<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: QRadar integration error: Failed to execute qradar-searches command (EDITED). in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/qradar-integration-error-failed-to-execute-qradar-searches/m-p/547014#M2263</link>
    <description>&lt;P&gt;Solved: the problem was in the query used to pull offense. There are some change not detected and, once fixed, it worked fine again.&lt;/P&gt;</description>
    <pubDate>Fri, 23 Jun 2023 14:24:35 GMT</pubDate>
    <dc:creator>lsepe434</dc:creator>
    <dc:date>2023-06-23T14:24:35Z</dc:date>
    <item>
      <title>QRadar integration error: Failed to execute qradar-searches command (EDITED).</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/qradar-integration-error-failed-to-execute-qradar-searches/m-p/536927#M1950</link>
      <description>&lt;P&gt;Hi all, I have a problem with QRadar integration. Let me summarize my environment and basic configuration.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Cortex XSoar version:&lt;/STRONG&gt;&amp;nbsp;&lt;SPAN&gt;6.10.0&lt;BR /&gt;&lt;STRONG&gt;QRadar integration version:&amp;nbsp;&lt;/STRONG&gt;IBM QRadar v3&lt;BR /&gt;&lt;STRONG&gt;Mapper:&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;QRadar - Generic Incoming Mapper&lt;BR /&gt;&lt;STRONG&gt;Incident type:&lt;/STRONG&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Qradar Generic&lt;BR /&gt;&lt;STRONG&gt;Event an fields to return from the events query:&amp;nbsp;&lt;/STRONG&gt;QIDNAME(qid), LOGSOURCENAME(logsourceid), CATEGORYNAME(highlevelcategory), CATEGORYNAME(category), PROTOCOLNAME(protocolid), sourceip, sourceport, destinationip, destinationport, QIDDESCRIPTION(qid), username, PROTOCOLNAME(protocolid), RULENAME("creEventList"), sourcegeographiclocation, sourceMAC, sourcev6, destinationgeographiclocation, destinationv6, LOGSOURCETYPENAME(devicetype), credibility, severity, magnitude, eventcount, eventDirection, postNatDestinationIP, postNatDestinationPort, postNatSourceIP, postNatSourcePort, preNatDestinationPort, preNatSourceIP, preNatSourcePort, UTF8(payload), starttime, devicetime &lt;STRONG&gt;(Note: it is the default one).&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The connection with QRadar istance works fine and I'm able to fetch offenses.&lt;BR /&gt;When an incident is pulled, for every incident, the associated PlayBook ends with following error:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="row entry-parent"&gt;
&lt;DIV class="floated left aligned sixteen wide mobile six wide tablet sixteen wide computer column"&gt;
&lt;DIV class="entry-metadata"&gt;
&lt;DIV class="entry-task-status semi-bold error"&gt;&lt;SPAN&gt;Task Error&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="entry-task-name"&gt;
&lt;DIV class="inner-entry-task-name"&gt;&lt;STRONG&gt;&lt;SPAN&gt;#270:&lt;/SPAN&gt;&lt;/STRONG&gt;&amp;nbsp;Run QRadar search&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="entry-view vertical-strech entry-error"&gt;
&lt;DIV class="vertical-strech demisto-data"&gt;
&lt;DIV&gt;&lt;SPAN class="entry-task-reason"&gt;&lt;STRONG&gt;&lt;SPAN&gt;Reason&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;
&lt;DIV class="entry-note-view" data-test-id="entry-note-markdown"&gt;
&lt;DIV&gt;
&lt;DIV class="entry-markdown-view"&gt;
&lt;DIV class="preplacer"&gt;Playbook &lt;STRONG&gt;QRadar Generic&lt;/STRONG&gt; execution error&lt;BR /&gt;&lt;BR /&gt;
&lt;DIV class="row entry-parent"&gt;
&lt;DIV class="floated left aligned sixteen wide mobile six wide tablet sixteen wide computer column"&gt;
&lt;DIV class="entry-metadata"&gt;
&lt;DIV class="entry-task-status semi-bold result error"&gt;&lt;SPAN&gt;QRadar v3 returned an error&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="entry-task-name"&gt;
&lt;DIV class="inner-entry-task-name"&gt;&lt;STRONG&gt;&lt;SPAN&gt;#270:&lt;/SPAN&gt;&lt;/STRONG&gt;&amp;nbsp;Run QRadar search&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="entry-task-command"&gt;&lt;STRONG&gt;&lt;SPAN&gt;Command:&lt;/SPAN&gt;&lt;/STRONG&gt;&amp;nbsp;
&lt;DIV class="display-parent-entry"&gt;&lt;SPAN class="parent-entry-label ellipsis show-as-link" title="!qradar-searches query_expression=&amp;quot;select  QIDNAME(qid), LOGSOURCENAME(logsourceid), CATEGORYNAME(highlevelcategory), CATEGORYNAME(category), PROTOCOLNAME(protocolid), sourceip, sourceport, destinationip, destinationport, QIDDESCRIPTION(qid), username, PROTOCOLNAME(protocolid), RULENAME(\&amp;quot;creEventList\&amp;quot;), sourcegeographiclocation, sourceMAC, sourcev6, destinationgeographiclocation, destinationv6, LOGSOURCETYPENAME(devicetype), credibility, severity, magnitude, eventcount, eventDirection, postNatDestinationIP, postNatDestinationPort, postNatSourceIP, postNatSourcePort, preNatDestinationPort, preNatSourceIP, preNatSourcePort, UTF8(payload), starttime, devicetime from events WHERE InOffense(187)  
LIMIT 50
START '1680097318'&amp;quot; headers=&amp;quot;&amp;quot; (QRadar v3[QRadar_CIC])"&gt;!qradar-searches query_expression="select QIDNAME(qid), LOGSOURCENAME(logsourceid), CATEGORYNAME(highlevelcategory), CATEGORYNAME(category), PROTOCOLNAME(protocolid), sourceip, sourceport, destinationip, destinationport, QIDDESCRIPTION(qid), username, PROTOCOLNAME(protocolid), RULENAME(\"creEventList\"), sourcegeographiclocation, sourceMAC, sourcev6, destinationgeographiclocation, destinationv6, LOGSOURCETYPENAME(devicetype), credibility, severity, magnitude, eventcount, eventDirection, postNatDestinationIP, postNatDestinationPort, postNatSourceIP, postNatSourcePort, preNatDestinationPort, preNatSourceIP, preNatSourcePort, UTF8(payload), starttime, devicetime from events WHERE InOffense(&lt;STRONG&gt;&amp;lt;offense ID here&amp;gt;&lt;/STRONG&gt;) LIMIT 50 START '1680097318'" headers=""&lt;/SPAN&gt;&lt;SPAN class="parent-entry-source ellipsis" title="QRadar_CIC"&gt;(QRadar v3)&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="entry-view vertical-strech entry-error"&gt;
&lt;DIV class="vertical-strech demisto-data"&gt;
&lt;DIV&gt;&lt;SPAN class="entry-task-reason"&gt;&lt;STRONG&gt;&lt;SPAN&gt;Reason&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;
&lt;DIV class="entry-note-view" data-test-id="entry-note-text"&gt;
&lt;DIV&gt;
&lt;P&gt;&lt;SPAN class=""&gt;Failed to execute qradar-searches command. Error: Could not create search for offense_id: &lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;Now, I attached other QRadar istances to our cortex XSoar and never got this error. So, there is a difference between this specific istances and the current one? Yes, we have some custom fields created for reports and &lt;STRONG&gt;Offense ID&lt;/STRONG&gt;&amp;nbsp;is one of them.&lt;BR /&gt;So, my assumptions/doubts are:&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;My analysis is correct' Is the custom field that create the error?&lt;/LI&gt;
&lt;LI&gt;If the above point is correct, I don't understand why. is it telling me that he's not able to retrieve events correlated to the offense id?&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
Edit to add: I performed further test and I think the custom field is not the root cause. First, it is not used in our search; second, I tried a simpler search in the Playground like the following:&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;!qradar-searches query_expression="select QIDNAME(qid)"&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;DIV class="preplacer"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="preplacer"&gt;&lt;BR /&gt;And I still get the same error. I don't think it's a permission related problem (the user that connect and pull has right privileges) and on QRadar the complete rule work fine.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="css-1ep9fjw react-select-dropdown__indicator react-select-dropdown__dropdown-indicator"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="fetch-settings-classifier"&gt;
&lt;DIV class="classifier-select-dropdown"&gt;
&lt;DIV class="react-select-dropdown-wrapper as-anchor"&gt;
&lt;DIV class="css-10nd86i react-select-dropdown-container"&gt;
&lt;DIV class="control-wrapper" tabindex="0" title="QRadar - Generic Incoming Mapper"&gt;
&lt;DIV class="css-1mhkvg react-select-dropdown__control" aria-labelledby="" aria-expanded="false" aria-haspopup="true"&gt;
&lt;DIV class="css-1ep9fjw react-select-dropdown__indicator react-select-dropdown__dropdown-indicator"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;I class="demisto-icon icon-field-url-24-r"&gt;&lt;/I&gt;&lt;/DIV&gt;
&lt;DIV class="ui divider"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;DIV class="field field_name_server required"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 29 Mar 2023 15:46:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/qradar-integration-error-failed-to-execute-qradar-searches/m-p/536927#M1950</guid>
      <dc:creator>lsepe434</dc:creator>
      <dc:date>2023-03-29T15:46:20Z</dc:date>
    </item>
    <item>
      <title>Re: QRadar integration error: Failed to execute qradar-searches command (EDITED).</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/qradar-integration-error-failed-to-execute-qradar-searches/m-p/537174#M1956</link>
      <description>&lt;P&gt;since you are working with Qradar V3 and need to retrive events try the below search, feel free to change the event ID.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="c"&gt;!qradar-search-retrieve-events query_expression="SELECT * from events where \"EventID\"='4624' limit 2
"&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2023 03:50:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/qradar-integration-error-failed-to-execute-qradar-searches/m-p/537174#M1956</guid>
      <dc:creator>vidurasupun</dc:creator>
      <dc:date>2023-03-31T03:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: QRadar integration error: Failed to execute qradar-searches command (EDITED).</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/qradar-integration-error-failed-to-execute-qradar-searches/m-p/547014#M2263</link>
      <description>&lt;P&gt;Solved: the problem was in the query used to pull offense. There are some change not detected and, once fixed, it worked fine again.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 14:24:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/qradar-integration-error-failed-to-execute-qradar-searches/m-p/547014#M2263</guid>
      <dc:creator>lsepe434</dc:creator>
      <dc:date>2023-06-23T14:24:35Z</dc:date>
    </item>
  </channel>
</rss>

