IBM Support

Configuring automatic processing of inbound email in Resilient

Question & Answer


Question

In this course, you learn how to configure the Resilient platform to connect to an email inbox and create a rule that processes email messages by using a template with a Python script. As a result of the script, an incident is created with extracted artifacts form the email messages (such as IPs and URLs) and an email notification is sent to the incident owner. 

You can configure the IBM Security Resilient platform to create new incidents or update existing incidents from incoming email.

Objectives

  • Observe automated email parsing in action
  • Configure an inbound email connection
  • Customize a sample email script
  • Create a rule to trigger the script
  • Test the email processing

Duration: 1 Hour
Follow the link in related information to view the course on the IBM Security Learning Academy

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSIP9Q","label":"IBM Security SOAR"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Version","Edition":" ","Line of Business":{"code":"LOB77","label":"Automation Platform"}}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
13 August 2021

UID

ibm13577689