<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Extrahop Reveal X Integration - Stop fetching of Hidden Detections possible? in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/extrahop-reveal-x-integration-stop-fetching-of-hidden-detections/m-p/1220765#M3904</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/975922579"&gt;@C.Perez&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Advanced Filter of ExtraHop Reveal(x)&amp;nbsp;integration is dictated by ExtraHop API. On their API documentation (&lt;A href="https://docs.extrahop.com/current/rest-api-guide/" target="_blank"&gt;https://docs.extrahop.com/current/rest-api-guide/)&lt;/A&gt;&amp;nbsp;under Detection categories, there is a list of supported categories that you can access via API and there is no .none.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It would be either .none categories is not available or not officially supported. I would reach out to ExtraHop since this is their API endpoint.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 18 Feb 2025 20:00:50 GMT</pubDate>
    <dc:creator>yuki_sato</dc:creator>
    <dc:date>2025-02-18T20:00:50Z</dc:date>
    <item>
      <title>Extrahop Reveal X Integration - Stop fetching of Hidden Detections possible?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/extrahop-reveal-x-integration-stop-fetching-of-hidden-detections/m-p/1220676#M3898</link>
      <description>&lt;P&gt;We've recently use the Extrahop integration to create tickets in XSOAR for our analysts to keep track of Extrahop tickets without having to go into Extrahop's console. However, we're trying to stop it from fetching "Hidden" or tuned detections I'm tuning out in Extrahop. I only fetch for 60+ Risk Scores and for "Open" or&amp;nbsp;&lt;SPAN&gt;.none per the filtering,&lt;/SPAN&gt;&amp;nbsp;detections only. I've tried "&lt;SPAN&gt;New&lt;/SPAN&gt;" but I think you need to enable some type of ticketing process for it to get a "New" status as it isn't grabbing any new legit one's that are open now. Hidden detections stay in an "Open" state so this filter will stay grab them even if they're supposed to be tuned. Anyone know how I can tune out "Hidden" / tuned detections from Extrahop to stop being fetched by the Extrahop integration in XSOAR?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;This is the Advanced Filter I'm using&lt;/P&gt;
&lt;P&gt;{&lt;BR /&gt;"status": ["&lt;SPAN&gt;.none&lt;/SPAN&gt;"],&lt;BR /&gt;"risk_score_min": 60&lt;BR /&gt;}&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 17:04:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/extrahop-reveal-x-integration-stop-fetching-of-hidden-detections/m-p/1220676#M3898</guid>
      <dc:creator>C.Perez</dc:creator>
      <dc:date>2025-02-17T17:04:09Z</dc:date>
    </item>
    <item>
      <title>Re: Extrahop Reveal X Integration - Stop fetching of Hidden Detections possible?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/extrahop-reveal-x-integration-stop-fetching-of-hidden-detections/m-p/1220765#M3904</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/975922579"&gt;@C.Perez&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Advanced Filter of ExtraHop Reveal(x)&amp;nbsp;integration is dictated by ExtraHop API. On their API documentation (&lt;A href="https://docs.extrahop.com/current/rest-api-guide/" target="_blank"&gt;https://docs.extrahop.com/current/rest-api-guide/)&lt;/A&gt;&amp;nbsp;under Detection categories, there is a list of supported categories that you can access via API and there is no .none.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It would be either .none categories is not available or not officially supported. I would reach out to ExtraHop since this is their API endpoint.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2025 20:00:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/extrahop-reveal-x-integration-stop-fetching-of-hidden-detections/m-p/1220765#M3904</guid>
      <dc:creator>yuki_sato</dc:creator>
      <dc:date>2025-02-18T20:00:50Z</dc:date>
    </item>
    <item>
      <title>Re: Extrahop Reveal X Integration - Stop fetching of Hidden Detections possible?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/extrahop-reveal-x-integration-stop-fetching-of-hidden-detections/m-p/1221150#M3909</link>
      <description>&lt;P&gt;Gotcha, I'll reach out to them thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 14:32:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/extrahop-reveal-x-integration-stop-fetching-of-hidden-detections/m-p/1221150#M3909</guid>
      <dc:creator>C.Perez</dc:creator>
      <dc:date>2025-02-20T14:32:02Z</dc:date>
    </item>
  </channel>
</rss>

