<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I get network traffic data in XSOAR from the SIEM ingestions? in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-do-i-get-network-traffic-data-in-xsoar-from-the-siem/m-p/553479#M2515</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/308216"&gt;@SGupta&lt;/a&gt;&amp;nbsp;While XSOAR could be used to create the report, I recommend using something like Netflow to gather this data.&lt;/P&gt;</description>
    <pubDate>Fri, 11 Aug 2023 12:01:53 GMT</pubDate>
    <dc:creator>atullo</dc:creator>
    <dc:date>2023-08-11T12:01:53Z</dc:date>
    <item>
      <title>How do I get network traffic data in XSOAR from the SIEM ingestions?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-do-i-get-network-traffic-data-in-xsoar-from-the-siem/m-p/552927#M2485</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We have to Generate a report that presents the network traffic data in XSOAR obtained from our SIEM. We would appreciate the guidance on the calculation process and the essential aspects we should include in the report.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you &lt;BR /&gt;&lt;LI-PRODUCT title="Cortex XSOAR" id="Cortex_XSOAR"&gt;&lt;/LI-PRODUCT&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 12:52:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-do-i-get-network-traffic-data-in-xsoar-from-the-siem/m-p/552927#M2485</guid>
      <dc:creator>SGupta</dc:creator>
      <dc:date>2023-08-08T12:52:59Z</dc:date>
    </item>
    <item>
      <title>Re: How do I get network traffic data in XSOAR from the SIEM ingestions?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-do-i-get-network-traffic-data-in-xsoar-from-the-siem/m-p/552950#M2490</link>
      <description>&lt;P&gt;Very opened ended question, without much details.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Depending on what the data us (sessions, opened/closed, blocked, bytes, etc etc) if it's being returned to the context and you then need to operate on it within the context of an Incident, you may need a widget that runs as an automation script to calculate whatever it is you're looking for:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.11/Cortex-XSOAR-Administrator-Guide/Create-a-Custom-Widget-Using-an-Automation-Script" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.11/Cortex-XSOAR-Administrator-Guide/Create-a-Custom-Widget-Using-an-Automation-Script&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you need it as a report across a bunch of different Incidents, then the data would need to be in an Incident field.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You'll want to start by referencing the sections on Widgets, Dashboards, and Reports on the Admin Guide:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.11/Cortex-XSOAR-Administrator-Guide/Overview" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.11/Cortex-XSOAR-Administrator-Guide/Overview&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 14:16:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-do-i-get-network-traffic-data-in-xsoar-from-the-siem/m-p/552950#M2490</guid>
      <dc:creator>MBeauchamp2</dc:creator>
      <dc:date>2023-08-08T14:16:09Z</dc:date>
    </item>
    <item>
      <title>Re: How do I get network traffic data in XSOAR from the SIEM ingestions?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-do-i-get-network-traffic-data-in-xsoar-from-the-siem/m-p/553071#M2496</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I require the data in bytes, specifically the amount of traffic received from the SIEM into XSOAR.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2023 10:46:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-do-i-get-network-traffic-data-in-xsoar-from-the-siem/m-p/553071#M2496</guid>
      <dc:creator>SGupta</dc:creator>
      <dc:date>2023-08-09T10:46:28Z</dc:date>
    </item>
    <item>
      <title>Re: How do I get network traffic data in XSOAR from the SIEM ingestions?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-do-i-get-network-traffic-data-in-xsoar-from-the-siem/m-p/553479#M2515</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/308216"&gt;@SGupta&lt;/a&gt;&amp;nbsp;While XSOAR could be used to create the report, I recommend using something like Netflow to gather this data.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2023 12:01:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/how-do-i-get-network-traffic-data-in-xsoar-from-the-siem/m-p/553479#M2515</guid>
      <dc:creator>atullo</dc:creator>
      <dc:date>2023-08-11T12:01:53Z</dc:date>
    </item>
  </channel>
</rss>

