Import AgentX playbooks
Import SOAR playbooks for automated investigation and incident response with AgentX.
Prerequisites
Logpoint v7.8.0 or later
SOAR enabled in Logpoint
AgentX playbooks .zip file downloaded from Help Center
Administrator access to Logpoint
Password for the .zip file (if password-protected)
Enable SOAR
Before importing playbooks, you must enable SOAR in Logpoint:
Go to Settings > System Settings and select System Settings.
Select General.
Select Enable SOAR in Logpoint.
Select Save.
Procedure
Go to SOAR Settings in the navigation bar and select System Export/Import.
Select Import.
Select Upload File and browse to the AgentX playbooks .zip file.
If the file is password-protected, enter the password.
Select Continue.
Review the package details to verify the import contents.
Select Import.
Wait for the import to complete. This may take several minutes.
Select Close when the import completes.
Expected outcome
AgentX playbooks appear in the Playbooks list and are ready for use in automated workflows.
Verification
Go to Playbooks in the navigation bar.
Search for "Logpoint AgentX" or "AgentX" in the playbook list.
Verify that AgentX playbooks appear, including:
Logpoint AgentX Ip-Block
Logpoint AgentX Process Dump
Logpoint AgentX Isolate-Unisolate Host
Logpoint AgentX Remove Item
Logpoint AgentX Terminate Process
Osquery Investigation playbooks
Configure AgentX APIs in SOAR
After importing playbooks, configure AgentX API integration:
Go to Settings > SOAR Settings and select Playbook Integrations.
Search for "AgentX" in Search Integration.
Select the ellipsis icon next to AgentX.
Select Configure Instance.
In manager_ip, enter your Logpoint IP address.
Select Save.
Next steps
Last updated
Was this helpful?