<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SearchIncidentsV2 not returning results in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/searchincidentsv2-not-returning-results/m-p/549766#M2328</link>
    <description>&lt;P&gt;But when I check your query, the IP is the same for the victim and target which does not sound right. Could you please copy and paste the same query in incidents search box to see if there is any alerts.&lt;/P&gt;</description>
    <pubDate>Tue, 18 Jul 2023 09:40:07 GMT</pubDate>
    <dc:creator>gyldz</dc:creator>
    <dc:date>2023-07-18T09:40:07Z</dc:date>
    <item>
      <title>SearchIncidentsV2 not returning results</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/searchincidentsv2-not-returning-results/m-p/549581#M2322</link>
      <description>&lt;P&gt;Hi, I am using SearchIncidentsV2 automation to loop through 2 IP addresses previously saved to IP incident key, to see if these IPs are showing in FireEye NX alerts. When I try to loop I receive empty foundIncidents key:&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MMagdic_0-1689670794647.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/51718i75B5CEF7C45A13BC/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MMagdic_0-1689670794647.png" alt="MMagdic_0-1689670794647.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I hardcode the IP addresses everything works as it should.&amp;nbsp;&lt;BR /&gt;What I am missing?&lt;BR /&gt;&lt;LI-PRODUCT title="Cortex XSOAR" id="Cortex_XSOAR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 09:00:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/searchincidentsv2-not-returning-results/m-p/549581#M2322</guid>
      <dc:creator>MMagdic</dc:creator>
      <dc:date>2023-07-18T09:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: SearchIncidentsV2 not returning results</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/searchincidentsv2-not-returning-results/m-p/549761#M2326</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/271971"&gt;@MMagdic&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you see any results when you use the same query in the incidents page search box?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 09:20:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/searchincidentsv2-not-returning-results/m-p/549761#M2326</guid>
      <dc:creator>gyldz</dc:creator>
      <dc:date>2023-07-18T09:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: SearchIncidentsV2 not returning results</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/searchincidentsv2-not-returning-results/m-p/549765#M2327</link>
      <description>&lt;P&gt;Yes, of course with hardcoded IP values.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 09:32:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/searchincidentsv2-not-returning-results/m-p/549765#M2327</guid>
      <dc:creator>MMagdic</dc:creator>
      <dc:date>2023-07-18T09:32:12Z</dc:date>
    </item>
    <item>
      <title>Re: SearchIncidentsV2 not returning results</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/searchincidentsv2-not-returning-results/m-p/549766#M2328</link>
      <description>&lt;P&gt;But when I check your query, the IP is the same for the victim and target which does not sound right. Could you please copy and paste the same query in incidents search box to see if there is any alerts.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 09:40:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/searchincidentsv2-not-returning-results/m-p/549766#M2328</guid>
      <dc:creator>gyldz</dc:creator>
      <dc:date>2023-07-18T09:40:07Z</dc:date>
    </item>
    <item>
      <title>Re: SearchIncidentsV2 not returning results</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/searchincidentsv2-not-returning-results/m-p/549805#M2331</link>
      <description>&lt;P&gt;Yes, the reason to have both (victim and target) is because sometimes FireEye NX is parsing incident fields not correctly, putting external (attacker IP) in target ip. But the query is working:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MMagdic_0-1689683575150.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/51726i654AB8D72120EE9B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MMagdic_0-1689683575150.png" alt="MMagdic_0-1689683575150.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;So the question is how to loop through a couple of IP addresses, e.g. at least 2 IP addresses in&amp;nbsp;&lt;SPAN&gt;SearchIncidentsV2 automation using query as a filter.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 12:36:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/searchincidentsv2-not-returning-results/m-p/549805#M2331</guid>
      <dc:creator>MMagdic</dc:creator>
      <dc:date>2023-07-18T12:36:01Z</dc:date>
    </item>
    <item>
      <title>Re: SearchIncidentsV2 not returning results</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/searchincidentsv2-not-returning-results/m-p/549809#M2332</link>
      <description>&lt;P&gt;See here results when I try with 2 IP addresses:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="query_results.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/51728i4314E6B685883619/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="query_results.png" alt="query_results.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="query_results_foundIncidents.png" style="width: 390px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/51727i538FBCF567230195/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="query_results_foundIncidents.png" alt="query_results_foundIncidents.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 12:42:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/searchincidentsv2-not-returning-results/m-p/549809#M2332</guid>
      <dc:creator>MMagdic</dc:creator>
      <dc:date>2023-07-18T12:42:39Z</dc:date>
    </item>
    <item>
      <title>Re: SearchIncidentsV2 not returning results</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/searchincidentsv2-not-returning-results/m-p/549821#M2333</link>
      <description>&lt;P&gt;Hi again, you need to use&amp;nbsp;join transformer for that task. Before searching the incidents Set another field as below and then use it in the search incidents task.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gyldz_3-1689685291576.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/51732i598EF1E6ECD6C377/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="gyldz_3-1689685291576.png" alt="gyldz_3-1689685291576.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="tinyMceEditor_14f04a2e6150f9gyldz_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gyldz_2-1689685246360.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/51731i26DA13675BD995C2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="gyldz_2-1689685246360.png" alt="gyldz_2-1689685246360.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 13:01:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/searchincidentsv2-not-returning-results/m-p/549821#M2333</guid>
      <dc:creator>gyldz</dc:creator>
      <dc:date>2023-07-18T13:01:48Z</dc:date>
    </item>
    <item>
      <title>Re: SearchIncidentsV2 not returning results</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/searchincidentsv2-not-returning-results/m-p/549832#M2334</link>
      <description>&lt;P&gt;Thanks, but this should work only by adding space before&amp;amp;after "or" to " or " (in Join Transformer) as in cli:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;!SearchIncidentsV2 query="type:FireEye NX Alert and fireeyenxalertvictimip:11.11.11.11 or 134.122.90.162"&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 13:41:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/searchincidentsv2-not-returning-results/m-p/549832#M2334</guid>
      <dc:creator>MMagdic</dc:creator>
      <dc:date>2023-07-18T13:41:46Z</dc:date>
    </item>
    <item>
      <title>Re: SearchIncidentsV2 not returning results</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/searchincidentsv2-not-returning-results/m-p/549833#M2335</link>
      <description>&lt;P&gt;Yes there was a space in the screenshot I shared&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 14:15:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/searchincidentsv2-not-returning-results/m-p/549833#M2335</guid>
      <dc:creator>gyldz</dc:creator>
      <dc:date>2023-07-18T14:15:46Z</dc:date>
    </item>
  </channel>
</rss>

