<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Creating an XSOAR Incident from Splunk in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/creating-an-xsoar-incident-from-splunk/m-p/546719#M2249</link>
    <description>&lt;P&gt;Hey team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We tried to push splunk alerts to XSOAR and we used the Splunk create XSOAR incident.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Splunk logs show that it was successful, but we do not see any incidents in XSOAR.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0cm;"&gt;&lt;SPAN&gt;apparently 06-19-2023 16:33:01.558 +0000 INFO sendmodalert [373426 AlertNotifierWorker-0] - action=create_xsoar_incident - Alert action script completed in duration=1480 ms with exit code=0&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there something missing from our end?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;#xsoar #splunk&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 21 Jun 2023 13:44:17 GMT</pubDate>
    <dc:creator>Moh.Yasser</dc:creator>
    <dc:date>2023-06-21T13:44:17Z</dc:date>
    <item>
      <title>Creating an XSOAR Incident from Splunk</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/creating-an-xsoar-incident-from-splunk/m-p/546719#M2249</link>
      <description>&lt;P&gt;Hey team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We tried to push splunk alerts to XSOAR and we used the Splunk create XSOAR incident.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Splunk logs show that it was successful, but we do not see any incidents in XSOAR.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0cm;"&gt;&lt;SPAN&gt;apparently 06-19-2023 16:33:01.558 +0000 INFO sendmodalert [373426 AlertNotifierWorker-0] - action=create_xsoar_incident - Alert action script completed in duration=1480 ms with exit code=0&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there something missing from our end?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;#xsoar #splunk&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 13:44:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/creating-an-xsoar-incident-from-splunk/m-p/546719#M2249</guid>
      <dc:creator>Moh.Yasser</dc:creator>
      <dc:date>2023-06-21T13:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: Creating an XSOAR Incident from Splunk</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/creating-an-xsoar-incident-from-splunk/m-p/546753#M2252</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/290616"&gt;@Moh.Yasser&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dear Yasser,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;for creating incidents on xsoar from splunk, you need integration called splunk pycharm, and additionally you have to have an app configured in splunk , so that the app can trigger incidents on xsoar. dm me if u need any additional info. &lt;A href="mailto:michaelusatx@gmail.com" target="_blank"&gt;michaelusatx@gmail.com&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;cheers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 16:44:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/creating-an-xsoar-incident-from-splunk/m-p/546753#M2252</guid>
      <dc:creator>michaeljohnson123</dc:creator>
      <dc:date>2023-06-21T16:44:55Z</dc:date>
    </item>
    <item>
      <title>Re: Creating an XSOAR Incident from Splunk</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/creating-an-xsoar-incident-from-splunk/m-p/548351#M2288</link>
      <description>&lt;P&gt;"We tried to push splunk alerts to XSOAR" - I'm assuming this means you're using the Demisto Add-on for Splunk. This is not the recommended way to get incidents into XSOAR for precisely the reason you've discovered - it is difficult to troubleshoot issues, and issues will cause incidents to be silently lost rather than raising errors.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The standard, recommended method uses queries from the XSOAR side, which will have logs to allow you to debug the issue in case of errors.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you *need* to use the Demisto add-on for some reason, I'd suggest checking your network from splunk to XSOAR, as well as making sure you have the appropriate instance.execute.external key set on the XSOAR side. Given the lack of proper logs you may need to use tcpdump to debug the issue.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 04:31:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/creating-an-xsoar-incident-from-splunk/m-p/548351#M2288</guid>
      <dc:creator>chrking</dc:creator>
      <dc:date>2023-07-06T04:31:20Z</dc:date>
    </item>
  </channel>
</rss>

