<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XSOAR Context Issue in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cortex-xsoar-context-issue/m-p/437729#M366</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Everyone,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have Cortex XSOAR with SplunkPY running and fetching incidents. I am using Splunk classifier and Splunk incoming mapper by default.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Drill down is being enriched successfully and i can see it parsed at both classifier &amp;amp; mapper stages - see below screenshot&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drilldown parsed in classifier&amp;amp;mapper" style="width: 362px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36696i49CD2271FADCD124/image-dimensions/362x251/is-moderation-mode/true?v=v2" width="362" height="251" role="button" title="2021-09-30_181850.png" alt="drilldown parsed in classifier&amp;amp;mapper" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;drilldown parsed in classifier&amp;amp;mapper&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;However, context is not splitting drill down details , It's all coming in one chunk of data and cannot be used in any playbook. - Below screenshot&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drilldown nor parsed in context" style="width: 467px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36695i3ADE169B539D84EE/image-dimensions/467x219/is-moderation-mode/true?v=v2" width="467" height="219" role="button" title="2021-09-30_182723.png" alt="drilldown nor parsed in context" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;drilldown nor parsed in context&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas what might be causing this? Is there anywhere else to check that might affect Drilldown parsing in context?&lt;/P&gt;</description>
    <pubDate>Thu, 30 Sep 2021 15:33:17 GMT</pubDate>
    <dc:creator>Rawabdeh</dc:creator>
    <dc:date>2021-09-30T15:33:17Z</dc:date>
    <item>
      <title>Cortex XSOAR Context Issue</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cortex-xsoar-context-issue/m-p/437729#M366</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Everyone,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have Cortex XSOAR with SplunkPY running and fetching incidents. I am using Splunk classifier and Splunk incoming mapper by default.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Drill down is being enriched successfully and i can see it parsed at both classifier &amp;amp; mapper stages - see below screenshot&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drilldown parsed in classifier&amp;amp;mapper" style="width: 362px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36696i49CD2271FADCD124/image-dimensions/362x251/is-moderation-mode/true?v=v2" width="362" height="251" role="button" title="2021-09-30_181850.png" alt="drilldown parsed in classifier&amp;amp;mapper" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;drilldown parsed in classifier&amp;amp;mapper&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;However, context is not splitting drill down details , It's all coming in one chunk of data and cannot be used in any playbook. - Below screenshot&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drilldown nor parsed in context" style="width: 467px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36695i3ADE169B539D84EE/image-dimensions/467x219/is-moderation-mode/true?v=v2" width="467" height="219" role="button" title="2021-09-30_182723.png" alt="drilldown nor parsed in context" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;drilldown nor parsed in context&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas what might be causing this? Is there anywhere else to check that might affect Drilldown parsing in context?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 15:33:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cortex-xsoar-context-issue/m-p/437729#M366</guid>
      <dc:creator>Rawabdeh</dc:creator>
      <dc:date>2021-09-30T15:33:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XSOAR Context Issue</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cortex-xsoar-context-issue/m-p/437865#M367</link>
      <description>&lt;P&gt;I think you have a transform issue.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Look at the following link on YouTube to MOD44's&amp;nbsp;&lt;A href="https://www.youtube.com/watch?v=OZAXnsdSYlI&amp;amp;list=PL_ZuwXjrdb3j_vcAFCMLQxlJ6oFAi3HYT&amp;amp;index=1" target="_blank" rel="noopener"&gt;PCSAE - Palo Alto Networks - Certification- Training- Domain 1&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Skip ahead to 34:15, I think this will help you.&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 19:35:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cortex-xsoar-context-issue/m-p/437865#M367</guid>
      <dc:creator>Strunce</dc:creator>
      <dc:date>2021-09-30T19:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XSOAR Context Issue</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cortex-xsoar-context-issue/m-p/438310#M368</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/191792"&gt;@Strunce&lt;/a&gt;&amp;nbsp;thank you for your reply.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This video discusses splitting data at classifier level, but I have that already applied in my classifier &amp;amp; mapper as per the above screenshots. No transformations are present within my classifier or mapper.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just created a complete new account with fresh installation and integration with a totally different Splunk instance and the same issue persists.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you happen to know how data is filled into context and what controls this process? should I dig into automations for pre-processing rules?&lt;/P&gt;</description>
      <pubDate>Sun, 03 Oct 2021 08:59:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cortex-xsoar-context-issue/m-p/438310#M368</guid>
      <dc:creator>Rawabdeh</dc:creator>
      <dc:date>2021-10-03T08:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XSOAR Context Issue</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cortex-xsoar-context-issue/m-p/438381#M369</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/143999"&gt;@Rawabdeh&lt;/a&gt;&amp;nbsp;, the fields you are showing (incident -&amp;gt; labels -&amp;gt; drilldown) are not being mapped. By default, each mapper has a couple of fields mapped. The rest of the fields are copied verbatim into the context data under "labels". This setting can be disable (if you wanted to) under the settings of the mapper under Advanced:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ABurt_0-1633334144942.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36761i62FBA333971DF405/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ABurt_0-1633334144942.png" alt="ABurt_0-1633334144942.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All data under the labels will be as presented by the source technology. If you would like the data parsed, you would need to alter the Splunk incoming mapper to map that field.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you know how you would like the data presented? As a table perhaps?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adam&lt;/P&gt;</description>
      <pubDate>Mon, 04 Oct 2021 07:57:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cortex-xsoar-context-issue/m-p/438381#M369</guid>
      <dc:creator>ABurt</dc:creator>
      <dc:date>2021-10-04T07:57:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XSOAR Context Issue</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cortex-xsoar-context-issue/m-p/438833#M385</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;for your contribution&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/169171"&gt;@ABurt&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually drill down is supposed to look like the first screenshot (I'm using it in my playbooks as&amp;nbsp;&lt;A target="_blank"&gt;Drilldown.[0].Country&lt;/A&gt;&lt;A target="_blank"&gt;.[0]&lt;/A&gt;&lt;A target="_blank"&gt; &lt;FONT color="#000000"&gt;&lt;U&gt;&amp;gt;&amp;gt; &lt;/U&gt;maps to: Saudi Arabia in the first screenshot)&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;I have tried checking that box you mentioned and indeed, it stopped throwing all JSON details under incident.labels and I was able to use the custom field (mapped with drilldown values) I&lt;/FONT&gt;&lt;FONT color="#000000"&gt; created. But that means I have to create a field for each value in each alert coming from Splunk and i don't think that's a feasible solution.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;What's confusing me is that context had drill down parsed just the way it's seen in mapper and I built my playbooks based on this format. Out of nowhere it noticed empty data in sub-playbooks and found out about this issue. No changes were applied on any account&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 14:23:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cortex-xsoar-context-issue/m-p/438833#M385</guid>
      <dc:creator>Rawabdeh</dc:creator>
      <dc:date>2021-10-05T14:23:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XSOAR Context Issue</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cortex-xsoar-context-issue/m-p/438844#M386</link>
      <description>&lt;P&gt;During the classification and mapping this is generally the way data is processed:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Classification determines what type of incident each new incident creation is created as&lt;/LI&gt;&lt;LI&gt;Mapping (specifically incoming in this instance) maps all the fields based on the type of incident (or globally)&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks as if the incoming mapper in screenshot 1 is populating a field named "drilldown" in the incident. This would honour the transformation happening at the mapper (i.e. the parseJSON transformer). The second screenshot, when data ends up in the labels, does not undergo any mapper rules such as the parse JSON.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the first screenshot, is the "drilldown" appearing in the incident as its own field or is this under the same "labels" as in the second screenshot?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 14:28:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cortex-xsoar-context-issue/m-p/438844#M386</guid>
      <dc:creator>ABurt</dc:creator>
      <dc:date>2021-10-05T14:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XSOAR Context Issue</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cortex-xsoar-context-issue/m-p/439074#M387</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/169171"&gt;@ABurt&lt;/a&gt;&amp;nbsp; This is exactly what's happening, context is not picking up this exact JSON parser.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Drill down is coming under label as shown in this screenshot&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2021-10-06_145147.png" style="width: 485px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36848i402FC9A68D5F8E1E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2021-10-06_145147.png" alt="2021-10-06_145147.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here i say it again, it was all parsed before and i built my playbooks based on these values.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Oct 2021 11:59:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cortex-xsoar-context-issue/m-p/439074#M387</guid>
      <dc:creator>Rawabdeh</dc:creator>
      <dc:date>2021-10-06T11:59:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XSOAR Context Issue</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cortex-xsoar-context-issue/m-p/439083#M388</link>
      <description>&lt;P&gt;Has anything else changed since you built the playbooks. Such as updating XSOAR or any changes to Splunk?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Oct 2021 13:05:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cortex-xsoar-context-issue/m-p/439083#M388</guid>
      <dc:creator>ABurt</dc:creator>
      <dc:date>2021-10-06T13:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XSOAR Context Issue</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cortex-xsoar-context-issue/m-p/439104#M389</link>
      <description>&lt;P&gt;That's what I've been trying to find out. the only changes I've made are on playbook inputs and classification. I have no idea how context parsing started behaving like this&lt;/P&gt;</description>
      <pubDate>Wed, 06 Oct 2021 14:36:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cortex-xsoar-context-issue/m-p/439104#M389</guid>
      <dc:creator>Rawabdeh</dc:creator>
      <dc:date>2021-10-06T14:36:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XSOAR Context Issue</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cortex-xsoar-context-issue/m-p/439118#M390</link>
      <description>&lt;P&gt;I have just created 4 fields and mapped their values to drill down details and it's working fine. I know this isn't the best practice to create custom fields for each alert coming from Splunk. This was only for testing purposes.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can confirm that this isn't related to drill down fetching or mapping. issue is narrowed down to context display i believe.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rawabdeh_1-1633532783695.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36853iDD97A835A12FAB1F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Rawabdeh_1-1633532783695.png" alt="Rawabdeh_1-1633532783695.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rawabdeh_0-1633532369929.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36852i1B355847BF353BD3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Rawabdeh_0-1633532369929.png" alt="Rawabdeh_0-1633532369929.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Oct 2021 15:06:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cortex-xsoar-context-issue/m-p/439118#M390</guid>
      <dc:creator>Rawabdeh</dc:creator>
      <dc:date>2021-10-06T15:06:46Z</dc:date>
    </item>
  </channel>
</rss>

