<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mapping labels &amp;quot;message&amp;quot; to Incident Context without Regex in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/mapping-labels-quot-message-quot-to-incident-context-without/m-p/570263#M2918</link>
    <description>&lt;P&gt;Looks like this is supposed to be auto mapped. Threat logs fetch from the Abnormal Security integration isn't parsing rawJson correctly so it comes in as one message. Campaigns and takeover requests are parsing correctly. Will contact vendor for support.&lt;BR /&gt;&lt;BR /&gt;On a side note, an easier approach than using regex to get the fields from labels.messages is to apply ParseJson transformer and then use Get field transformer to grab the value of the key,value pairs within the json message.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 18 Dec 2023 18:59:41 GMT</pubDate>
    <dc:creator>JohnsonJu</dc:creator>
    <dc:date>2023-12-18T18:59:41Z</dc:date>
    <item>
      <title>Mapping labels "message" to Incident Context without Regex</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/mapping-labels-quot-message-quot-to-incident-context-without/m-p/569733#M2910</link>
      <description>&lt;P&gt;Kind of similar to the below link:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cortex-xsoar-context-issue/td-p/437729" target="_blank"&gt;LIVEcommunity - Cortex XSOAR Context Issue - LIVEcommunity - 437729 (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've tried mapping content from the Abnormal Security integration&amp;nbsp;and from the Syslog v2 integration. The&amp;nbsp;Abnormal Security integration dumps the raw logs into labels.messages, meanwhile Syslog dumps the whole raw log into details.&amp;nbsp; Is there&amp;nbsp;a way to parse out chunks of data without using regex in every field of the incoming mapper?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 16:20:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/mapping-labels-quot-message-quot-to-incident-context-without/m-p/569733#M2910</guid>
      <dc:creator>JohnsonJu</dc:creator>
      <dc:date>2023-12-13T16:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: Mapping labels "message" to Incident Context without Regex</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/mapping-labels-quot-message-quot-to-incident-context-without/m-p/570263#M2918</link>
      <description>&lt;P&gt;Looks like this is supposed to be auto mapped. Threat logs fetch from the Abnormal Security integration isn't parsing rawJson correctly so it comes in as one message. Campaigns and takeover requests are parsing correctly. Will contact vendor for support.&lt;BR /&gt;&lt;BR /&gt;On a side note, an easier approach than using regex to get the fields from labels.messages is to apply ParseJson transformer and then use Get field transformer to grab the value of the key,value pairs within the json message.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Dec 2023 18:59:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/mapping-labels-quot-message-quot-to-incident-context-without/m-p/570263#M2918</guid>
      <dc:creator>JohnsonJu</dc:creator>
      <dc:date>2023-12-18T18:59:41Z</dc:date>
    </item>
  </channel>
</rss>

