To create and activate a Normalize Artifact Playbook, perform the following procedure.
Procedure
- Open the Splunk SOAR console.
- In the left navigation bar, click Playbooks.
- Drag and release the blue node to get started. Select Action.
- From the Available Apps menu, select Carbon Black Cloud.
- From the Available Actions menu, select normalize artifact.
- From the Available Assets menu, select an asset.
Note: Polling on the asset must be disabled.
- Map two input parameters:
- Map
raw
to artifacts > _raw
.
- Map
artifact_id
to the id
field of the artifact headers.
- Drag the blue node to the END block. Enter the name of the playbook in the corresponding field.
- Click Save.
- Enter a comment to save the playbook. Click Save.
- Go to the Playbooks page. In the Status column, set the status of the playbook to Active.