Check Point Exposure Management - Manual Status Update (Sentinel → Argos)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


On-demand playbook that reads the current Sentinel incident status and pushes it to the corresponding alert(s). Triggered manually from the incident actions menu.

Attribute Value
Type Playbook
Solution Check Point Cyberint Alerts
Source View on GitHub

Additional Documentation

📄 Source: Sync/CPEM_ManualStatusUpdate/readme.md

Summary

On-demand playbook that reads the current Sentinel incident status and pushes it to the corresponding alert(s). Analysts trigger this manually from the incident Actions menu when they want to explicitly sync status to Argos.

Flow: 1. Calls Check_Point_EM_Base to retrieve API credentials. 2. Reads the current incident status and close classification. 3. Maps Sentinel status → Argos status and closure reason. 4. For each linked alert, sends HTTP PUT to update the alert status. 5. Adds a sync result comment and tags the incident argos-manual-synced.

Prerequisites

  1. Check_Point_EM_Base playbook must be deployed in the same resource group.
  2. A valid Check Point Exposure Management API token configured in the Check_Point_EM_Base Key Vault.

Deployment

Deploy to Azure

Parameters

Parameter Required Description
PlaybookName No Name of the Logic App (default: Check_Point_EM_ManualStatusUpdate)
Check_Point_EM_Base_PlaybookName No Name of the base playbook (default: Check_Point_EM_Base)

Post-Deployment

  1. Grant the Logic App Managed Identity the Microsoft Sentinel Responder role on the resource group.
  2. Analysts can run this playbook from the Sentinel incident Actions > Run playbook menu.

Status Mapping

Sentinel Status Sentinel Classification Argos Status Argos Closure Reason
Active open
Closed True Positive closed resolved
Closed False Positive closed false_positive
Closed Benign Positive closed no_longer_a_threat
Closed Undetermined closed other

API Endpoints Used

Action Endpoint
Update alert status PUT /api/v1/alerts/{alert_ref_id}

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Playbooks · Back to Check Point Cyberint Alerts