<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Setting up classification &amp;amp; mapping for email ingest in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/setting-up-classification-amp-mapping-for-email-ingest/m-p/511151#M1101</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here are two different emails subject:&lt;/P&gt;
&lt;P&gt;1. Test email - Phishing Email&lt;/P&gt;
&lt;P&gt;2. Test email - Ping&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Two playbooks:&lt;/P&gt;
&lt;P&gt;1. Phishing Email&lt;/P&gt;
&lt;P&gt;2. Ping&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Currently I have setup two instances of integration "Mail Listener v2" with corresponding incident types so that phishing email will go to&amp;nbsp; playbook - phishing email and ping email will go to playbook - ping.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am looking for setting one instance of integration "Mail Listener v2" and using classification and mapping to send the alerts into different playbooks by keywords in subject. What I am trying to do is if the email subject contains "Phishing Email" and sender is from specific sender, then it will be sent to playbook - Phishing email", and similar actions for ping.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone know if this is possible or I have to keep using two instances for this setup? Thanks.&lt;/P&gt;</description>
    <pubDate>Sat, 06 Aug 2022 10:51:30 GMT</pubDate>
    <dc:creator>ce13</dc:creator>
    <dc:date>2022-08-06T10:51:30Z</dc:date>
    <item>
      <title>Setting up classification &amp; mapping for email ingest</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/setting-up-classification-amp-mapping-for-email-ingest/m-p/511151#M1101</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here are two different emails subject:&lt;/P&gt;
&lt;P&gt;1. Test email - Phishing Email&lt;/P&gt;
&lt;P&gt;2. Test email - Ping&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Two playbooks:&lt;/P&gt;
&lt;P&gt;1. Phishing Email&lt;/P&gt;
&lt;P&gt;2. Ping&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Currently I have setup two instances of integration "Mail Listener v2" with corresponding incident types so that phishing email will go to&amp;nbsp; playbook - phishing email and ping email will go to playbook - ping.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am looking for setting one instance of integration "Mail Listener v2" and using classification and mapping to send the alerts into different playbooks by keywords in subject. What I am trying to do is if the email subject contains "Phishing Email" and sender is from specific sender, then it will be sent to playbook - Phishing email", and similar actions for ping.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone know if this is possible or I have to keep using two instances for this setup? Thanks.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Aug 2022 10:51:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/setting-up-classification-amp-mapping-for-email-ingest/m-p/511151#M1101</guid>
      <dc:creator>ce13</dc:creator>
      <dc:date>2022-08-06T10:51:30Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up classification &amp; mapping for email ingest</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/setting-up-classification-amp-mapping-for-email-ingest/m-p/511173#M1102</link>
      <description>&lt;P&gt;What you're trying to do is definitely possible with a single Mail Listener + classifier, but you may need to rethink your classification logic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The classifier expects that a single field (+ filter + transformer set) will produce a (mostly) fixed list of values, and those values can be mapped onto incident types. This is simple and easy to do based solely on sender or receiver email addresses - each email address value goes to a different incident type. More complex logic (e.g. "it has X in the subject AND ...") may be possible, but you'd essentially need to fight to fit it within the classifier design, rather than it fitting neatly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, since you only get a single mapper object per mail listener, if you are currently using two different mappers you'll need to combine the mappers you're currently using into a single mapper. Mappers can have incident-type-specific mappings so you won't lose any custom logic in this process but it will be a little bit of extra work.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2022 01:04:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/setting-up-classification-amp-mapping-for-email-ingest/m-p/511173#M1102</guid>
      <dc:creator>chrking</dc:creator>
      <dc:date>2022-08-08T01:04:29Z</dc:date>
    </item>
  </channel>
</rss>

