Creating rule for closing KUMA alert when R-Vision SOAR incident is closed
To create a rule for sending an alert closing request to KUMA when an R-Vision SOAR incident is closed:
In the R-Vision SOAR web interface, under Settings → Incident management → Response playbooks, click the plus icon.
In the Name field, type the name of the rule, for example, Close alert.
In the Group drop-down list select All playbooks.
In the Autostart criteria settings block, click Add and enter the conditions for triggering the rule in the opened window:
In the Type drop-down list, select Field value.
In the Field drop-down list, select Incident status.
Select the Closed status.
Click Add.
Rule trigger conditions are added. The rule will trigger when an incident is closed.
In the Incident Response Actions settings block, click Add→ Run connector. In the opened window, select the connector that should be run when the rule is triggered: