/
How to Update ThreatLink via the UseCase Library

How to Update ThreatLink via the UseCase Library

  • Download the following files for use with this installation:

    • Case Settings:

 

Upgrading ThreatLink: A Step-by-Step Guide

Follow these simple steps to upgrade your ThreatLink environment:

  1. Install the Latest Version:

  • Head over to the SOAR use case library.

  • Locate the newest ThreatLink version and install it.

  • During the installation, make sure to configure the necessary connections.

  • DO NOT start the new playbook stream.

  1. Import Case Settings:

  • Go to "Settings."

  • Select "Case Settings."

  • Choose "General."

  • Click "Import" and import the provided Case Setting JSON file from the top of this page.

  1. Update the Case Template:

  • Open the Case Template.

  • Add two new tabs: "Alert Queries" and "System Fields."

  • Populate these tabs with the associated fields (refer to the screenshot provided).

  1. (MSSP Instances Only) Set Up Child Domain Integrations:

  • If you're upgrading an MSSP instance with alerting in child domains, you'll need to set up new Devo integration connections.

  • Use the alert API for each child domain.

  • Make a note of the connection names for each child domain.

  1. (MSSP Instances Only) Configure Domain Connection List:

  • Open the "Domain Connection Custom List."

  • Map each child domain to its corresponding connection name.

  1. Activate the New Version:

  • Pause the old ThreatLink streams.

  • Start the new playbook streams.

That's it! You've successfully upgraded your ThreatLink environment.

Important Notes:

  • Make sure you have the necessary permissions to perform these actions.

  • If you encounter any issues during the upgrade process, refer to the ThreatLink documentation or contact support for assistance.

  • Always back up your existing configuration before performing an upgrade.

  • After the upgrade, test your ThreatLink playbooks thoroughly to ensure they function correctly.

Related content

Devo ThreatLink Overview
Devo ThreatLink Overview
More like this
Cisco ThreatGrid
Cisco ThreatGrid
More like this
Threatminer
Threatminer
More like this
Anomali Threat Indicator integration
Anomali Threat Indicator integration
More like this
Anomali Threat Indicator integration
Anomali Threat Indicator integration
More like this