<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Creating a Playbook to Upload Indicators to Various XDR Tenants in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/creating-a-playbook-to-upload-indicators-to-various-xdr-tenants/m-p/555256#M2571</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/209373"&gt;@michaelsysec242&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see that there are two commands run and one of them was successful. What is the difference between those two commands or do you have two different integration instances enabled which caused the command to run two times?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 25 Aug 2023 09:35:57 GMT</pubDate>
    <dc:creator>gyldz</dc:creator>
    <dc:date>2023-08-25T09:35:57Z</dc:date>
    <item>
      <title>Creating a Playbook to Upload Indicators to Various XDR Tenants</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/creating-a-playbook-to-upload-indicators-to-various-xdr-tenants/m-p/555081#M2567</link>
      <description>&lt;P&gt;Hello all,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am currently building a playbook that can pull indicators from an external MISP system and then publish them to various tenants of Cortex XDR. I have seen that there was a similar post in the past yet the solution suggested in 2022 does not appear to work as expected. In regards to available automation scripts I am using the task called XDR Push Indicators and I receive the following error.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="michaelsysec242_0-1692889022972.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53088i49F4DBCFA2C3612D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="michaelsysec242_0-1692889022972.png" alt="michaelsysec242_0-1692889022972.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Take note that I want to configure and push the indicators that I receive in a job and not from the threat intel indicators that are based on the XSOAR platform. For almost every XDR/EDR system there is a way to publish indicators. I don't see any task that allows me to push and indicator and choose what Severity or comment should be. What am I missing here ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XSOAR" id="Cortex_XSOAR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 14:59:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/creating-a-playbook-to-upload-indicators-to-various-xdr-tenants/m-p/555081#M2567</guid>
      <dc:creator>michaelsysec242</dc:creator>
      <dc:date>2023-08-24T14:59:32Z</dc:date>
    </item>
    <item>
      <title>Re: Creating a Playbook to Upload Indicators to Various XDR Tenants</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/creating-a-playbook-to-upload-indicators-to-various-xdr-tenants/m-p/555256#M2571</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/209373"&gt;@michaelsysec242&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see that there are two commands run and one of them was successful. What is the difference between those two commands or do you have two different integration instances enabled which caused the command to run two times?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 09:35:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/creating-a-playbook-to-upload-indicators-to-various-xdr-tenants/m-p/555256#M2571</guid>
      <dc:creator>gyldz</dc:creator>
      <dc:date>2023-08-25T09:35:57Z</dc:date>
    </item>
    <item>
      <title>Re: Creating a Playbook to Upload Indicators to Various XDR Tenants</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/creating-a-playbook-to-upload-indicators-to-various-xdr-tenants/m-p/555507#M2577</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/287891"&gt;@gyldz&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;I am working with a few different Integrations including XDR IR, IOC and XQL. In the image I have sent I am only running it on a specific instance under the IOC integration. I cannot see any result of success from this method. Can you suggest a solution for this ?&lt;/P&gt;
&lt;P&gt;If not ill head over to the support to escalate this.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 10:53:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/creating-a-playbook-to-upload-indicators-to-various-xdr-tenants/m-p/555507#M2577</guid>
      <dc:creator>michaelsysec242</dc:creator>
      <dc:date>2023-08-28T10:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: Creating a Playbook to Upload Indicators to Various XDR Tenants</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/creating-a-playbook-to-upload-indicators-to-various-xdr-tenants/m-p/555807#M2582</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/209373"&gt;@michaelsysec242&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately, I could not reproduce this in my environment. Could you please proceed with the support ticket?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2023 06:54:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/creating-a-playbook-to-upload-indicators-to-various-xdr-tenants/m-p/555807#M2582</guid>
      <dc:creator>gyldz</dc:creator>
      <dc:date>2023-08-30T06:54:52Z</dc:date>
    </item>
    <item>
      <title>Re: Creating a Playbook to Upload Indicators to Various XDR Tenants</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/creating-a-playbook-to-upload-indicators-to-various-xdr-tenants/m-p/591201#M3436</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TRY on below order !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The following indicators were not found : 20.125.137.168&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. We need to enable the indicator&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;!xdr-iocs-enable indicator="20.125.137.168"&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. search the indicator whether its was listed&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;!SearchIndicator query="20.125.137.168"&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3.Push the indicator&lt;/P&gt;
&lt;P&gt;!xdr-iocs-push inidcator="20.125.137.168"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Chiranjeevi&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 10:08:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/creating-a-playbook-to-upload-indicators-to-various-xdr-tenants/m-p/591201#M3436</guid>
      <dc:creator>cV V</dc:creator>
      <dc:date>2024-07-04T10:08:23Z</dc:date>
    </item>
  </channel>
</rss>

