Open
Description
Actions requirements:
- Users should be able to make bulk actions by quick action on a group or sub-group
- Actions on bulk alerts should have a confirmation dialog box
- Quick actions include:
Default: Add to case (existing), Close, Acknowledge
if group containshost
(then isolate) (prerreq using endpoint integration)
If group containsrule
(then add exception)
if group containsprocess.name
(or pid, entity.id, etc.), then endpoint could “terminate process”
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment