Kaspersky Next XDR Expert

Editing alerts by using playbooks

Expand all | Collapse all

Kaspersky Next XDR Expert allows you to edit incidents manually or by using playbooks. When creating a playbook, you can configure the playbook algorithm to edit the alert properties.

To edit an alert by using a playbook, you must have one of the following XDR roles: Main administrator, SOC administrator, Tier 1 analyst, Tier 2 analyst, or Tenant administrator.

You cannot edit alerts that have the Closed status.

You can edit the following alerts properties by using the playbook:

  • Assignee
  • Alert status
  • Comment
  • ExternalReference attribute
  • Additional data attribute

Examples of the expressions that you can use in the playbook algorithm to edit the alert properties:

  • Assigning an alert to a user
  • Unassigning an alert from a user
  • Changing the alert status
  • Adding a comment to an alert
  • Editing the ExternalReference attribute
  • Editing the Additional data attribute