When you initiate an action in
Device Security
that involves a third-party integration–for example sending an alert
or vulnerability or quarantining a device—the pop-up panel includes
a link that takes you to a
Cortex XSOAR
playbook to see an overview of
the task (referred to as "incident" in XSOAR) and the status of
each step in the playbook's flow, visually represented by the
work plan.
For
the link in Device Security to open the corresponding playbook in Cortex
XSOAR, you must already be logged in to your XSOAR instance before
clicking it.
The green boxes in the work plan indicate
that a particular step was successfully performed. Following the
path through the work plangives you feedback about whether an action
was carried out successfully or, if not, where the process changed
course.
Clicking
a box in a work plan opens a side panel in the Cortex XSOAR UI with
an explanation of that step.
This gives
you visibility into the integration workflow and assists you in
making changes if required.