<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Create script to close XDR alerts from XSOAR. in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/create-script-to-close-xdr-alerts-from-xsoar/m-p/516147#M1240</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/226640"&gt;@Josep&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The current XDR integration does not have a command to update alerts. I would suggest raising a Feature Request at &lt;A href="https://xsoar.ideas.aha.io/ideas" target="_blank"&gt;https://xsoar.ideas.aha.io/ideas&lt;/A&gt;. You can also write the additional API call yourself if required, refer&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-api/cortex-xdr-apis/incident-management/update-an-alert" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-api/cortex-xdr-apis/incident-management/update-an-alert&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once you have the API call and the command added to the integration, you can configure a post-processing script to run when the XSOAR incident is closed. This script can be configured to close all related XDR alerts.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 28 Sep 2022 01:18:24 GMT</pubDate>
    <dc:creator>jfernandes1</dc:creator>
    <dc:date>2022-09-28T01:18:24Z</dc:date>
    <item>
      <title>Create script to close XDR alerts from XSOAR.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/create-script-to-close-xdr-alerts-from-xsoar/m-p/516095#M1237</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;XSOAR and XDR are used with mirroring, when an incident is closed from XSOAR it's closed in XDR too. However, the alerts in XDR are not. So an script is needed in XSOAR to close those XDR alerts. How is this is script done? where should be set? How to sync all up?&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 16:23:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/create-script-to-close-xdr-alerts-from-xsoar/m-p/516095#M1237</guid>
      <dc:creator>Josep</dc:creator>
      <dc:date>2022-09-27T16:23:51Z</dc:date>
    </item>
    <item>
      <title>Re: Create script to close XDR alerts from XSOAR.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/create-script-to-close-xdr-alerts-from-xsoar/m-p/516147#M1240</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/226640"&gt;@Josep&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The current XDR integration does not have a command to update alerts. I would suggest raising a Feature Request at &lt;A href="https://xsoar.ideas.aha.io/ideas" target="_blank"&gt;https://xsoar.ideas.aha.io/ideas&lt;/A&gt;. You can also write the additional API call yourself if required, refer&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-api/cortex-xdr-apis/incident-management/update-an-alert" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-api/cortex-xdr-apis/incident-management/update-an-alert&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once you have the API call and the command added to the integration, you can configure a post-processing script to run when the XSOAR incident is closed. This script can be configured to close all related XDR alerts.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 01:18:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/create-script-to-close-xdr-alerts-from-xsoar/m-p/516147#M1240</guid>
      <dc:creator>jfernandes1</dc:creator>
      <dc:date>2022-09-28T01:18:24Z</dc:date>
    </item>
  </channel>
</rss>

