<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Polling XDR Integration for Alerts that are not Incident Based in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/polling-xdr-integration-for-alerts-that-are-not-incident-based/m-p/536792#M1945</link>
    <description>&lt;P&gt;Just to update this thread, there is no suitable solution found and It may be possible that this is a recent change due to the 6.3 Update to XDR. Due to the lack of confirmation I will open a support ticket to escalate this matter.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Mar 2023 13:58:00 GMT</pubDate>
    <dc:creator>michaelsysec242</dc:creator>
    <dc:date>2023-03-28T13:58:00Z</dc:date>
    <item>
      <title>Polling XDR Integration for Alerts that are not Incident Based</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/polling-xdr-integration-for-alerts-that-are-not-incident-based/m-p/535400#M1928</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;I am running a Use-Case that requires me to poll the XDR Tenant for all alerts. These include Alerts that are found in an XDR Incident and Independent Alerts that are not found in an incident. For example a Low Severity alert from a BIOC Analytics Source that has not opened or should I say referenced in an incident. These Independent alerts are not retrieved with the "&lt;SPAN&gt;!xdr-get-alerts&lt;/SPAN&gt;" command. Even when querying for a specific Indipendant alert based on it's ID it is not retrieved. Does anyone have a solution for this ?&lt;/P&gt;
&lt;P&gt;There is no reason why these alerts shouldn't be available to be analysed on the XSOAR Platform.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the case that this is not possible, are the Alerts available for querying from the XQL Integration ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XSOAR" id="Cortex_XSOAR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 12:48:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/polling-xdr-integration-for-alerts-that-are-not-incident-based/m-p/535400#M1928</guid>
      <dc:creator>michaelsysec242</dc:creator>
      <dc:date>2023-03-22T12:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: Polling XDR Integration for Alerts that are not Incident Based</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/polling-xdr-integration-for-alerts-that-are-not-incident-based/m-p/535459#M1929</link>
      <description>&lt;P&gt;"&lt;SPAN&gt;&amp;nbsp;Even when querying for a specific Indipendant alert based on it's ID it is not retrieved. Does anyone have a solution for this ?&lt;/SPAN&gt;"&lt;/P&gt;
&lt;P&gt;Can you confirm if this is the case ? I think i saw an independent alert being fetched with case-id set to null&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 16:21:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/polling-xdr-integration-for-alerts-that-are-not-incident-based/m-p/535459#M1929</guid>
      <dc:creator>arnarayanan</dc:creator>
      <dc:date>2023-03-22T16:21:11Z</dc:date>
    </item>
    <item>
      <title>Re: Polling XDR Integration for Alerts that are not Incident Based</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/polling-xdr-integration-for-alerts-that-are-not-incident-based/m-p/535537#M1932</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/221822"&gt;@arnarayanan&lt;/a&gt;&amp;nbsp;I have double checked this when performing the command on all alerts from the past 24 Hours I see that only the incident based alerts are fetched. The problem remains.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 11:20:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/polling-xdr-integration-for-alerts-that-are-not-incident-based/m-p/535537#M1932</guid>
      <dc:creator>michaelsysec242</dc:creator>
      <dc:date>2023-03-23T11:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: Polling XDR Integration for Alerts that are not Incident Based</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/polling-xdr-integration-for-alerts-that-are-not-incident-based/m-p/535538#M1933</link>
      <description>&lt;P&gt;Hi ,Sorry, what i meant to ask is when you do an XDR-get-alert with a specific independent alert-id, what do you see as output on XSOAR.&amp;nbsp;&lt;BR /&gt;I am not an XDR expert, however i thought i saw XSOAR fetching an independent alert with case-id=null&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 11:33:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/polling-xdr-integration-for-alerts-that-are-not-incident-based/m-p/535538#M1933</guid>
      <dc:creator>arnarayanan</dc:creator>
      <dc:date>2023-03-23T11:33:09Z</dc:date>
    </item>
    <item>
      <title>Re: Polling XDR Integration for Alerts that are not Incident Based</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/polling-xdr-integration-for-alerts-that-are-not-incident-based/m-p/535542#M1934</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/221822"&gt;@arnarayanan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I perform this on a specific Alert ID that isn't incident related I receive the message that no alert has been fetched.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 12:49:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/polling-xdr-integration-for-alerts-that-are-not-incident-based/m-p/535542#M1934</guid>
      <dc:creator>michaelsysec242</dc:creator>
      <dc:date>2023-03-23T12:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: Polling XDR Integration for Alerts that are not Incident Based</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/polling-xdr-integration-for-alerts-that-are-not-incident-based/m-p/536792#M1945</link>
      <description>&lt;P&gt;Just to update this thread, there is no suitable solution found and It may be possible that this is a recent change due to the 6.3 Update to XDR. Due to the lack of confirmation I will open a support ticket to escalate this matter.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 13:58:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/polling-xdr-integration-for-alerts-that-are-not-incident-based/m-p/536792#M1945</guid>
      <dc:creator>michaelsysec242</dc:creator>
      <dc:date>2023-03-28T13:58:00Z</dc:date>
    </item>
    <item>
      <title>Re: Polling XDR Integration for Alerts that are not Incident Based</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/polling-xdr-integration-for-alerts-that-are-not-incident-based/m-p/567040#M2858</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;BR /&gt;I have the same problem. Does anyone found a solution for this?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2023 15:55:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/polling-xdr-integration-for-alerts-that-are-not-incident-based/m-p/567040#M2858</guid>
      <dc:creator>JoaoPGBotelho</dc:creator>
      <dc:date>2023-11-24T15:55:26Z</dc:date>
    </item>
    <item>
      <title>Re: Polling XDR Integration for Alerts that are not Incident Based</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/polling-xdr-integration-for-alerts-that-are-not-incident-based/m-p/592322#M3476</link>
      <description>&lt;P&gt;We lost a lot of alerts in XSOAR because of this limitation.&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/209373"&gt;@michaelsysec242&lt;/a&gt;&amp;nbsp;did you found any workaround?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2024 15:45:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/polling-xdr-integration-for-alerts-that-are-not-incident-based/m-p/592322#M3476</guid>
      <dc:creator>JoaoPGBotelho</dc:creator>
      <dc:date>2024-07-17T15:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: Polling XDR Integration for Alerts that are not Incident Based</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/polling-xdr-integration-for-alerts-that-are-not-incident-based/m-p/592598#M3488</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/144745"&gt;@JoaoPGBotelho&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;I still havent found a solution for this.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe try with the lastest content pack to see if this is patched.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jul 2024 10:44:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/polling-xdr-integration-for-alerts-that-are-not-incident-based/m-p/592598#M3488</guid>
      <dc:creator>michaelsysec242</dc:creator>
      <dc:date>2024-07-21T10:44:14Z</dc:date>
    </item>
  </channel>
</rss>

