ExpanseAggregateAttributionIP

Supported versions

Supported Cortex XSOAR versions: 6.0.0 and later.

Aggregate entries from multiple sources into AttributionIP

Script Data


NameDescription
Script Typepython3
Tags
Demisto Version6.0.0

Used In


This script is used in the following playbooks and scripts.

  • Expanse Attribution Subplaybook

Inputs


Argument NameDescription
inputInput list.
currentCurrent aggregation state.
source_ip_fieldsComma separated list of fields to treat as source IPs.
internal_ip_networksComma separated list of IPv4 Networks to be considered internal (default to RFC private networks).
sightings_fieldsComma separated list of field names to be considered sighting counts.

Outputs


PathDescriptionType
Expanse.AttributionIP.ipIP addressstring
Expanse.AttributionIP.privateIs the IP private?boolean
Expanse.AttributionIP.sightingsNumber of sessions seen on this devicenumber