Skip to content
Playbook All on Content Hub

Find and tag an existing indicator

Looks up an indicator by value and adds a tag to it.

@ftnt-dspilleMaintainer v1.0.0 Platform 7.4.0+ Published Aug 30, 2026
Download JSON · 4.3 KB

tag-existing-indicator.json

sha256:9692a8045600a5e76c51fe44507e56efde4db5e6d180a17f4dfc02090aeaf945

Sanitized by the pipeline and shipped inactive. Follow the before turning it on.

Shows the find-then-update pattern: query the Indicators module by value and update the match. Handy as a building block inside larger enrichment flows.

Something wrong with this item? Sign in to report

Report a problem

Sensitive data, copied content, broken imports, anything that shouldn't be here.

At least 10 characters. Please don't paste the sensitive value itself.0/1000