Scroll Top

Integrating Request Tracker (RT) with Energy SOAR

Request Tracker is enterprise grade ticketing system. Many organisations use Request Tracker for Incident Response (RTIR) to track, respond to and deal with reported security events

Request Tracker is enterprise grade ticketing system. Many organisations use Request Tracker for Incident Response (RTIR) to track, respond to and deal with reported security events.

In the following article we would like to introduce Request Tracker integration with Energy SOAR. This integration was tested with RT 5.0.2 and RTIR 5.0.1.

Using this integration you can take different actions. For example:

  • Search for tickets with queries,
  • Get ticket details,
  • Update tickets.

To configure RT on Energy SOAR just add instance details such as URL and user token.

Then add RT node to your workflow. In the following use case we get incidents, read ticket details and update the incident. You can extend the workflow by adding additional analysis nodes to update incidents with reputation information from Threat Intelligence regarding objects related to the incident.

To get tickets just fill out a query field:

To get a ticket details provide Ticket ID:

IDs can be taken dynamically from previous node using expressions:

The last node updates incident details. You can even update your custom fields:

We can observe in Energy SOAR that priority of all incidents has been changed.
You can integrate RTIR with Energy SOAR to get tickets, automatically analyze observables, take required actions, then finally close the resolved incident in RTIR.