How are Context Variables Maintained when Upgrading to 3.2 ?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

How are Context Variables Maintained when Upgrading to 3.2 ?

L4 Transporter

Hello Live Comm,

I am currently working on XSIAM 2.7 and I want to know what happens to context variables when upgrading the platform to 3.2.

2.7 has the incident and alert convention for variables such as alert.id or alert.hostname. If we have used these variables in a playbook or an automation what happens when the convention becomes issues and cases ? I can see that on the 3.2 version the variables become issue.id or parentIncidentFields.hostname. Does this mean that in order to upgrade smoothly we will need to review and rework all our playbooks and automations?

many thanks,

MSysec

PCSAE
1 accepted solution

Accepted Solutions

L4 Transporter

Interesting question..  we have playbooks developed in 2.7 with alert and incident fields.. and have migrated these to clients running 3.2 without any issue where they still reference ${alert.xxxx} and ${incident.xxxx).

From what I can see, in v3.2 it is still able to pull data ie ${alert.name} even though the context data shows ${issue.name} - so i think it does an auto rename in the backend - will check and confirm with our PAN SME this week when i meet with them.

but not sure how long this will be for.. so probably not a bad idea to amend playbooks to change alert > issue and incidents > cases

not sure why PAN decided to rename these in 3.x :- (

 

View solution in original post

1 REPLY 1

L4 Transporter

Interesting question..  we have playbooks developed in 2.7 with alert and incident fields.. and have migrated these to clients running 3.2 without any issue where they still reference ${alert.xxxx} and ${incident.xxxx).

From what I can see, in v3.2 it is still able to pull data ie ${alert.name} even though the context data shows ${issue.name} - so i think it does an auto rename in the backend - will check and confirm with our PAN SME this week when i meet with them.

but not sure how long this will be for.. so probably not a bad idea to amend playbooks to change alert > issue and incidents > cases

not sure why PAN decided to rename these in 3.x :- (

 

  • 1 accepted solution
  • 507 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!