<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mapping the Microsoft Security Graph to a custom incident type in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/mapping-the-microsoft-security-graph-to-a-custom-incident-type/m-p/393419#M194</link>
    <description>&lt;P&gt;Like I said, I am a beginner and when I discussed it with a coworker he pointed out to an automation that didn't take into account the recursion. This topic can thus be considered closed.&lt;/P&gt;</description>
    <pubDate>Wed, 24 Mar 2021 16:29:55 GMT</pubDate>
    <dc:creator>EVanderhasselt</dc:creator>
    <dc:date>2021-03-24T16:29:55Z</dc:date>
    <item>
      <title>Mapping the Microsoft Security Graph to a custom incident type</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/mapping-the-microsoft-security-graph-to-a-custom-incident-type/m-p/393415#M193</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am a noob in XSOAR, so if I am missing something obvious, my apologies.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I am working on a implementation where the system owner has set up a custom incident type for their Microsoft Security Graph API. The idea is now to do the mapping and I am stuck. The JSON contains the classic key value pairs but some of the values are actually arrays with dictionaries in them. For example&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hostStates:[{"fqdn":"host.domain.example","isAzureAdJoined":"false",...}]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to map the Hostnames field to the fqdn but I have no clue how to. I tried a couple of things already (hostStates.fqdn and hostStates[0]['fqdn']) without success.&lt;BR /&gt;&lt;BR /&gt;I noticed that in the examples I found online everybody has a nice key:value, nothing like what I am trying to do so this makes me wonder if what I am trying to do is actually possible via the web interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Like I said, this is a new tool for me and so every day I am learning something new.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Erik&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 16:10:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/mapping-the-microsoft-security-graph-to-a-custom-incident-type/m-p/393415#M193</guid>
      <dc:creator>EVanderhasselt</dc:creator>
      <dc:date>2021-03-24T16:10:56Z</dc:date>
    </item>
    <item>
      <title>Re: Mapping the Microsoft Security Graph to a custom incident type</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/mapping-the-microsoft-security-graph-to-a-custom-incident-type/m-p/393419#M194</link>
      <description>&lt;P&gt;Like I said, I am a beginner and when I discussed it with a coworker he pointed out to an automation that didn't take into account the recursion. This topic can thus be considered closed.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 16:29:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/mapping-the-microsoft-security-graph-to-a-custom-incident-type/m-p/393419#M194</guid>
      <dc:creator>EVanderhasselt</dc:creator>
      <dc:date>2021-03-24T16:29:55Z</dc:date>
    </item>
  </channel>
</rss>

