ZeroFox Alerts for Splunk SOAR
Supported Actions
- test connectivity: Validate the asset configuration for connectivity using supplied configuration
- on poll: Callback action for the on_poll ingest functionality
- take action: Take action on a ZeroFox an alert
- tag alert: Add or remove a tag to a ZeroFox alert
- threat submission: Add a manual threat to ZeroFox
- lookup alert: Retrieve a single alert and it's details, identified by its unique integer identifier
- modify notes: Append or replace notes on ZeroFox alert