Hello Team,
I need help building a SOAR playbook using a custom list in the Google SecOps platform. I’ve added the entity details with categories to the custom list and created a playbook to check those values against alerts. However, when I run the playbook, it seems to fail and goes to the 'else' condition instead of recognizing the matches.
I’ve tried adding the category and the actual values into the previous action condition block using both OR and AND conditions, but it still fails. Although I’ve defined the category in the custom list, it doesn’t seem to work.
Can anyone assist me in defining the conditions in the block to match these scenarios for false positive alert flows? I’ve also been working on use cases for EDR false positive alerts and certain cloud accounts where we expect a couple of alerts, and I want to ignore those alerts from the custom list.
I even tried running a simulator to test the flow. In the custom list option, I can see that it is taking the value I input, but it seems unable to verify against the actual custom list. The value I included in the SOAR playbook block is already present in the custom list.
Thanks,
Dnyaneshwar