XSIAM-ANALYST · Question #13
While investigating an incident on the Incident Overview page, an analyst notices that the playbook encountered an error. Upon playbook work plan review, it is determined that the error was caused…
The correct answer is B. Pause the step with the error, thus automatically triggering the execution of the remaining steps. When a playbook encounters an error and the analyst does not have permissions to modify or recreate the playbook, the recommended action is to pause the step with the error. This will skip the problematic step and allow the remaining steps of the playbook to execute, ensuring…
Question
While investigating an incident on the Incident Overview page, an analyst notices that the playbook encountered an error. Upon playbook work plan review, it is determined that the error was caused by a timeout. However, the analyst does not have the necessary permissions to fix or create a new playbook. Given the critical nature of the incident, what can the analyst do to ensure the playbook continues executing the remaining steps?
Options
- ANavigate to the step where the error occurred and run the task again.
- BPause the step with the error, thus automatically triggering the execution of the remaining steps.
- CContact TAC to resolve the task error, as the playbook cannot proceed without it.
- DClone the playbook, remove the faulty step, and run the new playbook to bypass the error.
How the community answered
(55 responses)- A11% (6)
- B78% (43)
- C4% (2)
- D7% (4)
Explanation
When a playbook encounters an error and the analyst does not have permissions to modify or recreate the playbook, the recommended action is to pause the step with the error. This will skip the problematic step and allow the remaining steps of the playbook to execute, ensuring the investigation or response continues. "Pausing a failed step in the playbook work plan allows the remaining steps to continue executing, useful when immediate playbook edits are not possible due to permission restrictions."
Topics
Community Discussion
No community discussion yet for this question.