Set up the OSquery of External Address in the /etc/hosts file playbook
Freigeben Version: Australia
Aktualisiert 12. März 2026
1 Minute Lesedauer
Use the following steps to set up the OSquery of External Address in the /etc/hosts file playbook.
Vorbereitungen
Role required:
sn_si.admin
flow_designer
Make sure you have installed Security Operations Spoke (sn_sec_spoke).
Prozedur
Login as a user with sn_si.user and flow_designer roles.
Navigate to All > Flow Designer and select the OSquery External Address in /etc/hosts playbook.
Wahlweise: Create a copy of the OSquery External Address in /etc/hosts playbook flow and make the necessary modifications.
To create a copy of the playbook's flow, select the icon and select Copy flow. Perform this step only if you plan to customize or make specific changes to the flow.
Abbildung : 1. OSquery of External Address in /etc/hosts playbook
Activate the playbooks.
Activate the main flow to use the playbook available in the base system.
Activate the copied flows after making the required changes.
Set a Trigger Condition for the playbook.
This playbook is triggered and associated with the security incident when the Category is Insider Breach.
Abbildung : 2. OSquery of External Address in /etc/hosts playbook trigger condition