Run Isolate Host
Isolate Host restricts system connections to other devices.
Before you begin
Role required: sn_si.analyst
About this task
Note: If no implementations are available, capability actions are not displayed in product menus.
The Security Operations Integration - Isolate Host or Endpoint flow can be triggered from the related list on a security incident.
Procedure
Navigate to a security incident.
Select Configuration Items from the Related List tab.
Select Isolate Host in the Actions on selected rows... drop-down menu.
The Isolate Host dialog box appears.
Choose the implementation.
Select Isolate Host.
The flow execution audit is displayed in the work notes section.
Parent Topic:Security Operations Integration- Isolate Host capability