Your playbook designer and the playbook define how emails are automatically associated with cases. In some cases, a case might be generated from an incoming email, for example, from a phishing threat service. In other cases, an incoming email might be associated with an existing case.
Your playbook designer can modify a template provided by IBM Security to process incoming email and automatically create tasks, set the case type and severity, and extract artifacts from the email. If the incoming email contains an attachment, the attachment can be added to the Attachments tab on the case.
The email is added to the Email tab of the case. From the Email tab, you can view the mailbox from which the email originated, the email sender, and the subject. If you have the required permissions, you can also download the email. To download an email, from the Email tab, click the download button to the right and select Download Email.
On the Artifacts tab, URLs or IP addresses from the email are displayed.