<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XSOAR Qradar Offense Ingestion Doubt in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-qradar-offense-ingestion-doubt/m-p/591091#M3429</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/171829"&gt;@DSilva8&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you share the query you are using in XSOAR to pull in offenses from QRadar?&amp;nbsp;&lt;BR /&gt;I think whare you are describing is the expected behavior. Unless your query for specific rule IDs triggers new offenses in QRadar, you won't see those offenses being ingested into XSOAR. This is because they are related to other offenses that don't match your query.&lt;/P&gt;</description>
    <pubDate>Wed, 03 Jul 2024 18:14:24 GMT</pubDate>
    <dc:creator>AbelSantamarina</dc:creator>
    <dc:date>2024-07-03T18:14:24Z</dc:date>
    <item>
      <title>XSOAR Qradar Offense Ingestion Doubt</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-qradar-offense-ingestion-doubt/m-p/590693#M3414</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We've a situation that we would like to clarify if it's a misconfiguration or if it is an expected behaviour.&lt;BR /&gt;&lt;BR /&gt;#Qradar integration is only fetching ofenses that includes specific rule ids but qradar how it works associates new events and new rules while we do not close the offense.&lt;BR /&gt;This causes that for example, the rule that triggered ofense number X is not one of the identified rules to fetch ofenses in xsoar so it's not fetched to xSOAR but it can be the case that 10/20 minutes later a new alert was triggered and it's generated by a rule that is identified to be fetched to qradar.&lt;BR /&gt;But As the last fetched timestamp and ofense ID is higher than the time and ID of offense that was update with new events and rule IDS, it's not fetched anymore.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Is there any way to fix it?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance,&lt;/P&gt;
&lt;P&gt;Davide Silva&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2024 08:45:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-qradar-offense-ingestion-doubt/m-p/590693#M3414</guid>
      <dc:creator>DSilva8</dc:creator>
      <dc:date>2024-06-28T08:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR Qradar Offense Ingestion Doubt</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-qradar-offense-ingestion-doubt/m-p/591091#M3429</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/171829"&gt;@DSilva8&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you share the query you are using in XSOAR to pull in offenses from QRadar?&amp;nbsp;&lt;BR /&gt;I think whare you are describing is the expected behavior. Unless your query for specific rule IDs triggers new offenses in QRadar, you won't see those offenses being ingested into XSOAR. This is because they are related to other offenses that don't match your query.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2024 18:14:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-qradar-offense-ingestion-doubt/m-p/591091#M3429</guid>
      <dc:creator>AbelSantamarina</dc:creator>
      <dc:date>2024-07-03T18:14:24Z</dc:date>
    </item>
  </channel>
</rss>

