Components
components are reusable workflow building blocks that combine actions, inputs, outputs, and interfaces so they can be reused across playbooks components, also known as vendor interaction components (vics), standardize vendor specific actions and data for use across playbooks components support two common use cases ingestion retrieve and transform third party data into ocsf/teds objects for use throughout a playbook enrichment retrieve and normalize additional context from external systems to support investigations, threat hunting, and response workflows choose your path i want to go to create a new component from the components library components homepage create a reusable component from actions on a playbook canvas create a component from playbook actions /#create a component from playbook actions (use group ) work with canvas tools on a playbook (select, cut, paste, group) organizing playbook in the canvas https //app archbee com/docs/wdlpsa7glls1ghfgxbo9d/ds geaogh 2ujxg roys install a swimlane content component swimlane content components configure inputs, outputs, and interfaces data and interfaces export, duplicate, or delete a component components homepage mark a component as an ai agent or use the ai agents library ai agents in orchestration https //app archbee com/docs/wdlpsa7glls1ghfgxbo9d/4er81s1tgemt4h2rvruaw build or modify a component with hero ai create and modify components with hero ai https //app archbee com/docs/wdlpsa7glls1ghfgxbo9d/ikukotgcorzumuwb jdsb run a component from hero ai chat hero ai companion https //app archbee com/docs/wdlpsa7glls1ghfgxbo9d/crqkfvngpcz wj8xthds7 understand how hero ai executes components how hero ai executes components https //app archbee com/docs/wdlpsa7glls1ghfgxbo9d/mgzx3dkiiv vi2mhoynev learn naming and interface best practices for ai enabled components ai friendly component best practices https //app archbee com/docs/wdlpsa7glls1ghfgxbo9d/3pknx5vxkqsjlltojro7b components homepage to access components, follow these steps log in to turbine from the left hand navigation pane, click orchestration and click components from the components homepage, you can see feature function title the component name shown for each swimlane content or user made component (same value as the name field) interface existing interfaces source custom (user made) or swimlane content updates recent updates made to the component search enter keyword(s) to search for a component filter use to sort by source, interface, or created by sort by use to sort by last modified, last created, or alphabetical arrow icon click to modify view between ascending results and descending results ellipsis icon click to export, duplicate, or delete plus icon click to open new component dialog new and define new component component builder and canvas tools there are several ways to work with turbine components from the components homepage, you can create a new component from scratch or open an existing one in the component builder from a playbook canvas, you can turn a set of actions into a reusable component this section covers the component canvas ui for playbook canvas tools (multi select, edit menu , group , cut, copy, paste, and zoom), see organizing playbook in the canvas https //app archbee com/docs/wdlpsa7glls1ghfgxbo9d/ds geaogh 2ujxg roys the component builder uses a drag and drop canvas where you add actions and nested components from the add panel on the left the add panel allows you to view, search, filter, sort, and drag actions and components onto the canvas components can be filtered by user made sorted by source or interface the component default view is alphabetical by user made, where you can easily expand or collapse the list to add a component, click on the desired component, then drag to the plus icon to the expanding responsive drop zone repeat to add additional components canvas tool panel and editor controls the component builder uses the same floating canvas tool panel as playbooks see organizing playbook in the canvas docid for build with hero ai , toggle add panel , add annotation , edit menu , and undo / redo control location purpose test editor header (top) opens the test console at the bottom of the window shortcut ββ§d (mac) / ctrl+shift+d (windows) save editor header (top) saves the component component details right side of the canvas shows summary , assets , data , and associations when you select the canvas or a node use edit on a node or ββ§e / ctrl+shift+e to toggle the details panel zoom bottom of the canvas zoom in, zoom out, or fit the view to turn playbook actions into a component from a playbook canvas, use group in the edit menu β not a separate toolbar control see create a component from playbook actions /#create a component from playbook actions test a component you can validate component behavior using the test console to test a component open the component in the component builder click test in the editor header (or press ββ§d / ctrl+shift+d ) configure the required inputs run the test review the execution results and outputs create a component from playbook actions from a playbook canvas, you can turn selected actions into a user made component use the same set of steps in the current playbook or drag the new component from the add panel into other playbooks scenario you built a playbook that lists emails, then runs two virustotal actions ( analyze a url and get analyses ) you want to reuse only the virustotal steps as virustotal analyze url group selected actions use group when you already have actions on the canvas and want to componentize them in one step open the playbook in the canvas editor in a single flow, hold shift and drag across the canvas to select a region that includes the actions you want open the canvas edit menu and click group , or press β g (mac) / ctrl+g (windows) in the new component dialog, enter a name (up to 50 characters; letters, numbers, and underscores only) see limitations /#limitations click save the grouped actions become one component node on the playbook the component is also available under components in the add panel and in your user content library group works on actions selected within one flow you cannot group across flows, playbook headers, or triggers if group is disabled, confirm you have at least one action selected and that the selection is valid for componentization ungroup a component to split a component back into individual actions on the canvas select the component node on the playbook canvas open the edit menu and click ungroup , or press ββ§g (mac) / ctrl+shift+g (windows) in the warning dialog, click continue ungroup removes the component from the library attachment for that playbook, splits the steps on the canvas, and may remove interface, input, or output mappings where applicable create component from homepage to create a new, user made component, follow these steps from the components homepage, click the plus icon the new component dialog opens where you must enter a name and can add a description the name can be up to 50 characters and must contain only letters, numbers, and underscores see limitations docid for the full rules click save to create the component and open the component canvas referring back to step 2, now that the component canvas is open, use the add panel to find the two crowdstrike vendor actions get ids and get incident details the example below walks you through the process of finding and adding the actions to the canvas from the add panel , ensure the actions tab is selected and the sort drop down has vendor for a quick search, filter by vendor click the filter icon and select crowdstrike the results show only the crowdstrike actions scroll through and select the desired actions, then click and drag each action onto the canvas you've successfully added actions to the component from here you can add/delete actions, configure, and/or modify them later the component is always accessible under user made components and in your content library save your work frequently! duplicate a component to duplicate a component navigate to orchestration > components locate the component click the ellipsis menu select duplicate export a component to export a component navigate to orchestration > components locate the component click the ellipsis menu select export delete a component to delete a component navigate to orchestration > components locate the component click the ellipsis menu select delete confirm the deletion deleted components cannot be recovered swimlane content components swimlane content components provide prebuilt ingestion and enrichment workflows that transform vendor specific data into standardized ocsf/teds formats using swimlane content components can accelerate playbook development reduce implementation effort with preconfigured workflows support large scale data ingestion improve investigation and response workflows through reusable enrichment patterns install a swimlane content component to install a swimlane content component navigate to library > swimlane content locate the component you want to install click install access the component from your content library or from the components tab in the add panel component details when creating a component, anytime you click on the canvas, the component details panel displays in the right hand side the table below describes the individual component detail tabs tab details summary contains the component name, description, source type, schema information, copy functionality, and hero ai settings assets displays available connector assets and allows assets to be assigned to connectors used by the component data displays interfaces, inputs, outputs, and configuration options for the component associations shows the number of dependent playbooks or components summary tab when visible to hero ai is enabled, a component description is required before the component can be saved components that use attachment inputs cannot be saved when visible to hero ai is enabled hero ai settings on a component hero ai settings are available only when hero ai is enabled for your tenant setting effect visible to hero ai allows hero ai companion to discover and run the component from chat a description is required when enabled components with attachment inputs cannot be saved when this setting is enabled requires confirmation to execute prompts users to confirm execution before hero ai runs the component this setting is enabled automatically when visible to hero ai is enabled, but it can be disabled mark as ai agent adds the component to the ai agents library full ai agent setup and usage instructions are documented in ai agents in orchestration component building mode allows hero ai to help create and modify components while working on the canvas visible to hero ai vs component building mode visible to hero ai and component building mode are different capabilities visible to hero ai allows hero ai companion to discover and execute the component from chat component building mode allows hero ai to help create and modify components while working on the canvas components that use attachment inputs cannot be saved when visible to hero ai is enabled components that use attachment inputs cannot be saved when visible to hero ai is enabled for guidance on names, descriptions, and interfaces that work well with hero ai and ai soc, see ai friendly component best practices # hero ai settings are configured from component details > summary related topics how hero ai executes components https //app archbee com/docs/wdlpsa7glls1ghfgxbo9d/mgzx3dkiiv vi2mhoynevcreate and modify components with hero ai https //app archbee com/docs/wdlpsa7glls1ghfgxbo9d/ikukotgcorzumuwb jdsbhero ai companion https //app archbee com/docs/wdlpsa7glls1ghfgxbo9d/crqkfvngpcz wj8xthds7ai agents in orchestration https //app archbee com/docs/wdlpsa7glls1ghfgxbo9d/r3yqj33rnpom0nvxb ocd data and interfaces interfaces define the expected data structure for a component components that use the same interface can be substituted without breaking existing input and output mappings when two components use the same interface, you can replace one with the other and preserve all mapped input and output fields each interface specifies what inputs a component accepts and what outputs it produces, promoting consistency and simplifying reuse across the canvas for example, a remediation interface might require fields such as observable and action type , ensuring that compatible components can be used interchangeably term definition defining characteristics component interface an interface defines the inputs and outputs expected by a component and enables compatible components to be used interchangeably used with components to assign an interface navigate to orchestration and select components create or open a component in the component builder click the data tab in the component details panel under the interface section, choose from available interfaces like object to alert v1 0 2 or error to enrichment v1 0 2 if you switch from a predefined interface to user defined , a dialog appears prompting you to either transfer available mappings into custom defined fields, or clear all mappings and start with a blank configuration this action cannot be undone, so review your current mappings before confirming user defined if none of the predefined interfaces match your use case, select user defined to manually configure the inputs and outputs using the component inputs manager this gives you full control over the data your component receives and returns supported input types include string β hostnames, file names, or email addresses number β severity scores, thresholds boolean β true/false flags object β structured fields with nested properties array β lists of strings, numbers, or objects attachment β file payloads or binary data once you save your configuration, these inputs appear under the inputs tab in the data panel and can be mapped like interface defined fields limitations limit value actions on the canvas no fixed maximum; add as many actions as your workflow requires component nesting depth up to 10 levels deep loop nesting depth up to 5 levels deep component run timeout (default) 4 hours total from start; extends by up to 1 hour per period of job activity component run timeout (maximum) 24 hours when set in the component manifest individual action timeout (default) 15 minutes for connector and most native actions action input and output size 20 mib per action component name length 50 characters maximum component name characters letters, numbers, and underscore only ( aβz , aβz , 0β9 , ) component description length 255 characters maximum for the full timeout and limit reference, see timeouts and limits # if a component name exceeds 50 characters or includes characters other than letters, numbers, or underscores, save can fail with an error shorten the name or replace spaces and special characters with underscores before you save you can edit the name on the component details panel summary tab at any time see also organizing playbook in the canvas https //app archbee com/docs/wdlpsa7glls1ghfgxbo9d/ds geaogh 2ujxg roys β multi select, group , cut, copy, paste, and other playbook canvas tools ai agents in orchestration https //app archbee com/docs/wdlpsa7glls1ghfgxbo9d/r3yqj33rnpom0nvxb ocdhow hero ai executes components https //app archbee com/docs/wdlpsa7glls1ghfgxbo9d/mgzx3dkiiv vi2mhoynevcreate and modify components with hero ai https //app archbee com/docs/wdlpsa7glls1ghfgxbo9d/ikukotgcorzumuwb jdsbhero ai companion https //app archbee com/docs/wdlpsa7glls1ghfgxbo9d/crqkfvngpcz wj8xthds7ai friendly component best practices https //app archbee com/docs/wdlpsa7glls1ghfgxbo9d/3pknx5vxkqsjlltojro7btimeouts and limits https //app archbee com/docs/wdlpsa7glls1ghfgxbo9d/3ofevwjnekrk dsscbqnx