Attaching playbooks to an alert

Chronicle SOAR allows for a total of 10 playbooks to be attached to an alert. Only 1 playbook can be attached automatically to a single alert. However, an additional 9 playbooks can be attached manually.

Add a playbook or playbook block to an alert

  1. Navigate to the Cases page.
  2. Click the alert, within a case, that the playbook or playbook block needs to be attached to.
  3. In the Playbooks tab, click Add Playbook on the right side of the screen. Choose the playbook or the playbook block to be added.
  4. If the selected playbook block requires input parameters, an Inputs dialog will appear. Either confirm the existing inputs or make the relevant input changes for the selected playbook block. If the playbook block does not require any input parameters, the Inputs dialog won't appear. 
  5. The added playbook block is displayed in the Playbooks tab in the case alert.