<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Custom Fetch Incidents in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/custom-fetch-incidents/m-p/551546#M2416</link>
    <description>&lt;P&gt;Hi, I want to use Exabeam integration in XSOAR but not to fetch incidents (incident responder) as it is currently set in fetch-incidents command, that is in fetch_incidents function. &lt;BR /&gt;&lt;BR /&gt;The plan would be to fetch with get-notable-users command, which produces this result (context-data), when using '&lt;SPAN class="parent-entry-label ellipsis show-as-link" title="!exabeam-get-notable-users time_period=&amp;quot;1 month&amp;quot; limit=&amp;quot;1&amp;quot; (Exabeam[Plinacro-Exabeam-UEBA])"&gt;!exabeam-get-notable-users time_period="1 month" limit="1"&lt;/SPAN&gt;&lt;SPAN class="parent-entry-source ellipsis" title="Plinacro-Exabeam-UEBA"&gt;(Exabeam)' in CLI:&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;RiskScore:null&lt;BR /&gt;HighestRiskSession:{} 17 items&lt;BR /&gt;numOfAssets:11&lt;BR /&gt;riskScore:188&lt;BR /&gt;numOfAccounts:1&lt;BR /&gt;accounts:[] 1 item&lt;BR /&gt;0:someusername&lt;BR /&gt;zones:[] 4 items&lt;BR /&gt;0:servers_0&lt;BR /&gt;1:servers_1&lt;BR /&gt;3:servers_2&lt;BR /&gt;endTime:1688539545557&lt;BR /&gt;numOfZones:4&lt;BR /&gt;startTime:1688453145557&lt;BR /&gt;loginHost:somehost&lt;BR /&gt;sessionId:someusername-20230704064545&lt;BR /&gt;numOfReasons:46&lt;BR /&gt;label:&lt;BR /&gt;username:someusername&lt;BR /&gt;numOfSecurityEvents:0&lt;BR /&gt;numOfEvents:23583&lt;BR /&gt;riskTransferScore:39.370000000000005&lt;BR /&gt;initialRiskScore:12&lt;BR /&gt;UserFullName:Some Username&lt;BR /&gt;LastActivity:Account is active&lt;BR /&gt;EmployeeType:null&lt;BR /&gt;FirstSeen:2023-03-01T13:33:53.253000&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now, the plan is to use get-notable-users to create incidents in xsoar, then create custom classifier, etc..&lt;BR /&gt;&lt;BR /&gt;Is there any tutorial explaining this case?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Attached is Exabeam original integration Python file.&lt;BR /&gt;&lt;LI-PRODUCT title="Cortex XSOAR" id="Cortex_XSOAR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 28 Jul 2023 07:14:05 GMT</pubDate>
    <dc:creator>MMagdic</dc:creator>
    <dc:date>2023-07-28T07:14:05Z</dc:date>
    <item>
      <title>Custom Fetch Incidents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/custom-fetch-incidents/m-p/551546#M2416</link>
      <description>&lt;P&gt;Hi, I want to use Exabeam integration in XSOAR but not to fetch incidents (incident responder) as it is currently set in fetch-incidents command, that is in fetch_incidents function. &lt;BR /&gt;&lt;BR /&gt;The plan would be to fetch with get-notable-users command, which produces this result (context-data), when using '&lt;SPAN class="parent-entry-label ellipsis show-as-link" title="!exabeam-get-notable-users time_period=&amp;quot;1 month&amp;quot; limit=&amp;quot;1&amp;quot; (Exabeam[Plinacro-Exabeam-UEBA])"&gt;!exabeam-get-notable-users time_period="1 month" limit="1"&lt;/SPAN&gt;&lt;SPAN class="parent-entry-source ellipsis" title="Plinacro-Exabeam-UEBA"&gt;(Exabeam)' in CLI:&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;RiskScore:null&lt;BR /&gt;HighestRiskSession:{} 17 items&lt;BR /&gt;numOfAssets:11&lt;BR /&gt;riskScore:188&lt;BR /&gt;numOfAccounts:1&lt;BR /&gt;accounts:[] 1 item&lt;BR /&gt;0:someusername&lt;BR /&gt;zones:[] 4 items&lt;BR /&gt;0:servers_0&lt;BR /&gt;1:servers_1&lt;BR /&gt;3:servers_2&lt;BR /&gt;endTime:1688539545557&lt;BR /&gt;numOfZones:4&lt;BR /&gt;startTime:1688453145557&lt;BR /&gt;loginHost:somehost&lt;BR /&gt;sessionId:someusername-20230704064545&lt;BR /&gt;numOfReasons:46&lt;BR /&gt;label:&lt;BR /&gt;username:someusername&lt;BR /&gt;numOfSecurityEvents:0&lt;BR /&gt;numOfEvents:23583&lt;BR /&gt;riskTransferScore:39.370000000000005&lt;BR /&gt;initialRiskScore:12&lt;BR /&gt;UserFullName:Some Username&lt;BR /&gt;LastActivity:Account is active&lt;BR /&gt;EmployeeType:null&lt;BR /&gt;FirstSeen:2023-03-01T13:33:53.253000&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now, the plan is to use get-notable-users to create incidents in xsoar, then create custom classifier, etc..&lt;BR /&gt;&lt;BR /&gt;Is there any tutorial explaining this case?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Attached is Exabeam original integration Python file.&lt;BR /&gt;&lt;LI-PRODUCT title="Cortex XSOAR" id="Cortex_XSOAR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 07:14:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/custom-fetch-incidents/m-p/551546#M2416</guid>
      <dc:creator>MMagdic</dc:creator>
      <dc:date>2023-07-28T07:14:05Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Fetch Incidents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/custom-fetch-incidents/m-p/551585#M2420</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please refer to the developer docs or use other existing integrations for example.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://xsoar.pan.dev/docs/integrations/fetching-incidents" target="_self"&gt;https://xsoar.pan.dev/docs/integrations/fetching-incidents&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 12:51:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/custom-fetch-incidents/m-p/551585#M2420</guid>
      <dc:creator>bhmurali</dc:creator>
      <dc:date>2023-07-28T12:51:08Z</dc:date>
    </item>
  </channel>
</rss>

