Skip to main content

Workflow Template: Create a Torq Case from a Field Mapping JSON

Create a case in Torq using this workflow to take as input a JSON that includes fields and tables to describe an event.

The "Create a Torq Case from a Field Mapping JSON" workflow template streamlines case management by automating the creation of cases in Torq from a JSON input. This workflow is ideal for organizations looking to enhance their incident response efficiency by mapping event details, including custom fields and security contexts, directly into Torq cases. It supports the addition of comments, artifacts, and tables, ensuring comprehensive case documentation and facilitating effective incident tracking and resolution.

Use Cases

Case Management

Workflow Breakdown

  1. Take in a JSON with fields corresponding to event details, including custom fields, description, normalized security context and MITRE ATT&CK tactics and techniques.

  2. Extract description elements and format for display or ingestion to case creation step

  3. Create case in Torq

  4. Add additional information, such as comments, artifacts and tables

Vendors

Scripting, Utils, Torq Cases

Did this answer your question?