<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XSOAR:  MDE malware- Incident Enrichment in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-mde-malware-incident-enrichment/m-p/547627#M2276</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/289506"&gt;@anna.tirao&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the case of the playbook&amp;nbsp;&lt;STRONG&gt;MDE Malware - Incident Enrichment&lt;/STRONG&gt;, the &lt;SPAN&gt;&lt;STRONG&gt;alert_ids&lt;/STRONG&gt;&amp;nbsp;&lt;/SPAN&gt;argument required for the task &lt;SPAN&gt;&lt;STRONG&gt;Get full alert details&lt;/STRONG&gt;&amp;nbsp;&lt;/SPAN&gt;is defined as an input in the playbook, as specified in the Playbook Triggered Header:&lt;BR /&gt;&lt;BR /&gt;Name:&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Value:&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Description:&lt;BR /&gt;AlertID&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ${incident.externalsystemid}&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;The Microsoft Defender For Endpoint alert ID.&lt;BR /&gt;&lt;BR /&gt;Since this is an input argument to the playbook, this value is expected to be passed in from its parent playbook. In case no value is passed, it will take as default value whatever is stored in the incident field &lt;STRONG&gt;externalsystemid&lt;/STRONG&gt;. That's what this expression&amp;nbsp;&lt;STRONG&gt;${incident.externalsystemid}&lt;/STRONG&gt; indicates in the value of this playbook input.&lt;BR /&gt;&lt;BR /&gt;The error message you are seeing indicates that this input is not being passed in as an argument and that the value is not set in the incident field&amp;nbsp;&lt;STRONG&gt;externalsystemid&lt;/STRONG&gt; either. To solve this issue, you will have to pass in a value on this argument or have the field&amp;nbsp;&lt;STRONG&gt;externalsystemid&lt;/STRONG&gt; populated with the AgentID before calling the subplaybook&amp;nbsp;&lt;STRONG&gt;MDE Malware - Incident Enrichment&lt;/STRONG&gt;&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;You can read more about playbook inputs and outputs in this link below:&lt;BR /&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Playbook-Inputs-and-Outputs" target="_blank" rel="noopener"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Playbook-Inputs-and-Outputs&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 28 Jun 2023 20:48:37 GMT</pubDate>
    <dc:creator>AbelSantamarina</dc:creator>
    <dc:date>2023-06-28T20:48:37Z</dc:date>
    <item>
      <title>XSOAR:  MDE malware- Incident Enrichment</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-mde-malware-incident-enrichment/m-p/547607#M2274</link>
      <description>&lt;P&gt;I am running error trying to pull the alert_id from a Defender incident under the sub playbook MDE Malware-Incident Enrichment -&amp;gt; Get full alert details using automation:&amp;nbsp;&lt;SPAN&gt;'microsoft-atp-get-alert-by-id'.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Error:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="row entry-parent"&gt;
&lt;DIV class="floated left aligned sixteen wide mobile six wide tablet sixteen wide computer column"&gt;
&lt;DIV class="entry-metadata"&gt;
&lt;DIV class="entry-task-name"&gt;
&lt;DIV class="inner-entry-task-name"&gt;&amp;nbsp;Get full alert details:&amp;nbsp;&lt;SPAN&gt;Missing argument &lt;/SPAN&gt;&lt;STRONG style="font-family: inherit;"&gt;alert_ids&lt;/STRONG&gt;&lt;SPAN&gt; for script &lt;/SPAN&gt;&lt;STRONG style="font-family: inherit;"&gt;microsoft-atp-get-alert-by-id&lt;/STRONG&gt;&lt;SPAN&gt; at Task &lt;/SPAN&gt;&lt;STRONG style="font-family: inherit;"&gt;Get full alert details&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN&gt;- stopping playbook &lt;/SPAN&gt;&lt;STRONG style="font-family: inherit;"&gt;Malware Investigation &amp;amp; Response Incident Handler&lt;/STRONG&gt;&lt;SPAN&gt; execution. But I was able to push through when I manually enter the alert IDs but I want it auto extracted.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 28 Jun 2023 17:04:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-mde-malware-incident-enrichment/m-p/547607#M2274</guid>
      <dc:creator>anna.tirao</dc:creator>
      <dc:date>2023-06-28T17:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR:  MDE malware- Incident Enrichment</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-mde-malware-incident-enrichment/m-p/547627#M2276</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/289506"&gt;@anna.tirao&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the case of the playbook&amp;nbsp;&lt;STRONG&gt;MDE Malware - Incident Enrichment&lt;/STRONG&gt;, the &lt;SPAN&gt;&lt;STRONG&gt;alert_ids&lt;/STRONG&gt;&amp;nbsp;&lt;/SPAN&gt;argument required for the task &lt;SPAN&gt;&lt;STRONG&gt;Get full alert details&lt;/STRONG&gt;&amp;nbsp;&lt;/SPAN&gt;is defined as an input in the playbook, as specified in the Playbook Triggered Header:&lt;BR /&gt;&lt;BR /&gt;Name:&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Value:&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Description:&lt;BR /&gt;AlertID&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ${incident.externalsystemid}&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;The Microsoft Defender For Endpoint alert ID.&lt;BR /&gt;&lt;BR /&gt;Since this is an input argument to the playbook, this value is expected to be passed in from its parent playbook. In case no value is passed, it will take as default value whatever is stored in the incident field &lt;STRONG&gt;externalsystemid&lt;/STRONG&gt;. That's what this expression&amp;nbsp;&lt;STRONG&gt;${incident.externalsystemid}&lt;/STRONG&gt; indicates in the value of this playbook input.&lt;BR /&gt;&lt;BR /&gt;The error message you are seeing indicates that this input is not being passed in as an argument and that the value is not set in the incident field&amp;nbsp;&lt;STRONG&gt;externalsystemid&lt;/STRONG&gt; either. To solve this issue, you will have to pass in a value on this argument or have the field&amp;nbsp;&lt;STRONG&gt;externalsystemid&lt;/STRONG&gt; populated with the AgentID before calling the subplaybook&amp;nbsp;&lt;STRONG&gt;MDE Malware - Incident Enrichment&lt;/STRONG&gt;&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;You can read more about playbook inputs and outputs in this link below:&lt;BR /&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Playbook-Inputs-and-Outputs" target="_blank" rel="noopener"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Playbook-Inputs-and-Outputs&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2023 20:48:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-mde-malware-incident-enrichment/m-p/547627#M2276</guid>
      <dc:creator>AbelSantamarina</dc:creator>
      <dc:date>2023-06-28T20:48:37Z</dc:date>
    </item>
  </channel>
</rss>

