Threat Response Console
PRECINCT CONFIGURATION
- Go to Admin > SOAR > Cisco Threat Response > Config
- Click the checkbox for Enable Cisco Threat Response Integration
- Paste the Client ID Client Password
- Click the disk icon (Save)
- Click Jobs and go to Artifacts from Cisco Threat Response.
- Select Triggers, expanding Manual Trigger and Interval Trigger.
- Toggle both to State: ENABLED
- The Interval Trigger is set to 2 hours by default, but you can update it to what best suits your organization. (Recommended: 10 minutes)
- Click the disk icon (Save)
The Cisco Threat Response API Integration document can be found Here