MatchIPinCIDRIndicators

Supported versions

Supported Cortex XSOAR versions: 6.0.0 and later.

Match provided IP address in all the Indicators of type CIDR with the provided tags (longest match).

Script Data


NameDescription
Script Typepython3
Tags
Demisto Version6.0.0

Inputs


Argument NameDescription
ipIP Address to match.
tagsTags to search (comma separated string).

Outputs


PathDescriptionType
MatchingCIDRIndicatorMatching CIDR IndicatorUnknown

Script Example

!MatchIPinCIDRIndicators ip="44.224.1.1" tags="AWS,GCP,Azure"

Context Example

{
"MatchingCIDRIndicator": {
"CustomFields": {
"region": "us-west-2",
"service": "EC2",
"tags": [
"AWS",
"AMAZON",
"EC2"
]
},
"expiration": "2020-11-30T22:46:50.594897749Z",
"expirationStatus": "active",
"firstSeen": "2020-11-23T22:04:13.912289994Z",
"id": "70575",
"lastSeen": "2020-11-23T22:15:06.02640521Z",
"score": 1,
"sourceBrands": [
"AWS Feed"
],
"sourceInstances": [
"AWS Feed_instance_1"
],
"value": "44.224.0.0/11"
}
}

Human Readable Output

Results

CustomFieldsexpirationexpirationStatusfirstSeenidlastSeenscoresourceBrandssourceInstancesvalue
region: us-west-2
service: EC2
tags: AWS,
AMAZON,
EC2
2020-11-30T22:46:50.594897749Zactive2020-11-23T22:04:13.912289994Z705752020-11-23T22:15:06.02640521Z1AWS FeedAWS Feed_instance_144.224.0.0/11