The Add IOC to Watchlist Alert Action adds the specified IOCs to a report in a watchlist.

Note:

Configuration:

Watchlist
  • The name of the watchlist.
  • Matches exactly
  • If the watchlist does not exist, it will be created.
  • The watchlist name can be overwritten with a field value in the results. Fieldname: watchlist.
Report Name:
  • The name of the report on the watchlist.
  • Matches exactly
  • If the report does not exist, it will be created.
  • The report name can be overwritten with a field value in the results. Fieldname: report_name.
IOC Match Type
The type of IOC to add to the watchlist report. The type is either Equality or Query.
IOC Field
The field name in the search results that contains the IOC to add to the watchlist report.
Table 1. Supported Fields
src src_ip src_port
dest dest_ip dest_port
domain os process
process_name process_hash hash
user
Severity
  • The severity to assign to the Alert Action report IOC.
  • The severity assignment can be overwritten with a field value in the results. Fieldname: severity.