Security Operations Carbon Black Integration - Isolate Host Flow
The Security Operations Carbon Black Integration - Isolate Host is the implementation for the Carbon Black integration launched by the Security Operations Integration - Isolate Host flow.
Before you begin
Role required: sn_si.analyst
About this task
The flow process activities include:
- Execution Tracking - Begin (CIs) Flow Action
- Get IP from CI
- Collect Carbon Black configurations
- Capability Execution Tracking- Failure Flow Action
- Get Sensor ID
- Set Network Isolation Enabled activity
- Update Sensor - returns Isolate Host result.
- Capability Execution Tracking - Complete Flow Action
Image omitted: carbon-black-integration-isolate-host-flow-v1.png
Flow designer for Security Operations Carbon Black Integration - Isolate Host\[Omitted image "carbon-black-integration-isolate-host-flow-v1-2.png"\] Alt text: Flow designer for Security Operations Carbon Black Integration - Isolate Host
Flow designer for Security Operations Carbon Black Integration - Isolate Host\[Omitted image "carbon-black-integration-isolate-host-flow-v1-2.png"\] Alt text: Flow designer for Security Operations Carbon Black Integration - Isolate Host
Activities specific to this flow are described here. For more information on other activities, see Common Security Operations integration flows and orchestration activities.
- Get Sensor ID Flow Action
The Get Sensor ID flow action gathers sensor identifiers to use in the flow. - Set Network Isolation Enabled activity
The Set Network Isolation Enabled workflow activity enables network isolation. - Update Sensor activity
The Update Sensor workflow activity updates the sensor to isolate hosts or endpoints.
Parent Topic:Security Operations Integration- Isolate Host capability