Create a job triggered by a delta in a feed
Create feed-delta jobs in Cortex XSOAR 8 SaaS.
Jobs triggered by a delta in a feed (event triggered jobs) run when a feed completes an operation and there is a change in the content. For the job to trigger, there must be a delta between the incoming feed and the previous one. You can define a job to trigger a playbook when the specified feed or feeds finish a fetch operation that includes a modification to the feed. The modification can be a new indicator, a modified indicator, or a removed indicator. For example, you may want to update your firewall every time a URL is added, modified, or removed from the Office 365 feed. You can configure a job that triggers the firewall update playbook to run whenever a modification is made to the feed.
For an example of using a job triggered by a delta in a feed, see the Create jobs to process indicators example.
Select Jobs → New Job.
Select Triggered by delta in feed.
Add or create any relevant tags to use as a search parameter in the system.
In the Trigger section, select one of the following:
Any feed: The playbook runs when a modification is made to any feed.
Specific feeds: Select the feed instances that will trigger the playbook to run when a modification is made to them.
In the BASIC INFORMATION section:
Add a meaningful name for the job.
Select the playbook you want to run when the conditions for the job are met.
Create new job.
Last updated
Was this helpful?
