<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to re-pull QRadar case in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-re-pull-qradar-case/m-p/546610#M2246</link>
    <description>&lt;P&gt;Preprocess rules which drop incidents create an audit log entry when they do so, so it's worth taking a look in your audit log for the missing incidents to see if they're being dropped unexpectedly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You should also take a look at your filtering options on the QRadar integration - it's also possible that the missing incidents were never fetched in the first place.&lt;/P&gt;</description>
    <pubDate>Wed, 21 Jun 2023 00:45:37 GMT</pubDate>
    <dc:creator>chrking</dc:creator>
    <dc:date>2023-06-21T00:45:37Z</dc:date>
    <item>
      <title>how to re-pull QRadar case</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-re-pull-qradar-case/m-p/541880#M2130</link>
      <description>&lt;P&gt;Our client leverages QRadar as their SIEM.&lt;BR /&gt;&lt;BR /&gt;will pull in all cases and then have a pre-processing rule that drops any case that does not have "MSSP" in the name.&lt;BR /&gt;&lt;BR /&gt;This works 99% of the time, but there are certain times when MSSP cases get dropped and we don't we don't know why yet.&lt;BR /&gt;&lt;BR /&gt;Is there a way to "re-pull" Qradar cases from QRadar if the integration has already recognized them and dropped them.&lt;BR /&gt;&lt;BR /&gt;I basically want a command to call QRadar integration again for a specific offense and have it create an XSOAR case.&lt;BR /&gt;&lt;BR /&gt;Any thoughts or suggestions are appreciated -&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 17:20:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-re-pull-qradar-case/m-p/541880#M2130</guid>
      <dc:creator>JoshBoyd</dc:creator>
      <dc:date>2023-05-11T17:20:35Z</dc:date>
    </item>
    <item>
      <title>Re: how to re-pull QRadar case</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-re-pull-qradar-case/m-p/541898#M2132</link>
      <description>&lt;P&gt;You could always try and setup the same integration and have it classified with a different name and no pre-processing to see what could be getting missed with the pre-processing rule.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 19:26:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-re-pull-qradar-case/m-p/541898#M2132</guid>
      <dc:creator>Ivetto</dc:creator>
      <dc:date>2023-05-11T19:26:02Z</dc:date>
    </item>
    <item>
      <title>Re: how to re-pull QRadar case</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-re-pull-qradar-case/m-p/546610#M2246</link>
      <description>&lt;P&gt;Preprocess rules which drop incidents create an audit log entry when they do so, so it's worth taking a look in your audit log for the missing incidents to see if they're being dropped unexpectedly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You should also take a look at your filtering options on the QRadar integration - it's also possible that the missing incidents were never fetched in the first place.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 00:45:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-to-re-pull-qradar-case/m-p/546610#M2246</guid>
      <dc:creator>chrking</dc:creator>
      <dc:date>2023-06-21T00:45:37Z</dc:date>
    </item>
  </channel>
</rss>

