Relationships
Cortex XSIAM guidance for creating indicator relationships during enrichment.
The create_relationships parameter in integrations creates relationships between indicators.
- defaultvalue: 'true'
additionalinfo: Create relationships between indicators as part of enrichment.
display: Create relationships
name: create_relationships
required: false
type: 8To create a relationship:
Create an
EntityRelationshipobject with the relationship's data. If more than one relationship exists, create a list and append all of theEntityRelationshipobjects to it.EntityRelationship( name='contains', entity_a='1.1.1.1', entity_a_type='IP', entity_b='2.2.2.2', entity_b_type='IP', source_reliability='B - Usually reliable', brand='My Integration ID')When setting the name of the relationship, choose a value that appears in the the predefined list of relationships.
Use the
Commonobject when creating the indicator and in the relationships key set the list ofEntityRelationshipobjects.Use
CommandResultsto set the relationships key to the list ofEntityRelationshipobjects.
For more information about creating a relationship entity, see EntityRelationship.
Example integrations
Last updated
Was this helpful?
