Atomic Runbook: Search IP Network Traffic in Chronicle
SkillSearchUse when querying UDM network connection events in Chronicle involving
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the Atomic Runbook: Search IP Network Traffic in Chronicle skill
What this skill tells your AI
The instructions your AI receives, as published by dandye/adk_runbooks in skills/atomic/ip-search-network-traffic-chronicle/SKILL.md and read by ahel’s review.
ID: RB-ATOM-IP-004
Version: 1.0
Last_Updated: 2025-05-30
Purpose: To perform a detailed search for network traffic events associated with a specific IP address in Chronicle SIEM using the search_security_events tool. This is typically used when a broader summary from lookup_entity is insufficient or indicates suspicious activity requiring deeper analysis.
Parent_Runbook(s)/Protocol(s): rules-bank/indicator_handling_protocols.md#1-atomic-indicator-ip-address, rb_ip_lookup_entity_chronicle.md
Trigger: When detailed network logs for an IP address are needed for investigation, often following an initial entity lookup or based on external threat intelligence.
Inputs Required
ip_address: string - The IP address to search for.- Source Example: Alert field, output from other enrichment runbooks.
hours_back(optional): integer - How many hours of historical data to search. Defaults to 24 if not provided.- Source Example: Analyst preference, default, or dynamically set.
max_events(optional): integer - Maximum number of event records to return. Defaults to 100.- Source Example: Default, or increased if a high volume of traffic is expected and needs review.
additional_query_terms(optional): string - Any additional UDM filter conditions to append to the query (e.g., "AND network.application_protocol = 'DNS'").- Source Example: Analyst input, or derived from context (e.g., investigating specific protocol activity).
Execution Steps
- Tool Selection:
- Primary_Tool_MCP_Server:
secops-mcp - Primary_Tool_Name:
search_security_events
- Primary_Tool_MCP_Server:
- Query Construction (for
textparameter of the tool):- Base query: "Network traffic where principal.ip is '{ip_address}' or target.ip is '{ip_address}'"
- Append time window: "... in the last {hours_back} hours"
- Append additional terms: " {additional_query_terms}" (if provided).
- Example
textvalue: "Network traffic where principal.ip is '192.168.1.100' or target.ip is '192.168.1.100' in the last 48 hours AND target.port = 445"
- Parameter Mapping:
- Map the constructed query string to MCP Tool parameter
text. - Map
hours_back(Input or default) to MCP Tool parameterhours_back. - Map
max_events(Input or default) to MCP Tool parametermax_events.
- Map the constructed query string to MCP Tool parameter
- Execute Tool: Call the
search_security_eventstool.- AI Agent Note: Refer to
rules-bank/mcp_tool_best_practices.mdfor guidance onsearch_security_events.
- AI Agent Note: Refer to
- Data Transformation/Extraction:
- The primary output is
events.events(a list of UDM event records). - AI agents may need to iterate through these events to extract key fields for summary or further processing.
- The primary output is
Outputs Expected
udm_events: list - A list of UDM event records matching the search criteria.translated_udm_query: string - The UDM query that was actually executed by Chronicle.total_events_matched: integer - The total number of events matching the query (may exceedmax_eventsreturned).output_status: string - ["Success", "NoEventsFound", "Failure"]- "NoEventsFound" indicates the tool ran successfully but found no matching events.
output_message: string (if Failure) - Details of the issue.
Decision Logic / Next Steps (If Applicable)
- IF
output_statusis "Success":- Log key findings from
udm_events(e.g., unique destination IPs/ports, protocols, data volumes, associated hostnames). - Analyze events for suspicious patterns (e.g., beaconing, large data transfers to unusual destinations, connections to known malicious infrastructure IPs from
rb_ip_get_gti_report.md). - Based on analysis, proceed to:
- Other atomic runbooks for related indicators (e.g.,
rb_domain_get_gti_report.mdif new domains are found). - Containment runbooks if malicious activity is confirmed (e.g.,
rules-bank/automated_response_playbook_criteria.mdfor blocking). - Escalation to human analyst if complex or ambiguous.
- Other atomic runbooks for related indicators (e.g.,
- Log key findings from
- IF
output_statusis "NoEventsFound":- Log "No network traffic found for IP {ip_address} matching criteria in Chronicle for the last {hours_back} hours."
- Consider if this lack of activity is itself suspicious depending on the IP's role and external reputation.
- ELSE (
output_statusis "Failure"):- Log error:
output_message. Reviewtranslated_udm_queryfor potential syntax issues if available. - Escalate to human analyst: "Failed to search network traffic for IP {ip_address} in Chronicle."
- Log error:
AI Agent Execution Notes
- Be cautious with very broad queries (e.g., long
hours_backwithout specificadditional_query_terms) as they can return excessive data or hit performance limits. - If
total_events_matchedis significantly higher thanmax_eventsreturned, the AI should note that only a subset of data was analyzed and consider if refined queries are needed to cover the remaining events. - The AI should correlate findings with
network_map.mdto understand if traffic is internal/external or crossing trust boundaries.
Metrics Collection Points
- Log execution time for this runbook.
- Log
output_status, number ofudm_eventsreturned, andtotal_events_matched. - (Reference
rules-bank/ai_performance_logging_requirements.md)
References
rules-bank/mcp_tool_best_practices.mdrules-bank/indicator_handling_protocols.mdrules-bank/analytical_query_patterns.mdrules-bank/ai_performance_logging_requirements.md
Signals
- GitHub stars
- 84
- Forks
- 14
- Last commit
- Sep 2026
Advanced
- Catalog kind
- skill
- Gateway key
ip-search-network-traffic-chronicle- Source
- github.com/dandye/adk_runbooks