<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pulling Calendar Invites from Inbox - EWS O365 Integration in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/pulling-calendar-invites-from-inbox-ews-o365-integration/m-p/572103#M2974</link>
    <description>&lt;P&gt;In the integration instance configuration, we are specifying a folder to monitor. It successfully processes email messages fine. The problem I'm having is when a calendar invite "email" type shows up. The integration is not importing it into XSOAR for processing. I can go to the folder in the Mailbox we are monitoring and see the phishing calendar invite there but the incident never gets created.&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jan 2024 17:09:55 GMT</pubDate>
    <dc:creator>sackett</dc:creator>
    <dc:date>2024-01-08T17:09:55Z</dc:date>
    <item>
      <title>Pulling Calendar Invites from Inbox - EWS O365 Integration</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/pulling-calendar-invites-from-inbox-ews-o365-integration/m-p/571804#M2968</link>
      <description>&lt;P&gt;We are using the EWS O365 integration to monitor an Exchange Online inbox. Any emails that hit the inbox get an incident created, and a Playbook handles things from there. This is working just fine but the problem I'm having is that it is ignoring calendar invite emails. Some phishing attempts we've seen come in as calendar invites, so I'd like to process them, but I don't see anything in the integration documentation about it. Is there a way to get these to import into XSOAR?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 17:12:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/pulling-calendar-invites-from-inbox-ews-o365-integration/m-p/571804#M2968</guid>
      <dc:creator>sackett</dc:creator>
      <dc:date>2024-01-04T17:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: Pulling Calendar Invites from Inbox - EWS O365 Integration</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/pulling-calendar-invites-from-inbox-ews-o365-integration/m-p/572102#M2973</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1179642397"&gt;@sackett&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;There are a few ways to do it. One way it in the integration instance configuration, you can specify a folder to monitor. You could organize emails that you want to create incidents for into a folder and other emails into another folder.&lt;/P&gt;
&lt;P&gt;Another way is to create a pre-process rule to drop/close calendar invite emails incidents or any other email that you do not want to create incidents for.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 16:51:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/pulling-calendar-invites-from-inbox-ews-o365-integration/m-p/572102#M2973</guid>
      <dc:creator>yuki_sato</dc:creator>
      <dc:date>2024-01-08T16:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: Pulling Calendar Invites from Inbox - EWS O365 Integration</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/pulling-calendar-invites-from-inbox-ews-o365-integration/m-p/572103#M2974</link>
      <description>&lt;P&gt;In the integration instance configuration, we are specifying a folder to monitor. It successfully processes email messages fine. The problem I'm having is when a calendar invite "email" type shows up. The integration is not importing it into XSOAR for processing. I can go to the folder in the Mailbox we are monitoring and see the phishing calendar invite there but the incident never gets created.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 17:09:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/pulling-calendar-invites-from-inbox-ews-o365-integration/m-p/572103#M2974</guid>
      <dc:creator>sackett</dc:creator>
      <dc:date>2024-01-08T17:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: Pulling Calendar Invites from Inbox - EWS O365 Integration</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/pulling-calendar-invites-from-inbox-ews-o365-integration/m-p/572136#M2975</link>
      <description>&lt;P&gt;Could you confirm you do not have a pre-process rule to drop calendar invite incidents?&lt;/P&gt;
&lt;P&gt;Another place to look for is the classifier of the instance. it might not classifying calendar invites as the other incident type.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 17:30:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/pulling-calendar-invites-from-inbox-ews-o365-integration/m-p/572136#M2975</guid>
      <dc:creator>yuki_sato</dc:creator>
      <dc:date>2024-01-08T17:30:57Z</dc:date>
    </item>
    <item>
      <title>Re: Pulling Calendar Invites from Inbox - EWS O365 Integration</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/pulling-calendar-invites-from-inbox-ews-o365-integration/m-p/572147#M2976</link>
      <description>&lt;P&gt;I looked at my pre-processing configuration, and I don't see any rules there, so that shouldn't be the issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I looked at the classifier info for the instance, and it looks unconfigured to me. I see a configuration at the bottom that says, "Direct unclassified events to: &amp;lt;Incident Type&amp;gt;." So, from my understanding of how this works, any items fetched by the instance should be treated as the same incident type regardless of what type of item it is. Right?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm new to XSOAR, so I may be missing something foundational/basic.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for trying to help!&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 17:50:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/pulling-calendar-invites-from-inbox-ews-o365-integration/m-p/572147#M2976</guid>
      <dc:creator>sackett</dc:creator>
      <dc:date>2024-01-08T17:50:48Z</dc:date>
    </item>
    <item>
      <title>Re: Pulling Calendar Invites from Inbox - EWS O365 Integration</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/pulling-calendar-invites-from-inbox-ews-o365-integration/m-p/572155#M2977</link>
      <description>&lt;P&gt;When you say classifier is unconfigured, do you mean there is no classifier assigned to the instance?&lt;/P&gt;
&lt;P&gt;If there is a classified, do you see anything under selected field? Do you see any incident types being assigned at the right side?&lt;/P&gt;
&lt;P&gt;"Direct unclassified events to:" portion is for unassigned incident types only, so if you don't assigned the field to identity incident type, it will be assigned to whatever is selected there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another place I would check is fetch history for the instance. Microsoft integrations have detailed fetch history table to see what was fetched so I would check there. Another option is to go into your instance configuration and change Log Level to Verbose and check what the integration instance is running. This log will be included with other logs under Settings &amp;gt; About &amp;gt; Troubleshooting &amp;gt; Download Logs&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 18:15:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/pulling-calendar-invites-from-inbox-ews-o365-integration/m-p/572155#M2977</guid>
      <dc:creator>yuki_sato</dc:creator>
      <dc:date>2024-01-08T18:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: Pulling Calendar Invites from Inbox - EWS O365 Integration</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/pulling-calendar-invites-from-inbox-ews-o365-integration/m-p/572175#M2979</link>
      <description>&lt;P&gt;Sorry for the confusion. There is a classifier configured on the instance. When I open up that classifier, I don't see anything configured. There are no entries under the various Incident Types list on the right, and everything on the left is just kind of blank. The only thing I see that seems configured is the "Direct unclassified events to:" area at the bottom. That setting has the Incident Type I&amp;nbsp;want. Since I'm not specifying any fields to incident types, wouldn't all of them be considered unclassified?&lt;BR /&gt;&lt;BR /&gt;I sent a test calendar invite to the mailbox with verbose logging enabled. When looking through the log, I see in the API response header that the invite is in the list but is never considered as a new item to be processed. Based on this info, I'd say the Content Pack is coded to ignore invites and process only emails. I see this pack is coded by XSOAR, how do I put in a request to get that feature added?&lt;BR /&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 21:06:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/pulling-calendar-invites-from-inbox-ews-o365-integration/m-p/572175#M2979</guid>
      <dc:creator>sackett</dc:creator>
      <dc:date>2024-01-08T21:06:52Z</dc:date>
    </item>
  </channel>
</rss>

