Components
components are reusable workflow building blocks that combine actions, inputs, outputs, and interfaces so they can be reused across playbooks components, also known as vendor interaction components (vics), standardize vendor specific actions and data for use across playbooks components support two common use cases ingestion retrieve and transform third party data into ocsf/teds objects for use throughout a playbook enrichment retrieve and normalize additional context from external systems to support investigations, threat hunting, and response workflows choose your path i want to go to create a new component from the components library components listing page create a reusable component from actions on a playbook canvas create a component from playbook actions https //docs swimlane com/components#create a component from playbook actions (use group ) work with canvas tools on a playbook (select, cut, paste, group) organizing playbook in the canvas docid\ ds geaogh 2ujxg roys install a swimlane content component swimlane content components configure inputs, outputs, and interfaces data and interfaces export, duplicate, or delete a component components listing page mark a component as an ai agent or use the ai agents library ai agents in orchestration docid 4er81s1tgemt4h2rvruaw build or modify a component with hero ai create and modify components with hero ai docid\ ikukotgcorzumuwb jdsb run a component from hero ai chat hero ai companion docid\ crqkfvngpcz wj8xthds7 understand how hero ai executes components how hero ai executes components docid\ mgzx3dkiiv vi2mhoynev learn naming and interface best practices for ai enabled components ai friendly component best practices docid 3pknx5vxkqsjlltojro7b components listing page the components listing page provides a centralized view of all available components in your environment from this page, you can search for components, apply filters, review component details, and perform common management actions to access the components listing page log in to turbine from the left navigation pane, select orchestration click components search components use the search bar in the upper right corner of the page to quickly locate components you can search by component name component description the component list updates to display matching results as you type filter components use the filters at the top of the page to narrow the list of components created the created filter displays components based on when they were created select one of the available relative time ranges, including last 15 minutes last 30 minutes last 1 hour last 5 hours last 10 hours last 24 hours today yesterday last 2 days last 3 days last 7 days this week last week this month last month this year you can also select custom range to specify a start date and end date after selecting a range, click apply to update the list created by the created by filter displays components created by specific users you can search for a user by name select one or more users select all to display components created by every user last updated the last updated filter works the same way as the created filter filter components based on when they were last modified by selecting a predefined relative time range or a custom date range, then click apply last updated by the last updated by filter works the same way as the created by filter search for one or more users and select them to display components last updated by those users source use the source filter to display components based on their source available options include custom — components created by users swimlane content — components provided by swimlane you can search for a source and select one or more options interface use the interface filter to display components associated with specific interfaces you can search for an interface select one or more interfaces select all to display components with any interface visible to hero ai use the visible to hero ai filter to display components based on whether they are available for hero ai available options include yes no select one or more values to filter the component list sort components click the last updated column heading to sort the component list by the date the components were last modified click the column heading again to reverse the sort order component list columns the components listing page displays the following information for each component column description name displays the component name the component source (for example, custom ) is displayed below the component name created date the component was created created by user who created the component last updated date the component was last modified last updated by user who last modified the component interface the interface assigned to the component visible to hero ai indicates whether the component is available for use with hero ai component actions each component includes a more options (⋮) menu that provides additional management actions action description export export the component duplicate create a copy of the component delete permanently delete the component use + to open the new component dialog and create a component by default, all filters are set to all , and the page displays all components that you have permission to view you can apply multiple filters at the same time and use search with filters the search bar searches only the component name and description to reset a filter, select all from the corresponding filter dropdown component builder and canvas tools there are several ways to work with turbine components from the components listing page, you can create a new component from scratch or open an existing one in the component builder from a playbook canvas, you can turn a set of actions into a reusable component this section covers the component canvas ui for playbook canvas tools (multi select, edit menu , group , cut, copy, paste, and zoom), see organizing playbook in the canvas docid\ ds geaogh 2ujxg roys the component builder uses a drag and drop canvas where you add actions and nested components from the add panel on the left the add panel allows you to view, search, filter, sort, and drag actions and components onto the canvas components can be filtered by user made sorted by source or interface the component default view is alphabetical by user made, where you can easily expand or collapse the list to add a component, click on the desired component, then drag to the plus icon to the expanding responsive drop zone repeat to add additional components canvas tool panel and editor controls the component builder uses the same floating canvas tool panel as playbooks see organizing playbook in the canvas https //docs swimlane com/components#organizing playbook in the canvas for build with hero ai , toggle add panel , add annotation , edit menu , and undo / redo control location purpose test editor header (top) opens the test console at the bottom of the window shortcut ⌘⇧d (mac) / ctrl+shift+d (windows) save editor header (top) saves the component component details right side of the canvas shows summary , assets , data , and associations when you select the canvas or a node use edit on a node or ⌘⇧e / ctrl+shift+e to toggle the details panel zoom bottom of the canvas zoom in, zoom out, or fit the view to turn playbook actions into a component from a playbook canvas, use group in the edit menu — not a separate toolbar control see create a component from playbook actions https //docs swimlane com/components#create a component from playbook actions test a component you can validate component behavior using the test console to test a component open the component in the component builder click test in the editor header (or press ⌘⇧d / ctrl+shift+d ) configure the required inputs run the test review the execution results and outputs create a component from playbook actions from a playbook canvas, you can turn selected actions into a user made component use the same set of steps in the current playbook or drag the new component from the add panel into other playbooks scenario you built a playbook that lists emails, then runs two virustotal actions ( analyze a url and get analyses ) you want to reuse only the virustotal steps as virustotal analyze url group selected actions use group when you already have actions on the canvas and want to componentize them in one step open the playbook in the canvas editor in a single flow, hold shift and drag across the canvas to select a region that includes the actions you want open the canvas edit menu and click group , or press ⌘ g (mac) / ctrl+g (windows) in the new component dialog, enter a name (up to 50 characters; letters, numbers, and underscores only) see limitations https //docs swimlane com/components#limitations click save the grouped actions become one component node on the playbook the component is also available under components in the add panel and in your user content library group works on actions selected within one flow you cannot group across flows, playbook headers, or triggers if group is disabled, confirm you have at least one action selected and that the selection is valid for componentization ungroup a component to split a component back into individual actions on the canvas select the component node on the playbook canvas open the edit menu and click ungroup , or press ⌘⇧g (mac) / ctrl+shift+g (windows) in the warning dialog, click continue ungroup removes the component from the library attachment for that playbook, splits the steps on the canvas, and may remove interface, input, or output mappings where applicable create component from homepage to create a new, user made component, follow these steps from the components listing page, click the plus icon the new component dialog opens where you must enter a name and can add a description the name can be up to 50 characters and must contain only letters, numbers, and underscores see limitations https //docs swimlane com/components#limitations for the full rules click save to create the component and open the component canvas referring back to step 2, now that the component canvas is open, use the add panel to find the two crowdstrike vendor actions get ids and get incident details the example below walks you through the process of finding and adding the actions to the canvas from the add panel , ensure the actions tab is selected and the sort drop down has vendor for a quick search, filter by vendor click the filter icon and select crowdstrike the results show only the crowdstrike actions scroll through and select the desired actions, then click and drag each action onto the canvas you've successfully added actions to the component from here you can add/delete actions, configure, and/or modify them later the component is always accessible under user made components and in your content library save your work frequently! duplicate a component to duplicate a component navigate to orchestration > components locate the component click the ellipsis menu select duplicate export a component to export a component navigate to orchestration > components locate the component click the ellipsis menu select export delete a component to delete a component navigate to orchestration > components locate the component click the ellipsis menu select delete confirm the deletion deleted components cannot be recovered swimlane content components swimlane content components provide prebuilt ingestion and enrichment workflows that transform vendor specific data into standardized ocsf/teds formats using swimlane content components can accelerate playbook development reduce implementation effort with preconfigured workflows support large scale data ingestion improve investigation and response workflows through reusable enrichment patterns install a swimlane content component to install a swimlane content component navigate to library > swimlane content locate the component you want to install click install access the component from your content library or from the components tab in the add panel component details when creating a component, anytime you click on the canvas, the component details panel displays in the right hand side the table below describes the individual component detail tabs tab details summary contains the component name, description, source type, schema information, copy functionality, and hero ai settings assets displays available connector assets and allows assets to be assigned to connectors used by the component data displays interfaces, inputs, outputs, and configuration options for the component associations shows the number of dependent playbooks or components summary tab when visible to hero ai is enabled, a component description is required before the component can be saved components that use attachment inputs cannot be saved when visible to hero ai is enabled hero ai settings on a component hero ai settings are available only when hero ai is enabled for your tenant setting effect visible to hero ai allows hero ai companion to discover and run the component from chat a description is required when enabled components with attachment inputs cannot be saved when this setting is enabled requires confirmation to execute prompts users to confirm execution before hero ai runs the component this setting is enabled automatically when visible to hero ai is enabled, but it can be disabled mark as ai agent adds the component to the ai agents library full ai agent setup and usage instructions are documented in ai agents in orchestration component building mode allows hero ai to help create and modify components while working on the canvas visible to hero ai vs component building mode visible to hero ai and component building mode are different capabilities visible to hero ai allows hero ai companion to discover and execute the component from chat component building mode allows hero ai to help create and modify components while working on the canvas components that use attachment inputs cannot be saved when visible to hero ai is enabled components that use attachment inputs cannot be saved when visible to hero ai is enabled for guidance on names, descriptions, and interfaces that work well with hero ai and ai soc, see ai friendly component best practices # hero ai settings are configured from component details > summary related topics how hero ai executes components docid\ mgzx3dkiiv vi2mhoynevcreate and modify components with hero ai docid\ ikukotgcorzumuwb jdsbhero ai companion docid\ crqkfvngpcz wj8xthds7ai agents in orchestration docid 4er81s1tgemt4h2rvruaw data and interfaces interfaces define the expected data structure for a component components that use the same interface can be substituted without breaking existing input and output mappings when two components use the same interface, you can replace one with the other and preserve all mapped input and output fields each interface specifies what inputs a component accepts and what outputs it produces, promoting consistency and simplifying reuse across the canvas for example, a remediation interface might require fields such as observable and action type , ensuring that compatible components can be used interchangeably term definition defining characteristics component interface an interface defines the inputs and outputs expected by a component and enables compatible components to be used interchangeably used with components to assign an interface navigate to orchestration and select components create or open a component in the component builder click the data tab in the component details panel under the interface section, choose from available interfaces like object to alert v1 0 2 or error to enrichment v1 0 2 if you switch from a predefined interface to user defined , a dialog appears prompting you to either transfer available mappings into custom defined fields, or clear all mappings and start with a blank configuration this action cannot be undone, so review your current mappings before confirming user defined if none of the predefined interfaces match your use case, select user defined to manually configure the inputs and outputs using the component inputs manager this gives you full control over the data your component receives and returns supported input types include string – hostnames, file names, or email addresses number – severity scores, thresholds boolean – true/false flags object – structured fields with nested properties array – lists of strings, numbers, or objects attachment – file payloads or binary data once you save your configuration, these inputs appear under the inputs tab in the data panel and can be mapped like interface defined fields limitations limit value actions on the canvas no fixed maximum; add as many actions as your workflow requires component nesting depth up to 10 levels deep loop nesting depth up to 5 levels deep component run timeout (default) 4 hours total from start; extends by up to 1 hour per period of job activity component run timeout (maximum) 24 hours when set in the component manifest individual action timeout (default) 15 minutes for connector and most native actions action input and output size 20 mib per action component name length 50 characters maximum component name characters letters, numbers, and underscore only ( a–z , a–z , 0–9 , ) component description length 255 characters maximum for the full timeout and limit reference, see timeouts and limits # if a component name exceeds 50 characters or includes characters other than letters, numbers, or underscores, save can fail with an error shorten the name or replace spaces and special characters with underscores before you save you can edit the name on the component details panel summary tab at any time see also organizing playbook in the canvas docid\ ds geaogh 2ujxg roys — multi select, group , cut, copy, paste, and other playbook canvas tools ai agents in orchestration docid 4er81s1tgemt4h2rvruawhow hero ai executes components docid\ mgzx3dkiiv vi2mhoynevcreate and modify components with hero ai docid\ ikukotgcorzumuwb jdsbhero ai companion docid\ crqkfvngpcz wj8xthds7ai friendly component best practices docid 3pknx5vxkqsjlltojro7btimeouts and limits docid 3ofevwjnekrk dsscbqnx