Security Operations Integration- Get Network Statistics capability
The Get Network Statistics capability retrieves a list of active network connections from a host or endpoint. It can be used for incident enrichment during investigations. This capability is triggered automatically when a configuration item is added to a security incident.
The Get Network Statistics capability has a flow, Security Operations Integrations - Get Network Statistics flow that accepts one or more CIs and tasks. The flow iterates over each implementation and each CI and re-invokes the implementation flow.
Note: If no implementations are available, capability actions are not displayed in product menus.
- Security Operations Integrations - Get Network Statistics flow
The Security Operations Integrations - Get Network Statistics flow retrieves a list of active network connections from a host or endpoint. - Security Incident Response- Get Network Statistics flow
The Security Incident Response > Get Network Statistics flow retrieves the network statistics for an affected Windows-based resource when added to a security incident in the Analysis state.
Parent Topic:Integration capabilities
Related topics
Security Operations Integration- Block Request capability
Security Operations Integration- Email Search and Delete capability
Security Operations Integration- Enrich CI capability
Security Operations Integration- Enrich Observable capability
Security Operations Integration- Get Running Processes capability
Security Operations Integration- Isolate Host capability
Security Operations Integration- Publish to Watchlist capability
Security Operations Integration- Sightings Search capability