<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ESA (Cisco IronPort) and XSOAR Integration in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cisco-esa-cisco-ironport-and-xsoar-integration/m-p/600669#M3706</link>
    <description>&lt;P&gt;Kindly find below the used command:&lt;/P&gt;
&lt;P&gt;!cisco-sma-message-search end_date=now start_date="2 days" subject_filter_operator=contains subject_filter_value="_Subject_Name_"&lt;/P&gt;</description>
    <pubDate>Tue, 15 Oct 2024 08:37:53 GMT</pubDate>
    <dc:creator>Omar_Hany</dc:creator>
    <dc:date>2024-10-15T08:37:53Z</dc:date>
    <item>
      <title>Cisco ESA (Cisco IronPort) and XSOAR Integration</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cisco-esa-cisco-ironport-and-xsoar-integration/m-p/600478#M3700</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm facing an issue with my integration between Cisco ESA and XSOAR. When I search for specific emails that contain attachments or subjects in Arabic, the SOAR can fetch and display them without any problem. However, when I try to search specifically using an Arabic subject line, the SOAR fails to perform the search.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone encountered a similar issue or have any recommendations on how to resolve this? Any help would be greatly appreciated!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Oct 2024 20:38:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cisco-esa-cisco-ironport-and-xsoar-integration/m-p/600478#M3700</guid>
      <dc:creator>Omar_Hany</dc:creator>
      <dc:date>2024-10-13T20:38:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ESA (Cisco IronPort) and XSOAR Integration</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cisco-esa-cisco-ironport-and-xsoar-integration/m-p/600524#M3704</link>
      <description>&lt;P&gt;Could you share which integration command you are using for this?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2024 15:22:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cisco-esa-cisco-ironport-and-xsoar-integration/m-p/600524#M3704</guid>
      <dc:creator>yuki_sato</dc:creator>
      <dc:date>2024-10-14T15:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ESA (Cisco IronPort) and XSOAR Integration</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cisco-esa-cisco-ironport-and-xsoar-integration/m-p/600669#M3706</link>
      <description>&lt;P&gt;Kindly find below the used command:&lt;/P&gt;
&lt;P&gt;!cisco-sma-message-search end_date=now start_date="2 days" subject_filter_operator=contains subject_filter_value="_Subject_Name_"&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2024 08:37:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cisco-esa-cisco-ironport-and-xsoar-integration/m-p/600669#M3706</guid>
      <dc:creator>Omar_Hany</dc:creator>
      <dc:date>2024-10-15T08:37:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ESA (Cisco IronPort) and XSOAR Integration</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cisco-esa-cisco-ironport-and-xsoar-integration/m-p/600678#M3707</link>
      <description>&lt;P&gt;I found that it can fetch the results successfully, the main problem was searching with subjects or attachments that have more than one word.&lt;/P&gt;
&lt;P&gt;For example, if I search for subject "Forward Test", the query does not return any results.&lt;/P&gt;
&lt;P&gt;However, if I search for just Forward" or "Test" individually, it successfully fetches the results.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Any suggestion to solve this issue would be greatly appreciated&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2024 09:40:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cisco-esa-cisco-ironport-and-xsoar-integration/m-p/600678#M3707</guid>
      <dc:creator>Omar_Hany</dc:creator>
      <dc:date>2024-10-15T09:40:36Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ESA (Cisco IronPort) and XSOAR Integration</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cisco-esa-cisco-ironport-and-xsoar-integration/m-p/600776#M3709</link>
      <description>&lt;P&gt;Looking at the integration code and the API document by Cisco, it does look to follow the API guide (&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/esa/esa15-5-1/api_guide/b_Secure_Email_API_Guide_15-5-1/b_ESA_API_Guide_chapter_010.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/esa/esa15-5-1/api_guide/b_Secure_Email_API_Guide_15-5-1/b_ESA_API_Guide_chapter_010.html&lt;/A&gt;). I included a screenshot of where the integration submits GET request to the API endpoint.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I do want to point out that in XSOAR, parameters (end_date, start_date,&amp;nbsp;subject_filter_operator, etc.) are set under params variable but according to the API documentation, the endpoint is expecting "endDate=2018-11-23T00:00:00.000Z&amp;amp;limit=25&amp;amp;offset=0&amp;amp;orderBy=&lt;BR /&gt;received&amp;amp;orderDir=desc&amp;amp;quarantineType=pvo&amp;amp;quarantines=Outbreak,Virus,File+Analysis,Unclassified,Policy&amp;amp;startDate" format where each parameter is concatenated with "&amp;amp;". I would test this format and how XSOAR is submitting the request to make sure they are both supported.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;If you have an API tool like Postman, I would test submitting requests to the endpoint by setting these variables up to verify if the endpoint accepts subjectFilterValue:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;params = assign_params(&lt;BR /&gt;envelopeSenderfilterOperator=sender_filter_operator,&lt;BR /&gt;envelopeSenderfilterValue=sender_filter_value,&lt;BR /&gt;envelopeRecipientfilterOperator=recipient_filter_operator,&lt;BR /&gt;envelopeRecipientfilterValue=recipient_filter_value,&lt;BR /&gt;subjectfilterOperator=subject_filter_operator,&lt;BR /&gt;subjectfilterValue=subject_filter_value,&lt;BR /&gt;ciscoHost=cisco_host,&lt;BR /&gt;searchOption=search_option,&lt;BR /&gt;offset=offset,&lt;BR /&gt;limit=limit,&lt;BR /&gt;fileSha256=file_sha_256,&lt;BR /&gt;attachmentNameOperator=attachment_name_operator,&lt;BR /&gt;attachmentNameValue=attachment_name_value,&lt;BR /&gt;**format_custom_query_args(custom_query),&lt;BR /&gt;)&lt;/P&gt;
&lt;P&gt;return self._http_request("GET",f"message-tracking/messages?startDate={start_date}&amp;amp;endDate={end_date}",params=params,)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2024 15:32:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cisco-esa-cisco-ironport-and-xsoar-integration/m-p/600776#M3709</guid>
      <dc:creator>yuki_sato</dc:creator>
      <dc:date>2024-10-15T15:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ESA (Cisco IronPort) and XSOAR Integration</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cisco-esa-cisco-ironport-and-xsoar-integration/m-p/600815#M3710</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1047883985"&gt;@Omar_Hany&lt;/a&gt;&amp;nbsp;Try url encoding your subject and then passing it as value to the argument&amp;nbsp;&lt;SPAN&gt;subject_filter_value. If you try "Forward%20Test" instead of "Forward Test" it might work.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2024 17:50:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/cisco-esa-cisco-ironport-and-xsoar-integration/m-p/600815#M3710</guid>
      <dc:creator>akoppad</dc:creator>
      <dc:date>2024-10-15T17:50:12Z</dc:date>
    </item>
  </channel>
</rss>

