Set up the Repeat Detection playbook
Use the following steps to set up the Repeat Detection playbook.
Before you begin
Role required:
- sn_si.admin
- flow_designer
Make sure you have installed Security Operations Spoke (sn_sec_spoke). You have an option to modify the following system properties:
sn_sec_spoke.similarphish.earlyterminationscoresn_sec_spoke.similarphish.lookbackdayssn_sec_spoke.similarphish.maxcomparisonsizesn_sec_spoke.similarphish.minmatchscore
Procedure
Login as a user with sn_si.user and flow_designer roles.
Navigate to All > Flow Designer and select the Repeat Detection playbook.
You can create a copy of the Repeat Detection playbook flow and make the necessary modifications.
To create a copy of the playbook's flow, select the
Image omitted: more-action-menu.png
More actions menu icon and select **Copy flow**. Perform this step only if you plan to customize or make specific changes to the flow.
More actions menu icon and select **Copy flow**. Perform this step only if you plan to customize or make specific changes to the flow.
Activate the playbooks.
- Activate the main flow to use the playbook available in the base system.
- Activate the copied flows after making the required changes.
- Set a Trigger Condition for the playbook.
This playbook is triggered when the Security Incident is not empty.
Parent Topic:Playbook for Repeat Detection