nbsp;&lt;SPAN&gt;&lt;CODE&gt;AssignAnalystToIncident&lt;/CODE&gt; command with the roles parameter will assign the ticket to all the users that belong to that specific role. Run the command with the username parameter only.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you're using a conditional task approach&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Playbook steps I assume you currently have (Steps 1-3)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1. Assign the incident to the analyst&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. Analyst chooses the radio button option and clicks "Mark Completed". (Cannot be in quiet mode for custom automation solution)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3. Playbook step to set the Incident Categorisations&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;4. Custom automation that uses XSOAR REST API to URI&amp;nbsp;&lt;CODE&gt;/investigation/&amp;lt;Incident ID&lt;/CODE&gt;&amp;gt; (Check screenshot for more information) . In returned results find "Task Done" warroom entry for the conditional check in Step 2. Grab username who completed the task.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2023-01-23 at 7.19.59 pm.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47326i09B821CA6D410C60/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2023-01-23 at 7.19.59 pm.png" alt="Screen Shot 2023-01-23 at 7.19.59 pm.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;5. Assign the incident owner to the above username&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Recommended Approach.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As you can see the above approach is complicate and requires a custom automation. I would recommend the below approach.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Configure a Data Collection task to be a "Ask by Task". This is done by de-selecting all the options in "Select communication channels".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2023-01-23 at 7.08.46 pm.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47322i17A56D6D118E1195/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2023-01-23 at 7.08.46 pm.png" alt="Screen Shot 2023-01-23 at 7.08.46 pm.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Then create a field linked question.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2023-01-23 at 7.11.09 pm.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47323i66DBEEB0E959B7CC/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2023-01-23 at 7.11.09 pm.png" alt="Screen Shot 2023-01-23 at 7.11.09 pm.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;When the task is called it should look like the below during the playbook run.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2023-01-23 at 7.13.04 pm.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47324iAB50F6DA1B6D00D7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2023-01-23 at 7.13.04 pm.png" alt="Screen Shot 2023-01-23 at 7.13.04 pm.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;When the analyst selects an answer, the field is updated directly and the user who submitted the answer is also captured in the context.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2023-01-23 at 7.16.19 pm.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47325iD1EBD3485EE3DB50/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2023-01-23 at 7.16.19 pm.png" alt="Screen Shot 2023-01-23 at 7.16.19 pm.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 08:22:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/multiple-question-realted-to-assign-owner-from-playbook/m-p/528145#M1685</guid>
      <dc:creator>jfernandes1</dc:creator>
      <dc:date>2023-01-23T08:22:44Z</dc:date>
    </item>
  </channel>
</rss>

