<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic XSOAR keeps firing the same incident in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-keeps-firing-the-same-incident/m-p/614119#M3723</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My XSOAR instance is a cloud hosted environment running on the latest version 8 build.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a playbook that sends a notification email to a user in response to a change in their account settings to confirm if recognized. The user is requested to respond via the webform link that the data collection task generates in the email that gets sent. The webform expires after an hour if the user fails to respond.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If a user does not respond within the hour, the playbook flow stops there and updates the XSOAR case with a custom message I defined. This has always been the case for the past few months since this playbook was created.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, since the beginning of this week (21-Oct-2024), XSOAR keeps creating cases on the same detection until a user responds to the email. This has resulted in hundreds of notification emails being sent to each user.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have created a TAC case for investigation and have had to stop the auto-run of the playbook to stop the email spam until this gets resolved.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone else in the community come across the same issue in their environment recently ?&lt;/P&gt;</description>
    <pubDate>Thu, 24 Oct 2024 01:09:16 GMT</pubDate>
    <dc:creator>PWJ2020</dc:creator>
    <dc:date>2024-10-24T01:09:16Z</dc:date>
    <item>
      <title>XSOAR keeps firing the same incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-keeps-firing-the-same-incident/m-p/614119#M3723</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My XSOAR instance is a cloud hosted environment running on the latest version 8 build.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a playbook that sends a notification email to a user in response to a change in their account settings to confirm if recognized. The user is requested to respond via the webform link that the data collection task generates in the email that gets sent. The webform expires after an hour if the user fails to respond.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If a user does not respond within the hour, the playbook flow stops there and updates the XSOAR case with a custom message I defined. This has always been the case for the past few months since this playbook was created.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, since the beginning of this week (21-Oct-2024), XSOAR keeps creating cases on the same detection until a user responds to the email. This has resulted in hundreds of notification emails being sent to each user.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have created a TAC case for investigation and have had to stop the auto-run of the playbook to stop the email spam until this gets resolved.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone else in the community come across the same issue in their environment recently ?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2024 01:09:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-keeps-firing-the-same-incident/m-p/614119#M3723</guid>
      <dc:creator>PWJ2020</dc:creator>
      <dc:date>2024-10-24T01:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR keeps firing the same incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-keeps-firing-the-same-incident/m-p/615884#M3748</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/245785"&gt;@PWJ2020&lt;/a&gt;,&amp;nbsp;Can you please share the TAC case number that you created so that I can track it internally?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, would it be possible for you to share a screenshot of the section in your playbook that implements this functionality?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 17:52:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-keeps-firing-the-same-incident/m-p/615884#M3748</guid>
      <dc:creator>AbelSantamarina</dc:creator>
      <dc:date>2024-10-31T17:52:53Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR keeps firing the same incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-keeps-firing-the-same-incident/m-p/616390#M3762</link>
      <description>&lt;P&gt;Hi Abel,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Deepti is updating you on Slack right now as of this message &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2024 04:12:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-keeps-firing-the-same-incident/m-p/616390#M3762</guid>
      <dc:creator>PWJ2020</dc:creator>
      <dc:date>2024-11-08T04:12:03Z</dc:date>
    </item>
  </channel>
</rss>

