cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who rated this post

L1 Bithead

I wouldn't recommend that because if you get an incident with 500 IPs, XSOAR will execute the same playbook at the same time, and its not very efficient. I think the best is to focus on when you get an incident from, like if its from a specific integration and incident type

Who rated this post