Skip to main content
Solved

Can we execute a retro hunt using the playbook based on the provided timeline?

  • January 16, 2025
  • 2 replies
  • 15 views

vanitharaj1208
Forum|alt.badge.img+14

is it possible to run retrohunt from playbook ?

Best answer by RanjithHegdeK

Hello @vanitharaj1208 

Yes its possible to execute Retro hunt from the playbook using Action "Execute Retrohunt" from GoogleChronicle. Rule ID, Start time and End time is required.

Reference: Google SecOps  |  Google Security Operations  |  Google Cloud

Thanks

2 replies

RanjithHegdeK
Forum|alt.badge.img+2
  • Bronze 1
  • Answer
  • January 16, 2025

Hello @vanitharaj1208 

Yes its possible to execute Retro hunt from the playbook using Action "Execute Retrohunt" from GoogleChronicle. Rule ID, Start time and End time is required.

Reference: Google SecOps  |  Google Security Operations  |  Google Cloud

Thanks


vanitharaj1208
Forum|alt.badge.img+14
  • Author
  • Silver 2
  • January 16, 2025

I have a rule that previously generated detections, but now when I attempt to run a retro hunt, it is not generating any alerts.