<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Multiple Instances fetching VS. One instance and then claasify and post a new incident in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/multiple-instances-fetching-vs-one-instance-and-then-claasify/m-p/565388#M2825</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We've got an scenario where we are fetching mails from a mail server. When an email is received in the mail server, it applies some ruling and send it to a folder, then with XSOAR we've got N instances, one per folder and this is how we are classifying incidents and Use Cases.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;While there we few folders, it seemed to be the right choice. But recently we've been growing on folders and thus on instances so we've been discussing which would be the approach.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Should we keep creating instances, one per folder? Oi isntead create one mail fetcher and the make the classification in XSOAR?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR,&lt;/P&gt;
&lt;P&gt;Fernando Otero&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XSOAR" id="Cortex_XSOAR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;#aws #fetching&lt;/P&gt;</description>
    <pubDate>Mon, 13 Nov 2023 16:05:56 GMT</pubDate>
    <dc:creator>foteromartinez</dc:creator>
    <dc:date>2023-11-13T16:05:56Z</dc:date>
    <item>
      <title>Multiple Instances fetching VS. One instance and then claasify and post a new incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/multiple-instances-fetching-vs-one-instance-and-then-claasify/m-p/565388#M2825</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We've got an scenario where we are fetching mails from a mail server. When an email is received in the mail server, it applies some ruling and send it to a folder, then with XSOAR we've got N instances, one per folder and this is how we are classifying incidents and Use Cases.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;While there we few folders, it seemed to be the right choice. But recently we've been growing on folders and thus on instances so we've been discussing which would be the approach.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Should we keep creating instances, one per folder? Oi isntead create one mail fetcher and the make the classification in XSOAR?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR,&lt;/P&gt;
&lt;P&gt;Fernando Otero&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XSOAR" id="Cortex_XSOAR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;#aws #fetching&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 16:05:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/multiple-instances-fetching-vs-one-instance-and-then-claasify/m-p/565388#M2825</guid>
      <dc:creator>foteromartinez</dc:creator>
      <dc:date>2023-11-13T16:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Instances fetching VS. One instance and then claasify and post a new incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/multiple-instances-fetching-vs-one-instance-and-then-claasify/m-p/566003#M2836</link>
      <description>&lt;P&gt;Most of the email fetching integrations, for example this one for EWS (&lt;A href="https://xsoar.pan.dev/docs/reference/integrations/ewso365" target="_blank"&gt;https://xsoar.pan.dev/docs/reference/integrations/ewso365&lt;/A&gt;) require the folder that you want to fetch from.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So in your case, you're doing it the right way where you have multiple instances, each pointing at their own folder.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you were using gmail (&lt;A href="https://xsoar.pan.dev/docs/reference/integrations/gmail#configure-gmail-in-cortex-xsoar" target="_blank"&gt;https://xsoar.pan.dev/docs/reference/integrations/gmail#configure-gmail-in-cortex-xsoar&lt;/A&gt;), then it uses a query instead of folders, so classification may apply there.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 15:46:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/multiple-instances-fetching-vs-one-instance-and-then-claasify/m-p/566003#M2836</guid>
      <dc:creator>MBeauchamp2</dc:creator>
      <dc:date>2023-11-16T15:46:24Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Instances fetching VS. One instance and then claasify and post a new incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/multiple-instances-fetching-vs-one-instance-and-then-claasify/m-p/566124#M2845</link>
      <description>&lt;P&gt;Hi!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First of all thanks a lot for your response! Is it the right choice even if we have more than 20 folders? Isn't it a bit high in computer usage?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR!&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2023 09:09:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/multiple-instances-fetching-vs-one-instance-and-then-claasify/m-p/566124#M2845</guid>
      <dc:creator>foteromartinez</dc:creator>
      <dc:date>2023-11-17T09:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Instances fetching VS. One instance and then claasify and post a new incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/multiple-instances-fetching-vs-one-instance-and-then-claasify/m-p/566169#M2847</link>
      <description>&lt;P&gt;Well it's the same amount of emails being fetched regardless right?&amp;nbsp; &amp;nbsp;As I said depending on your integration, it might be the only way to do it.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also consider the opportunity to streamline your folders on the other side if possible.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2023 15:28:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/multiple-instances-fetching-vs-one-instance-and-then-claasify/m-p/566169#M2847</guid>
      <dc:creator>MBeauchamp2</dc:creator>
      <dc:date>2023-11-17T15:28:55Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Instances fetching VS. One instance and then claasify and post a new incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/multiple-instances-fetching-vs-one-instance-and-then-claasify/m-p/566359#M2850</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/278086"&gt;@foteromartinez&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;I also want to add that depending on the integration and logic you apply while moving emails to different folders, you can also move the items to different folders using XSOAR. For example, EWS integration has the below command where you can use in a playbook. In this way, you would have less number of integration to maintain.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;DIV class="row top-padded"&gt;
&lt;DIV class="five wide break-word column integration-command-name"&gt;ews-move-item:&amp;nbsp;&lt;SPAN&gt;Move an item to different folder in the mailbox.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="row top-padded"&gt;
&lt;DIV class="five wide break-word column integration-command-name"&gt;ews-move-item-between-mailboxes:&amp;nbsp;&lt;SPAN&gt;Moves an item from one mailbox to different mailbox.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="row top-padded"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 20 Nov 2023 10:14:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/multiple-instances-fetching-vs-one-instance-and-then-claasify/m-p/566359#M2850</guid>
      <dc:creator>gyldz</dc:creator>
      <dc:date>2023-11-20T10:14:13Z</dc:date>
    </item>
  </channel>
</rss>

