Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Roll up lookup info to security incident activity

The Roll up lookup info to security incident activity can be used with any workflow to gather information from a threat lookup and output a summary of the contents as well as the ID of the originating security incident in task work notes.

Results

Possible results for this activity are:

ResultDescription
SuccessLookup report summary rolled up to security incident.
FailureOriginating task and lookup summary report are empty.
VariableDescription
scanID[string]Lookup identifier.

Output variables

The output variables contain data that can be used in subsequent activities.

VariableDescription
siId[string]Security incident identifier.
response [string]Summary of lookup results including: IoC value, Result, Failure reason, lookup reference, and so on.

Parent Topic:Common Security Operations integration flows and orchestration activities