To create a work order for a security alert, click , select the security alert for the impacted device you noted,
and then click .
or
To create a work order for a vulnerability, click , click the name of the vulnerability you noted earlier,
select the device name in the Instances column, and then click .
The Send
to AIMS dialog box appears.
Choose someone to assign the work order to in the Assign
to list, choose a severity level in the Priority list, and enter a
note in the Add Comments field.
After you’ve
configured these three required settings, the Send button changes
from gray to blue, indicating that you can proceed.
Send the work order to AIMS.
After
you click Send, a link appears. When you
click it, a new browser window opens to the XSOAR playbook for this
action.
To confirm that the work order was sent, click the link to
the
XSOAR playbook for
this action.
For the link in Device Security to open the
corresponding playbook in Cortex XSOAR, you must already be logged
in to your XSOAR instance before clicking it.
The green
boxes in the playbook indicate that a particular step was successfully
performed. Following the path through the playbook gives you feedback
about whether an action was carried out successfully or, if not,
where the process changed course.
Also refresh the Security
Alerts or Vulnerability Details page and hover your cursor over
the entry in the Last Action column for the alert or the Vulnerability
Responses column for the vulnerability instance for which you sent
a work order.