<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic McAfee Integration not sending Summary of alerts to XSOAR for ingestion. in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/mcafee-integration-not-sending-summary-of-alerts-to-xsoar-for/m-p/518849#M1312</link>
    <description>&lt;P&gt;I have an integration between McAfee ESM (SIEM) that produces Alerts. 95% of alerts are received by the XSOAR including the "Summary" which is essentially the Alert Packet. Every few days some alerts are received that do not contain the summary. So essentially the time-stamp and the Alert Name appears yet there are no Summary details. The context data has been analysed and does not show any details.&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The Integration has is updated to the latest version.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;The McAfee ESM is of a recent version.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;This is a relatively new phenomenon yet no explanation has been found.&lt;/LI&gt;
&lt;LI&gt;A new integration has been defined with a new Instance in order to attempt to fix this problem, unfortunately without results.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;A playbook for Unclassified events has been set to attempt to retrieve the summary for every anomalous alert through the Instance. Which also doesn't work 100% of the time.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;The XSOAR is community edition.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I have two questions;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Does anyone have a solution or workaround for this problem ?&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Is there a way to ensure 100% Alert transfer for this usually static use case ?&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Thanks in advance.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XSOAR" id="Cortex_XSOAR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp; #McafeeESM&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 23 Oct 2022 07:25:17 GMT</pubDate>
    <dc:creator>michaelsysec242</dc:creator>
    <dc:date>2022-10-23T07:25:17Z</dc:date>
    <item>
      <title>McAfee Integration not sending Summary of alerts to XSOAR for ingestion.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/mcafee-integration-not-sending-summary-of-alerts-to-xsoar-for/m-p/518849#M1312</link>
      <description>&lt;P&gt;I have an integration between McAfee ESM (SIEM) that produces Alerts. 95% of alerts are received by the XSOAR including the "Summary" which is essentially the Alert Packet. Every few days some alerts are received that do not contain the summary. So essentially the time-stamp and the Alert Name appears yet there are no Summary details. The context data has been analysed and does not show any details.&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The Integration has is updated to the latest version.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;The McAfee ESM is of a recent version.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;This is a relatively new phenomenon yet no explanation has been found.&lt;/LI&gt;
&lt;LI&gt;A new integration has been defined with a new Instance in order to attempt to fix this problem, unfortunately without results.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;A playbook for Unclassified events has been set to attempt to retrieve the summary for every anomalous alert through the Instance. Which also doesn't work 100% of the time.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;The XSOAR is community edition.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I have two questions;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Does anyone have a solution or workaround for this problem ?&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Is there a way to ensure 100% Alert transfer for this usually static use case ?&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Thanks in advance.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XSOAR" id="Cortex_XSOAR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp; #McafeeESM&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Oct 2022 07:25:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/mcafee-integration-not-sending-summary-of-alerts-to-xsoar-for/m-p/518849#M1312</guid>
      <dc:creator>michaelsysec242</dc:creator>
      <dc:date>2022-10-23T07:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: McAfee Integration not sending Summary of alerts to XSOAR for ingestion.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/mcafee-integration-not-sending-summary-of-alerts-to-xsoar-for/m-p/518869#M1314</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/209373"&gt;@michaelsysec242&lt;/a&gt;, you'll need to check the data coming into the mapper to verify where the issue is. Screenshot below shows the raw vs mapped fields.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2022-10-24 at 1.28.44 pm.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44830i3B968105307C9DC9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2022-10-24 at 1.28.44 pm.png" alt="Screen Shot 2022-10-24 at 1.28.44 pm.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;1. Select the source of the alerts, this would McAfee ESM for you.&lt;/P&gt;
&lt;P&gt;2. Look at the raw data that is being sent from the API call. Ensure you can see the missing data here. If missing here its an API issue with McAfee's API.&lt;/P&gt;
&lt;P&gt;3. If the missing data is found above, map it to a field.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2022 02:36:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/mcafee-integration-not-sending-summary-of-alerts-to-xsoar-for/m-p/518869#M1314</guid>
      <dc:creator>jfernandes1</dc:creator>
      <dc:date>2022-10-24T02:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: McAfee Integration not sending Summary of alerts to XSOAR for ingestion.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/mcafee-integration-not-sending-summary-of-alerts-to-xsoar-for/m-p/518989#M1320</link>
      <description>&lt;P&gt;Thanks for your message. The incidents that do not contain the required "Summary" is not a mapping issue. Even after ingestion the Context Data doesn't contain any event details, just time stamps. As I mentioned before these are the same alerts that most of the time provide a static set of fields that do not change.&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/208028"&gt;@jfernandes1&lt;/a&gt;&amp;nbsp;is it recommended to speak with McAfee or PAN CSP regarding this issue ?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2022 08:07:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/mcafee-integration-not-sending-summary-of-alerts-to-xsoar-for/m-p/518989#M1320</guid>
      <dc:creator>michaelsysec242</dc:creator>
      <dc:date>2022-10-25T08:07:25Z</dc:date>
    </item>
  </channel>
</rss>

