<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic XSOAR - domain_name and domain_id not mapped - Even not reflecting in past incidents in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-domain-name-and-domain-id-not-mapped-even-not-reflecting/m-p/997191#M3794</link>
    <description>&lt;P&gt;I get the hard time to mapped the domain_id under the Label section coming from Qradar data.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The mentioned fields not parsed at the first place, luckily the domain_id is found in the Qradar_instance and mapped by creating the new incident field.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Issue:&lt;/STRONG&gt; The new incident field for domain_id not being updated in the past incident, need support to reflect the same in past incident which become handy to filter out the different domains.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Dec 2024 08:23:10 GMT</pubDate>
    <dc:creator>A.Hussain514562</dc:creator>
    <dc:date>2024-12-09T08:23:10Z</dc:date>
    <item>
      <title>XSOAR - domain_name and domain_id not mapped - Even not reflecting in past incidents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-domain-name-and-domain-id-not-mapped-even-not-reflecting/m-p/997191#M3794</link>
      <description>&lt;P&gt;I get the hard time to mapped the domain_id under the Label section coming from Qradar data.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The mentioned fields not parsed at the first place, luckily the domain_id is found in the Qradar_instance and mapped by creating the new incident field.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Issue:&lt;/STRONG&gt; The new incident field for domain_id not being updated in the past incident, need support to reflect the same in past incident which become handy to filter out the different domains.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2024 08:23:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-domain-name-and-domain-id-not-mapped-even-not-reflecting/m-p/997191#M3794</guid>
      <dc:creator>A.Hussain514562</dc:creator>
      <dc:date>2024-12-09T08:23:10Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR - domain_name and domain_id not mapped - Even not reflecting in past incidents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-domain-name-and-domain-id-not-mapped-even-not-reflecting/m-p/1001611#M3847</link>
      <description>&lt;P&gt;&amp;nbsp;hey there,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;sorry, I dont fully understand, but from what I am guessing:&lt;BR /&gt;&lt;BR /&gt;So you adjusted the mapper to meet the requirements of mapping the domain_id field to an incident field.&lt;/P&gt;
&lt;P&gt;This will NOT affect old incidents, as the mapper is run before ... or better between ingestion and incident creation, so a re-run is not possible, sorry&lt;BR /&gt;&lt;BR /&gt;what you could try (no guaranty)&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Identify where the data is stored,&lt;BR /&gt;if not mapped we would expect to find them under "incident.labels"&lt;/LI&gt;
&lt;LI&gt;from the incident overview run a script against all old incidents (depends of course on the amount)&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example (far fetched one)&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;search for&amp;nbsp;&lt;EM&gt;status:closed -category:job domainoffense:""&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;Select all incidents and Run Command like&lt;BR /&gt;&lt;EM&gt;!setIncident domainoffense=${incident.labels.WHEREVER}&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Honestly not sure if it works&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 08:44:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-domain-name-and-domain-id-not-mapped-even-not-reflecting/m-p/1001611#M3847</guid>
      <dc:creator>JStephan</dc:creator>
      <dc:date>2025-01-09T08:44:33Z</dc:date>
    </item>
  </channel>
</rss>

