<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ingest Taxii feed into XSOAR 6.12 in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/560375#M2685</link>
    <description>&lt;P&gt;Hi Tony,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try incrementing that setting to intervals of 5 days to see if the indicators increase.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks like it may be only looking at the feed if the indicators are day old but may have more indicators if your first fetch time is more days back.&lt;/P&gt;</description>
    <pubDate>Tue, 03 Oct 2023 15:15:24 GMT</pubDate>
    <dc:creator>albmartinez</dc:creator>
    <dc:date>2023-10-03T15:15:24Z</dc:date>
    <item>
      <title>Ingest Taxii feed into XSOAR 6.12</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/560273#M2673</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to ingest our taxii feed into XSOAR 6.12 with following steps:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;installed XSOAR 6.12 on ubuntu 22.0.4 LTS&lt;/LI&gt;
&lt;LI&gt;launched the web portal, and installed TAXII Feed (1.x) pack from marketplace&lt;/LI&gt;
&lt;LI&gt;Ingest feed using "Integration Instance Settings"&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;Typed in the parameters such as name, discovery service URL, username/password, collection name, poll service url, first fetch time,set Feed Fetch Interval to 10 mins, etc.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Test successful&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;With above steps, it was able to pull indicator from the collection I specified, but, it seems every time it only pulls one indicator and the same one over and overall again,&amp;nbsp;the taxii feed provides over thousands of indicators per day, but I only see one indicator on Threat Intel dashboard -&amp;gt; XSOAR Indicators.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note, I have also tested the same feeds with other platforms such as ThreatQ and ThreatConnect, from there the feeds are ingested as expected.&lt;/P&gt;
&lt;P&gt;Could someone please advise on it?&lt;BR /&gt;# XSOAR6.12&amp;nbsp; #taxii integration&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2023 18:34:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/560273#M2673</guid>
      <dc:creator>TonyZhu</dc:creator>
      <dc:date>2023-10-02T18:34:38Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest Taxii feed into XSOAR 6.12</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/560363#M2681</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/317417"&gt;@TonyZhu&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you using the same discovery service and collection for the ThreatConnect and ThreatQ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, what is your "First Fetch Time" set to?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please advise,&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 14:19:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/560363#M2681</guid>
      <dc:creator>albmartinez</dc:creator>
      <dc:date>2023-10-03T14:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest Taxii feed into XSOAR 6.12</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/560370#M2684</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/260191"&gt;@albmartinez&lt;/a&gt;,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you for looking into it.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes. It's the same service and collection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The "First Fetch Time" set to 1 day.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 14:42:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/560370#M2684</guid>
      <dc:creator>TonyZhu</dc:creator>
      <dc:date>2023-10-03T14:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest Taxii feed into XSOAR 6.12</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/560375#M2685</link>
      <description>&lt;P&gt;Hi Tony,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try incrementing that setting to intervals of 5 days to see if the indicators increase.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks like it may be only looking at the feed if the indicators are day old but may have more indicators if your first fetch time is more days back.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 15:15:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/560375#M2685</guid>
      <dc:creator>albmartinez</dc:creator>
      <dc:date>2023-10-03T15:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest Taxii feed into XSOAR 6.12</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/560385#M2686</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/260191"&gt;@albmartinez&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's the same behavior after setting it to 5 days...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 15:47:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/560385#M2686</guid>
      <dc:creator>TonyZhu</dc:creator>
      <dc:date>2023-10-03T15:47:01Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest Taxii feed into XSOAR 6.12</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/560596#M2692</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/260191"&gt;@albmartinez&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any more feedback would be appreciated. Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2023 21:32:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/560596#M2692</guid>
      <dc:creator>TonyZhu</dc:creator>
      <dc:date>2023-10-04T21:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest Taxii feed into XSOAR 6.12</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/561754#M2733</link>
      <description>&lt;P&gt;What does the fetch history (the anticlockwise arrow icon) on the instance say was fetched?&lt;/P&gt;
&lt;P&gt;What query are you using on the threat intel page? If you change the query to something like "sourceInstance:&amp;lt;instance name&amp;gt;" do you get different results?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 01:30:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/561754#M2733</guid>
      <dc:creator>chrking</dc:creator>
      <dc:date>2023-10-16T01:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest Taxii feed into XSOAR 6.12</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/562149#M2738</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/208030"&gt;@chrking&lt;/a&gt;&amp;nbsp;for looking into it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The fetch history shows that there are only 2 indicators pulled every scheduled job.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The query in threat intel page shows the same result.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-10-17 at 1.07.42 PM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54495i3CD736F7730A173C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2023-10-17 at 1.07.42 PM.png" alt="Screenshot 2023-10-17 at 1.07.42 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-10-17 at 1.09.54 PM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54496i2D45BF7D12AFCB94/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-10-17 at 1.09.54 PM.png" alt="Screenshot 2023-10-17 at 1.09.54 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 20:18:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/562149#M2738</guid>
      <dc:creator>TonyZhu</dc:creator>
      <dc:date>2023-10-17T20:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest Taxii feed into XSOAR 6.12</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/562187#M2739</link>
      <description>&lt;P&gt;OK, so this is actually really good info. The fact that the time isn't changing means that it's not updating it's last run timestamp for some reason. This shouldn't happen under normal operations. I'd suggest turning debug mode on, then looking at the output in your integration-instance.log. It's possible there are issues parsing the results that are causing the fetch to terminate early and not update the last run timestamp.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 01:59:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/562187#M2739</guid>
      <dc:creator>chrking</dc:creator>
      <dc:date>2023-10-18T01:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest Taxii feed into XSOAR 6.12</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/562483#M2749</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/208030"&gt;@chrking&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I checked the integration-instance.log under debug mode, there was no exceptions/error in it but I noticed that the timestamp is&amp;nbsp;"created": "0001-01-01T00:00:00Z" in following logs, does it look right to you?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;2023-10-19 08:36:22.8314 info (maliciousFile_TAXIIFeed_fetch-indicators) debug-mode started.
#### http client print found: False.
#### Env {'PATH': '/usr/local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin', 'HOSTNAME': 'cd2c01af9608', 'HTTP_PROXY': '', 'http_proxy': '', 'HTTPS_PROXY': '', 'https_proxy': '', 'no_proxy': '', 'NO_PROXY': '', 'LANG': 'C.UTF-8', 'GPG_KEY': 'A035C8C19219BA821ECEA86B64E628F8D684696D', 'PYTHON_VERSION': '3.10.13', 'PYTHON_PIP_VERSION': '23.0.1', 'PYTHON_SETUPTOOLS_VERSION': '65.5.1', 'PYTHON_GET_PIP_URL': 'https://github.com/pypa/get-pip/raw/9af82b715db434abb94a0a6f3569f43e72157346/public/get-pip.py', 'PYTHON_GET_PIP_SHA256': '45a2bb8bf2bb5eff16fdd00faef6f29731831c7c59bd9fc2bf1f3bed511ff1fe', 'DOCKER_IMAGE': 'demisto/taxii:1.0.0.76522', 'HOME': '/root'}.
#### Params: {
  "cert_text": null,
  "collection": "malicious-file",
  "credentials": {
    "credential": "",
    "credentials": {
      "cacheVersn": 0,
      "created": "0001-01-01T00:00:00Z",
      "id": "",
      "locked": false,
      "modified": "0001-01-01T00:00:00Z",
      "name": "",
      "password": "MASKED_SECRET",
      "sizeInBytes": 0,
      "sshkey": "",
      "sshkeyPass": "",
      "user": "",
      "vaultInstanceId": "",
      "version": 0,
      "workgroup": ""
    },
    "identifier": "{user_name}",
    "password": "MASKED_SECRET",
    "passwordChanged": false
  },
  "creds_certificate": null,
  "discovery_service": "https://{feed-url}/discovery",
  "feed": true,
  "feedBypassExclusionList": true,
  "feedExpirationInterval": 0,
  "feedExpirationPolicy": "never",
  "feedFetchInterval": 10,
  "feedReliability": "A - Completely reliable",
  "feedReputation": "Malicious",
  "feedTags": null,
  "initial_interval": "5 day",
  "insecure": false,
  "key_text": "",
  "poll_service": "https://{feed-service}/taxii11/poll",
  "polling_timeout": "20",
  "proxy": false,
  "subscription_id": null,
  "tlp_color": "RED"
}.&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 19 Oct 2023 21:05:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/562483#M2749</guid>
      <dc:creator>TonyZhu</dc:creator>
      <dc:date>2023-10-19T21:05:13Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest Taxii feed into XSOAR 6.12</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/562484#M2750</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/208030"&gt;@chrking&lt;/a&gt;, the request and response in the log, it's keep pulling the same indicators over and over again, while the feed generates thousands new indicators everyday&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;'&amp;lt;taxii_11:Poll_Request xmlns:taxii_11="http://taxii.mitre.org/messages/taxii_xml_binding-1.1"\nmessage_id="e0509e9e-9a0c-4155-9987-6a7914a99cb1"\ncollection_name="malicious-file"\n&amp;gt;\n&amp;lt;taxii_11:Exclusive_Begin_Timestamp&amp;gt;2023-10-17T23:20:00Z&amp;lt;/taxii_11:Exclusive_Begin_Timestamp&amp;gt;\n&amp;lt;taxii_11:Inclusive_End_Timestamp&amp;gt;2023-10-19T15:36:00Z&amp;lt;/taxii_11:Inclusive_End_Timestamp&amp;gt;\n&amp;lt;taxii_11:Poll_Parameters allow_asynch="false"&amp;gt;&amp;lt;taxii_11:Response_Type&amp;gt;FULL&amp;lt;/taxii_11:Response_Type&amp;gt;&amp;lt;/taxii_11:Poll_Parameters&amp;gt;\n&amp;lt;/taxii_11:Poll_Request&amp;gt;' (source: /builds/GOPATH/src/gitlab.xdr.pan.local/xdr/xsoar/server/services/automation/dockercoderunner.go:979) 
2023-10-19 08:37:11.5815 info (maliciousFile_TAXIIFeed_fetch-indicators) cURL:
curl -X POST https://{feed-service}/taxii11/poll -H "Accept: */*" -H "Content-Type: application/xml" -H "X-TAXII-Content-Type: urn:taxii.mitre.org:message:xml:1.1" -H "X-TAXII-Accept: urn:taxii.mitre.org:message:xml:1.1" -H "X-TAXII-Services: urn:taxii.mitre.org:services:1.1" -H "X-TAXII-Protocol: urn:taxii.mitre.org:protocol:https:1.0" -H "Authorization: Basic &amp;lt;XX_REPLACED&amp;gt;" --noproxy "*" -d '&amp;lt;taxii_11:Poll_Fulfillment xmlns:taxii_11="http://taxii.mitre.org/messages/taxii_xml_binding-1.1"\n                    message_id="a6a2a4aa-5354-4c3a-adec-2ab50105add4" collection_name="malicious-file" result_id="d257e14a-76bc-40bd-a6f8-af2cea5778f5"\n                    result_part_number="2"/&amp;gt;' (source: /builds/GOPATH/src/gitlab.xdr.pan.local/xdr/xsoar/server/services/automation/dockercoderunner.go:979) 
2023-10-19 08:37:11.5836 info (maliciousFile_TAXIIFeed_fetch-indicators) cURL:
curl -X POST https://{feed-service}/taxii11/poll -H "Accept: */*" -H "Content-Type: application/xml" -H "X-TAXII-Content-Type: urn:taxii.mitre.org:message:xml:1.1" -H "X-TAXII-Accept: urn:taxii.mitre.org:message:xml:1.1" -H "X-TAXII-Services: urn:taxii.mitre.org:services:1.1" -H "X-TAXII-Protocol: urn:taxii.mitre.org:protocol:https:1.0" -H "Authorization: Basic &amp;lt;XX_REPLACED&amp;gt;" --noproxy "*" -d '&amp;lt;taxii_11:Poll_Fulfillment xmlns:taxii_11="http://taxii.mitre.org/messages/taxii_xml_binding-1.1"\n                    message_id="71a32d1c-6c6f-4480-b10e-253bdc76f2b1" collection_name="malicious-file" result_id="d257e14a-76bc-40bd-a6f8-af2cea5778f5"\n                    result_part_number="3"/&amp;gt;' (source: /builds/GOPATH/src/gitlab.xdr.pan.local/xdr/xsoar/server/services/automation/dockercoderunner.go:979) 
2023-10-19 08:37:11.5854 info (maliciousFile_TAXIIFeed_fetch-indicators) cURL:
curl -X POST https://{feed-service}/taxii11/poll -H "Accept: */*" -H "Content-Type: application/xml" -H "X-TAXII-Content-Type: urn:taxii.mitre.org:message:xml:1.1" -H "X-TAXII-Accept: urn:taxii.mitre.org:message:xml:1.1" -H "X-TAXII-Services: urn:taxii.mitre.org:services:1.1" -H "X-TAXII-Protocol: urn:taxii.mitre.org:protocol:https:1.0" -H "Authorization: Basic &amp;lt;XX_REPLACED&amp;gt;" --noproxy "*" -d '&amp;lt;taxii_11:Poll_Fulfillment xmlns:taxii_11="http://taxii.mitre.org/messages/taxii_xml_binding-1.1"\n                    message_id="1a058a73-0682-4776-bda7-20b02e2e330a" collection_name="malicious-file" result_id="d257e14a-76bc-40bd-a6f8-af2cea5778f5"\n                    result_part_number="4"/&amp;gt;' (source: /builds/GOPATH/src/gitlab.xdr.pan.local/xdr/xsoar/server/services/automation/dockercoderunner.go:979) &lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 21:07:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/562484#M2750</guid>
      <dc:creator>TonyZhu</dc:creator>
      <dc:date>2023-10-19T21:07:20Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest Taxii feed into XSOAR 6.12</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/562853#M2754</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/317417"&gt;@TonyZhu&lt;/a&gt;&amp;nbsp;the created/modified dates here are related to the credential I think, this likely just means you're using a username/password configured in the integration itself rather than a linked credential and isn't inherently concerning.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These parts pulled out from the logs look like requests rather than responses, but it's interesting that XSOAR is pulling 4 full pages of results but only returning 2 results.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This definitely looks like some kind of incompatibility between the way your taxii server is returning the results and the way XSOAR is parsing them. I'd love to set up my own version of the taxii client with additional debugging details so I can see exactly what is being pulled, but I'm kind of guessing this is non-public threat intel?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Would you be able to SSH to your XSOAR server, execute one of the curl commands from that file with the&amp;nbsp;&amp;lt;XX_REPLACED&amp;gt; part restored to valid basic auth (see&amp;nbsp;&lt;A href="https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Authorization#basic_authentication" target="_blank"&gt;https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Authorization#basic_authentication&lt;/A&gt;&amp;nbsp;) and post a sample of the results showing a redacted version of an un-fetched indicator? I'm looking for the XML structure of the indicator rather than any content, so feel free to replace any actual content with "REDACTED".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Filing a support case would be the other option, that way you could share the results without it being public.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 07:11:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/562853#M2754</guid>
      <dc:creator>chrking</dc:creator>
      <dc:date>2023-10-24T07:11:31Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest Taxii feed into XSOAR 6.12</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/563620#M2786</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/208030"&gt;@chrking&lt;/a&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is the response of the cabby-client request from malicious-url collection, it returns malicious uri/IP indicators in STIX format that is the same as curl commands returns. I truncate the result to a few indicators from each pages (there are 3 pages in total):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We also have other collections such as malicious-file that contains file hash indicators,&amp;nbsp; please let me know if you want to look at it's response that is similar format to malicious-uri:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;lt;stix:STIX_Package xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:stix="http://stix.mitre.org/stix-1" xmlns:indicator="http://stix.mitre.org/Indicator-2" xmlns:cybox="http://cybox.mitre.org/cybox-2" xmlns:cyboxCommon="http://cybox.mitre.org/common-2" xmlns:URIObject="http://cybox.mitre.org/objects#URIObject-2" xmlns:DomainNameObj="http://cybox.mitre.org/objects#DomainNameObject-1" xmlns:FileObj="http://cybox.mitre.org/objects#FileObject-2" xmlns:AddressObject="http://cybox.mitre.org/objects#AddressObject-2" xmlns:report="http://stix.mitre.org/Report-1" xmlns:threat-actor="http://stix.mitre.org/ThreatActor-1" xmlns:ttp="http://stix.mitre.org/TTP-1" xmlns:stix-ciq="http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1" xmlns:stixCommon="http://stix.mitre.org/common-1" xmlns:xal="urn:oasis:names:tc:ciq:xal:3" xmlns:xpil="urn:oasis:names:tc:ciq:xpil:3" xmlns:cyboxVocabs="http://cybox.mitre.org/default_vocabularies-2" xmlns:stixVocabs="http://stix.mitre.org/default_vocabularies-1" xmlns:taxii_11="http://taxii.mitre.org/messages/taxii_xml_binding-1.1" id="&amp;lt;REDACTED&amp;gt;-threat-intel:package-d9178671-1c06-4450-b9b1-cc23ccbd191d" timestamp="2023-10-15T00:00:00Z" version="1.2"&amp;gt;
&amp;lt;stix:STIX_Header&amp;gt;
  &amp;lt;stix:Title&amp;gt;malicious-uri for 2023-10-15T00:00:00Z - Page:1&amp;lt;/stix:Title&amp;gt;
  &amp;lt;stix:Description&amp;gt;malicious-uri for 2023-10-15T00:00:00Z - Page:1&amp;lt;/stix:Description&amp;gt;
&amp;lt;/stix:STIX_Header&amp;gt;
&amp;lt;stix:Observables cybox_major_version="2" cybox_minor_version="1"&amp;gt;
    &amp;lt;cybox:Observable id="&amp;lt;REDACTED&amp;gt;-threat-intel:observable-3cb1a50b-0e2f-406b-8c7c-b2b7027027b8"&amp;gt;
      &amp;lt;cybox:Object id="&amp;lt;REDACTED&amp;gt;-threat-intel:URI-c966274b-a11f-4971-890d-739a661a34ad"&amp;gt;
        &amp;lt;cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType" type="FQDN"&amp;gt;
          &amp;lt;DomainNameObj:Value&amp;gt;&amp;lt;REDACTED phishing.com&amp;gt;&amp;lt;/DomainNameObj:Value&amp;gt;
          &amp;lt;cyboxCommon:Custom_Properties&amp;gt;
            &amp;lt;cyboxCommon:Property name="confidence"&amp;gt;100&amp;lt;/cyboxCommon:Property&amp;gt;
            &amp;lt;cyboxCommon:Property name="categories"&amp;gt;Phishing&amp;lt;/cyboxCommon:Property&amp;gt;
          &amp;lt;/cyboxCommon:Custom_Properties&amp;gt;
        &amp;lt;/cybox:Properties&amp;gt;
      &amp;lt;/cybox:Object&amp;gt;
    &amp;lt;/cybox:Observable&amp;gt;
    ...
    &amp;lt;cybox:Observable id="&amp;lt;REDACTED&amp;gt;-threat-intel:observable-190320dd-e5b4-44f8-be8b-79c5e84ef4e5"&amp;gt;
      &amp;lt;cybox:Object id="&amp;lt;REDACTED&amp;gt;-threat-intel:URI-621605c7-0f06-4ac9-8609-60ff5a533226"&amp;gt;
        &amp;lt;cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType" type="FQDN"&amp;gt;
          &amp;lt;DomainNameObj:Value&amp;gt;&amp;lt;REDACTED malicious.com&amp;gt;&amp;lt;/DomainNameObj:Value&amp;gt;
          &amp;lt;cyboxCommon:Custom_Properties&amp;gt;
            &amp;lt;cyboxCommon:Property name="confidence"&amp;gt;100&amp;lt;/cyboxCommon:Property&amp;gt;
            &amp;lt;cyboxCommon:Property name="categories"&amp;gt;Malicious Outbound Data/Botnets&amp;lt;/cyboxCommon:Property&amp;gt;
          &amp;lt;/cyboxCommon:Custom_Properties&amp;gt;
        &amp;lt;/cybox:Properties&amp;gt;
      &amp;lt;/cybox:Object&amp;gt;
    &amp;lt;/cybox:Observable&amp;gt;
&amp;lt;/stix:Observables&amp;gt;
&amp;lt;/stix:STIX_Package&amp;gt;

&amp;lt;stix:STIX_Package xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:stix="http://stix.mitre.org/stix-1" xmlns:indicator="http://stix.mitre.org/Indicator-2" xmlns:cybox="http://cybox.mitre.org/cybox-2" xmlns:cyboxCommon="http://cybox.mitre.org/common-2" xmlns:URIObject="http://cybox.mitre.org/objects#URIObject-2" xmlns:DomainNameObj="http://cybox.mitre.org/objects#DomainNameObject-1" xmlns:FileObj="http://cybox.mitre.org/objects#FileObject-2" xmlns:AddressObject="http://cybox.mitre.org/objects#AddressObject-2" xmlns:report="http://stix.mitre.org/Report-1" xmlns:threat-actor="http://stix.mitre.org/ThreatActor-1" xmlns:ttp="http://stix.mitre.org/TTP-1" xmlns:stix-ciq="http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1" xmlns:stixCommon="http://stix.mitre.org/common-1" xmlns:xal="urn:oasis:names:tc:ciq:xal:3" xmlns:xpil="urn:oasis:names:tc:ciq:xpil:3" xmlns:cyboxVocabs="http://cybox.mitre.org/default_vocabularies-2" xmlns:stixVocabs="http://stix.mitre.org/default_vocabularies-1" xmlns:taxii_11="http://taxii.mitre.org/messages/taxii_xml_binding-1.1" id="&amp;lt;REDACTED&amp;gt;-threat-intel:package-ae0e2b3f-e030-4138-a969-f63b7e13b700" timestamp="2023-10-15T00:00:00Z" version="1.2"&amp;gt;
&amp;lt;stix:STIX_Header&amp;gt;
  &amp;lt;stix:Title&amp;gt;malicious-uri for 2023-10-15T00:00:00Z - Page:2&amp;lt;/stix:Title&amp;gt;
  &amp;lt;stix:Description&amp;gt;malicious-uri for 2023-10-15T00:00:00Z - Page:2&amp;lt;/stix:Description&amp;gt;
&amp;lt;/stix:STIX_Header&amp;gt;
&amp;lt;stix:Observables cybox_major_version="2" cybox_minor_version="1"&amp;gt;
    &amp;lt;cybox:Observable id="&amp;lt;REDACTED&amp;gt;-threat-intel:observable-98dc9483-a600-462f-8524-611b73bfff0a"&amp;gt;
      &amp;lt;cybox:Object id="&amp;lt;REDACTED&amp;gt;-threat-intel:URI-ddf796cb-082b-4e69-b536-5f379800e238"&amp;gt;
        &amp;lt;cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType" type="FQDN"&amp;gt;
          &amp;lt;DomainNameObj:Value&amp;gt;&amp;lt;REDACTED phishing.com&amp;gt;&amp;lt;/DomainNameObj:Value&amp;gt;
          &amp;lt;cyboxCommon:Custom_Properties&amp;gt;
            &amp;lt;cyboxCommon:Property name="confidence"&amp;gt;100&amp;lt;/cyboxCommon:Property&amp;gt;
            &amp;lt;cyboxCommon:Property name="categories"&amp;gt;Phishing&amp;lt;/cyboxCommon:Property&amp;gt;
          &amp;lt;/cyboxCommon:Custom_Properties&amp;gt;
        &amp;lt;/cybox:Properties&amp;gt;
      &amp;lt;/cybox:Object&amp;gt;
    &amp;lt;/cybox:Observable&amp;gt;
    ...
    &amp;lt;cybox:Observable id="&amp;lt;REDACTED&amp;gt;-threat-intel:observable-871f5a4b-9ede-46cd-811f-757bacd1ab7e"&amp;gt;
      &amp;lt;cybox:Object id="&amp;lt;REDACTED&amp;gt;-threat-intel:URI-7b4aee1c-53a1-429c-9c7d-b5777e14fa71"&amp;gt;
        &amp;lt;cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType" type="FQDN"&amp;gt;
          &amp;lt;DomainNameObj:Value&amp;gt;&amp;lt;REDACTED suspicious.com&amp;gt;&amp;lt;/DomainNameObj:Value&amp;gt;
          &amp;lt;cyboxCommon:Custom_Properties&amp;gt;
            &amp;lt;cyboxCommon:Property name="confidence"&amp;gt;80&amp;lt;/cyboxCommon:Property&amp;gt;
            &amp;lt;cyboxCommon:Property name="categories"&amp;gt;Suspicious&amp;lt;/cyboxCommon:Property&amp;gt;
          &amp;lt;/cyboxCommon:Custom_Properties&amp;gt;
        &amp;lt;/cybox:Properties&amp;gt;
      &amp;lt;/cybox:Object&amp;gt;
    &amp;lt;/cybox:Observable&amp;gt;
&amp;lt;/stix:Observables&amp;gt;
&amp;lt;/stix:STIX_Package&amp;gt;

&amp;lt;stix:STIX_Package xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:stix="http://stix.mitre.org/stix-1" xmlns:indicator="http://stix.mitre.org/Indicator-2" xmlns:cybox="http://cybox.mitre.org/cybox-2" xmlns:cyboxCommon="http://cybox.mitre.org/common-2" xmlns:URIObject="http://cybox.mitre.org/objects#URIObject-2" xmlns:DomainNameObj="http://cybox.mitre.org/objects#DomainNameObject-1" xmlns:FileObj="http://cybox.mitre.org/objects#FileObject-2" xmlns:AddressObject="http://cybox.mitre.org/objects#AddressObject-2" xmlns:report="http://stix.mitre.org/Report-1" xmlns:threat-actor="http://stix.mitre.org/ThreatActor-1" xmlns:ttp="http://stix.mitre.org/TTP-1" xmlns:stix-ciq="http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1" xmlns:stixCommon="http://stix.mitre.org/common-1" xmlns:xal="urn:oasis:names:tc:ciq:xal:3" xmlns:xpil="urn:oasis:names:tc:ciq:xpil:3" xmlns:cyboxVocabs="http://cybox.mitre.org/default_vocabularies-2" xmlns:stixVocabs="http://stix.mitre.org/default_vocabularies-1" xmlns:taxii_11="http://taxii.mitre.org/messages/taxii_xml_binding-1.1" id="&amp;lt;REDACTED&amp;gt;-threat-intel:package-cce78e5a-29b6-4787-87d8-e55eb4592a2b" timestamp="2023-10-15T00:00:00Z" version="1.2"&amp;gt;
&amp;lt;stix:STIX_Header&amp;gt;
  &amp;lt;stix:Title&amp;gt;malicious-uri for 2023-10-15T00:00:00Z - Page:3&amp;lt;/stix:Title&amp;gt;
  &amp;lt;stix:Description&amp;gt;malicious-uri for 2023-10-15T00:00:00Z - Page:3&amp;lt;/stix:Description&amp;gt;
&amp;lt;/stix:STIX_Header&amp;gt;
&amp;lt;stix:Observables cybox_major_version="2" cybox_minor_version="1"&amp;gt;
    &amp;lt;cybox:Observable id="&amp;lt;REDACTED&amp;gt;-threat-intel:observable-9b4e5963-de78-4a06-a1b2-1c2fe4513ccc"&amp;gt;
      &amp;lt;cybox:Object id="&amp;lt;REDACTED&amp;gt;-threat-intel:URI-0e912113-6b00-4f6c-8333-fd5dbc07fe61"&amp;gt;
        &amp;lt;cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType" type="FQDN"&amp;gt;
          &amp;lt;DomainNameObj:Value&amp;gt;&amp;lt;REDACTED suspicious.com&amp;gt;&amp;lt;/DomainNameObj:Value&amp;gt;
          &amp;lt;cyboxCommon:Custom_Properties&amp;gt;
            &amp;lt;cyboxCommon:Property name="confidence"&amp;gt;80&amp;lt;/cyboxCommon:Property&amp;gt;
            &amp;lt;cyboxCommon:Property name="categories"&amp;gt;Suspicious&amp;lt;/cyboxCommon:Property&amp;gt;
          &amp;lt;/cyboxCommon:Custom_Properties&amp;gt;
        &amp;lt;/cybox:Properties&amp;gt;
      &amp;lt;/cybox:Object&amp;gt;
    &amp;lt;/cybox:Observable&amp;gt;
    &amp;lt;cybox:Observable id="&amp;lt;REDACTED&amp;gt;-threat-intel:observable-81ec8944-054d-4799-aefc-eaa45aa2ad17"&amp;gt;
      &amp;lt;cybox:Object id="&amp;lt;REDACTED&amp;gt;-threat-intel:URI-e33646db-faab-4815-a932-22eb1e7a0062"&amp;gt;
        &amp;lt;cybox:Properties xsi:type="URIObject:URIObjectType"&amp;gt;
          &amp;lt;URIObject:Value&amp;gt;&amp;lt;REDACTED suspicious.com&amp;gt;&amp;lt;/URIObject:Value&amp;gt;
          &amp;lt;cyboxCommon:Custom_Properties&amp;gt;
            &amp;lt;cyboxCommon:Property name="confidence"&amp;gt;80&amp;lt;/cyboxCommon:Property&amp;gt;
            &amp;lt;cyboxCommon:Property name="port"&amp;gt;58204&amp;lt;/cyboxCommon:Property&amp;gt;
            &amp;lt;cyboxCommon:Property name="categories"&amp;gt;Computer/Information Security,Suspicious&amp;lt;/cyboxCommon:Property&amp;gt;
          &amp;lt;/cyboxCommon:Custom_Properties&amp;gt;
        &amp;lt;/cybox:Properties&amp;gt;
      &amp;lt;/cybox:Object&amp;gt;
    &amp;lt;/cybox:Observable&amp;gt;
    ...
    &amp;lt;/cybox:Observable&amp;gt;
    &amp;lt;cybox:Observable id="&amp;lt;REDACTED&amp;gt;-threat-intel:observable-6019be08-2c42-40db-8ccc-55f46c9c856d"&amp;gt;
      &amp;lt;cybox:Object id="&amp;lt;REDACTED&amp;gt;-threat-intel:URI-8bc4bee3-3298-4af2-acb0-cd3e4a46dd23"&amp;gt;
        &amp;lt;cybox:Properties xsi:type="URIObject:URIObjectType"&amp;gt;
          &amp;lt;URIObject:Value&amp;gt;&amp;lt;REDACTED suspicious.com&amp;gt;&amp;lt;/URIObject:Value&amp;gt;
          &amp;lt;cyboxCommon:Custom_Properties&amp;gt;
            &amp;lt;cyboxCommon:Property name="confidence"&amp;gt;80&amp;lt;/cyboxCommon:Property&amp;gt;
            &amp;lt;cyboxCommon:Property name="port"&amp;gt;80&amp;lt;/cyboxCommon:Property&amp;gt;
            &amp;lt;cyboxCommon:Property name="categories"&amp;gt;Suspicious&amp;lt;/cyboxCommon:Property&amp;gt;
          &amp;lt;/cyboxCommon:Custom_Properties&amp;gt;
        &amp;lt;/cybox:Properties&amp;gt;
      &amp;lt;/cybox:Object&amp;gt;
    &amp;lt;/cybox:Observable&amp;gt;
&amp;lt;/stix:Observables&amp;gt;
&amp;lt;/stix:STIX_Package&amp;gt;

&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 15:11:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/563620#M2786</guid>
      <dc:creator>TonyZhu</dc:creator>
      <dc:date>2023-11-02T15:11:44Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest Taxii feed into XSOAR 6.12</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/564444#M2805</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/317417"&gt;@TonyZhu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Looking at the samples you've provided, these appear to be STIX packages rather than Poll Responses, which is what we'd be expecting for the response to a TAXII poll request. In a Poll Response, we'd expect the content to be inside a &amp;lt;Content_Block&amp;gt; tag which doesn't appear to be happening here and I suspect that's why nothing is getting parsed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You should be able to parse Stix Packages with&amp;nbsp;!CreateIndicatorsFromSTIX or similar, but there's no integration to automatically fetch STIX packages from a specific URL. If you want to go this route (as opposed to seeing if you can convince your taxii server to produce actual taxii responses) then a regularly scheduled job calling !HttpV2 and&amp;nbsp;!CreateIndicatorsFromSTIX would be one possible option.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 04:35:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/564444#M2805</guid>
      <dc:creator>chrking</dc:creator>
      <dc:date>2023-11-06T04:35:57Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest Taxii feed into XSOAR 6.12</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/565064#M2818</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/208030"&gt;@chrking&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the response.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am able to use curl command that is in the&amp;nbsp;&lt;SPAN&gt;integration-instance.log and replaced&amp;nbsp;Authorization: Basic &amp;lt;XX_REPLACED&amp;gt; with&amp;nbsp;Basic Auth Header. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;With following command line:&lt;/SPAN&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;curl -X POST https://api.sep.securitycloud.symantec.com/v1/threat-intel/taxii11/poll -H "Accept: */*" -H "Content-Type: application/xml" -H "X-TAXII-Content-Type: urn:taxii.mitre.org:message:xml:1.1" -H "X-TAXII-Accept: urn:taxii.mitre.org:message:xml:1.1" -H "X-TAXII-Services: urn:taxii.mitre.org:services:1.1" -H "X-TAXII-Protocol: urn:taxii.mitre.org:protocol:https:1.0" -H "Authorization: Basic &amp;lt;XX_REPLACED&amp;gt;" --noproxy "*" -d '&amp;lt;taxii_11:Poll_Request xmlns:taxii_11="http://taxii.mitre.org/messages/taxii_xml_binding-1.1"
message_id="59dec59d-2e24-4d72-9344-705e5e258813"
collection_name="malicious-file"&amp;gt;
&amp;lt;taxii_11:Exclusive_Begin_Timestamp&amp;gt;2023-10-27T23:20:00Z&amp;lt;/taxii_11:Exclusive_Begin_Timestamp&amp;gt;
&amp;lt;taxii_11:Inclusive_End_Timestamp&amp;gt;2023-10-29T19:10:00Z&amp;lt;/taxii_11:Inclusive_End_Timestamp&amp;gt;
&amp;lt;taxii_11:Poll_Parameters allow_asynch="false"&amp;gt;&amp;lt;taxii_11:Response_Type&amp;gt;FULL&amp;lt;/taxii_11:Response_Type&amp;gt;&amp;lt;/taxii_11:Poll_Parameters&amp;gt;
&amp;lt;/taxii_11:Poll_Request&amp;gt;'&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Poll_Response looks like following, there are thousands of file hash indicators so I truncated them in STIX packages.&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;lt;taxii_11:Poll_Response xmlns:taxii_11="http://taxii.mitre.org/messages/taxii_xml_binding-1.1" message_id="907893d2-4dd2-4e06-b18c-b4a04642b5c8" in_response_to="59dec59d-2e24-4d72-9344-705e5e258813" result_id="b2e8cc8c-1b6a-4485-917f-7c5de8313f1c" collection_name="malicious-file" more="true" result_part_number="1"&amp;gt;&amp;lt;taxii_11:Record_Count partial_count="false"&amp;gt;2000&amp;lt;/taxii_11:Record_Count&amp;gt;
  &amp;lt;taxii_11:Content_Block&amp;gt;
    &amp;lt;taxii_11:Content_Binding binding_id="urn:stix.mitre.org:xml:1.2"/&amp;gt;
    &amp;lt;taxii_11:Content&amp;gt;
&amp;lt;stix:STIX_Package
    xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
    xmlns:stix="http://stix.mitre.org/stix-1"
    xmlns:indicator="http://stix.mitre.org/Indicator-2"
    xmlns:cybox="http://cybox.mitre.org/cybox-2"
    xmlns:cyboxCommon="http://cybox.mitre.org/common-2"
    xmlns:URIObject="http://cybox.mitre.org/objects#URIObject-2"
    xmlns:DomainNameObj="http://cybox.mitre.org/objects#DomainNameObject-1"
    xmlns:FileObj="http://cybox.mitre.org/objects#FileObject-2"
    xmlns:AddressObject="http://cybox.mitre.org/objects#AddressObject-2"
    xmlns:report="http://stix.mitre.org/Report-1"
    xmlns:threat-actor="http://stix.mitre.org/ThreatActor-1"
    xmlns:ttp="http://stix.mitre.org/TTP-1"
    xmlns:stix-ciq="http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1"
    xmlns:stixCommon="http://stix.mitre.org/common-1"
    xmlns:xal="urn:oasis:names:tc:ciq:xal:3"
    xmlns:xpil="urn:oasis:names:tc:ciq:xpil:3"
    xmlns:cyboxVocabs="http://cybox.mitre.org/default_vocabularies-2"
    xmlns:stixVocabs="http://stix.mitre.org/default_vocabularies-1"
    id="&amp;lt;REDACTED&amp;gt;:package-fa373751-d860-4fdf-8922-52739e01ca8d"
    timestamp="2023-10-27T23:20:00Z"
    version="1.2"&amp;gt;
&amp;lt;stix:STIX_Header&amp;gt;
  &amp;lt;stix:Title&amp;gt;malicious-file for 2023-10-27T23:20:00Z - Page:1&amp;lt;/stix:Title&amp;gt;
  &amp;lt;stix:Description&amp;gt;malicious-file for 2023-10-27T23:20:00Z - Page:1&amp;lt;/stix:Description&amp;gt;
&amp;lt;/stix:STIX_Header&amp;gt;
&amp;lt;stix:Observables cybox_major_version="2" cybox_minor_version="1"&amp;gt;
    &amp;lt;cybox:Observable id="&amp;lt;REDACTED&amp;gt;:observable-b2b52fb7-12e9-4051-9a7d-4807fd09c497"&amp;gt;
      &amp;lt;cybox:Object id="&amp;lt;REDACTED&amp;gt;:File-335ee5db-36ee-40ec-bc24-096f3d9ef21c"&amp;gt;
        &amp;lt;cybox:Properties xsi:type="FileObj:FileObjectType"&amp;gt;
          &amp;lt;FileObj:Hashes&amp;gt;
            &amp;lt;cyboxCommon:Hash&amp;gt;
              &amp;lt;cyboxCommon:Type xsi:type="cyboxVocabs:HashNameVocab-1.0"&amp;gt;SHA256&amp;lt;/cyboxCommon:Type&amp;gt;
              &amp;lt;cyboxCommon:Simple_Hash_Value&amp;gt;&amp;lt;REDACTED&amp;gt;&amp;lt;/cyboxCommon:Simple_Hash_Value&amp;gt;
            &amp;lt;/cyboxCommon:Hash&amp;gt;
          &amp;lt;/FileObj:Hashes&amp;gt;
        &amp;lt;/cybox:Properties&amp;gt;
      &amp;lt;/cybox:Object&amp;gt;
    &amp;lt;/cybox:Observable&amp;gt;
    &amp;lt;cybox:Observable id="&amp;lt;REDACTED&amp;gt;:observable-59d4a0f3-ae7a-426b-893c-d425d27e43f8"&amp;gt;
      &amp;lt;cybox:Object id="&amp;lt;REDACTED&amp;gt;:File-1627e197-09c2-47d8-9723-1bb1d37b05a2"&amp;gt;
        &amp;lt;cybox:Properties xsi:type="FileObj:FileObjectType"&amp;gt;
          &amp;lt;FileObj:Hashes&amp;gt;
            &amp;lt;cyboxCommon:Hash&amp;gt;
              &amp;lt;cyboxCommon:Type xsi:type="cyboxVocabs:HashNameVocab-1.0"&amp;gt;SHA256&amp;lt;/cyboxCommon:Type&amp;gt;
              &amp;lt;cyboxCommon:Simple_Hash_Value&amp;gt;&amp;lt;REDACTED&amp;gt;&amp;lt;/cyboxCommon:Simple_Hash_Value&amp;gt;
            &amp;lt;/cyboxCommon:Hash&amp;gt;
          &amp;lt;/FileObj:Hashes&amp;gt;
        &amp;lt;/cybox:Properties&amp;gt;
      &amp;lt;/cybox:Object&amp;gt;
    &amp;lt;/cybox:Observable&amp;gt;
&amp;lt;/stix:Observables&amp;gt;
&amp;lt;/stix:STIX_Package&amp;gt;
&amp;lt;/taxii_11:Content&amp;gt;&amp;lt;/taxii_11:Content_Block&amp;gt;&amp;lt;/taxii_11:Poll_Response&amp;gt;&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 00:01:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/565064#M2818</guid>
      <dc:creator>TonyZhu</dc:creator>
      <dc:date>2023-11-10T00:01:15Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest Taxii feed into XSOAR 6.12</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/565104#M2819</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/317417"&gt;@TonyZhu&lt;/a&gt;&amp;nbsp; This first response only has a couple of indicators in it, but eyeballing them against the TAXII client code it seems like they should parse OK. At first I was wondering if XSOAR wasn't pulling subsequent pages of the poll response, but from the logs above it looks like it is.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think you'll need Engineering and (probably) a custom debug version of the taxii client to troubleshoot this, sorry.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 06:25:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/565104#M2819</guid>
      <dc:creator>chrking</dc:creator>
      <dc:date>2023-11-10T06:25:35Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest Taxii feed into XSOAR 6.12</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/565393#M2826</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/208030"&gt;@chrking&lt;/a&gt;. Really appreciate it!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There were lots of indicators (over thousands) in response I only kept few of them just for displaying, along with the response header.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Where I can get the customer debug version of the taxii client?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 16:57:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ingest-taxii-feed-into-xsoar-6-12/m-p/565393#M2826</guid>
      <dc:creator>TonyZhu</dc:creator>
      <dc:date>2023-11-13T16:57:55Z</dc:date>
    </item>
  </channel>
</rss>

