<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Updating Cortex XDR EDL from XSOAR in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/updating-cortex-xdr-edl-from-xsoar/m-p/1001636#M3848</link>
    <description>&lt;P&gt;Hello LiveComm,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am building a use-case in which we want to update and manage the Cortex XDR EDL from the XSOAR. We do not want just to create new IOC's but rather we want to interact with the EDL so that Firewalls can access it correctly. From what I have read on the various documentation the Cortex XDR EDL is&amp;nbsp; not available for API access (Management). Can someone suggest how we can build this or perhaps change the flow of this case to use the export generic indicator service and let the XDR pull what it needs to update the EDL.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks,&lt;/P&gt;
&lt;P&gt;MR&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XSOAR" id="Cortex_XSOAR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 09 Jan 2025 09:37:40 GMT</pubDate>
    <dc:creator>michaelsysec242</dc:creator>
    <dc:date>2025-01-09T09:37:40Z</dc:date>
    <item>
      <title>Updating Cortex XDR EDL from XSOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/updating-cortex-xdr-edl-from-xsoar/m-p/1001636#M3848</link>
      <description>&lt;P&gt;Hello LiveComm,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am building a use-case in which we want to update and manage the Cortex XDR EDL from the XSOAR. We do not want just to create new IOC's but rather we want to interact with the EDL so that Firewalls can access it correctly. From what I have read on the various documentation the Cortex XDR EDL is&amp;nbsp; not available for API access (Management). Can someone suggest how we can build this or perhaps change the flow of this case to use the export generic indicator service and let the XDR pull what it needs to update the EDL.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks,&lt;/P&gt;
&lt;P&gt;MR&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XSOAR" id="Cortex_XSOAR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 09:37:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/updating-cortex-xdr-edl-from-xsoar/m-p/1001636#M3848</guid>
      <dc:creator>michaelsysec242</dc:creator>
      <dc:date>2025-01-09T09:37:40Z</dc:date>
    </item>
    <item>
      <title>Re: Updating Cortex XDR EDL from XSOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/updating-cortex-xdr-edl-from-xsoar/m-p/1001865#M3849</link>
      <description>&lt;P&gt;Hey there,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IMHO an option would be to use XSOAR to handle the EDL completely,&lt;/P&gt;
&lt;P&gt;so adding the XDR EDL to XSOAR as a feed and using the generic export to update the firewalls&lt;/P&gt;
&lt;P&gt;additional you could use the XDR IOC integration to add indicators to XDR itself if needed&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 14:53:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/updating-cortex-xdr-edl-from-xsoar/m-p/1001865#M3849</guid>
      <dc:creator>JStephan</dc:creator>
      <dc:date>2025-01-09T14:53:37Z</dc:date>
    </item>
  </channel>
</rss>

