<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic XSOAR Qradar Ingestion in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-qradar-ingestion/m-p/465373#M563</link>
    <description>&lt;P&gt;I am attempting to ingest Qradar into the XSOAR using the Integration. I need to pull &lt;STRONG&gt;custom fields&lt;/STRONG&gt; from the SIEM&amp;nbsp; and what I need to understand is as follows;&lt;/P&gt;&lt;P&gt;Is it preferable to pull these fields within an AQL Search at the playbook stage ?&lt;/P&gt;&lt;P&gt;Or is it preferable to pull these fields from Qradar Integration setting ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;The use case is as follows;&lt;/P&gt;&lt;P&gt;I am dealing with a SIEM that has different fields assigned per offence type. For example, Target Domain(Custom) appears in a particular offence and under a different name in a different offence. I do not have access to change the Qradar Fields.&lt;/P&gt;&lt;P&gt;My preferable solution would be to perform a search according to each type within the playbook.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone provide me with an &lt;STRONG&gt;example of a simple AQL Query for pulling a Custom field&lt;/STRONG&gt; and its contents for a specific offence ?&lt;/P&gt;&lt;P&gt;Thanks in Advanced&lt;/P&gt;</description>
    <pubDate>Sun, 13 Feb 2022 08:32:05 GMT</pubDate>
    <dc:creator>michaelsysec242</dc:creator>
    <dc:date>2022-02-13T08:32:05Z</dc:date>
    <item>
      <title>XSOAR Qradar Ingestion</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-qradar-ingestion/m-p/465373#M563</link>
      <description>&lt;P&gt;I am attempting to ingest Qradar into the XSOAR using the Integration. I need to pull &lt;STRONG&gt;custom fields&lt;/STRONG&gt; from the SIEM&amp;nbsp; and what I need to understand is as follows;&lt;/P&gt;&lt;P&gt;Is it preferable to pull these fields within an AQL Search at the playbook stage ?&lt;/P&gt;&lt;P&gt;Or is it preferable to pull these fields from Qradar Integration setting ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;The use case is as follows;&lt;/P&gt;&lt;P&gt;I am dealing with a SIEM that has different fields assigned per offence type. For example, Target Domain(Custom) appears in a particular offence and under a different name in a different offence. I do not have access to change the Qradar Fields.&lt;/P&gt;&lt;P&gt;My preferable solution would be to perform a search according to each type within the playbook.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone provide me with an &lt;STRONG&gt;example of a simple AQL Query for pulling a Custom field&lt;/STRONG&gt; and its contents for a specific offence ?&lt;/P&gt;&lt;P&gt;Thanks in Advanced&lt;/P&gt;</description>
      <pubDate>Sun, 13 Feb 2022 08:32:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-qradar-ingestion/m-p/465373#M563</guid>
      <dc:creator>michaelsysec242</dc:creator>
      <dc:date>2022-02-13T08:32:05Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR Qradar Ingestion</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-qradar-ingestion/m-p/466989#M576</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;Unless you have a special reason to do it form the playbook then to set it in the integration instance setting would be proffered:&lt;BR /&gt;1. You'll save resources by not executing&amp;nbsp;unnecessary commands in the playbook&lt;BR /&gt;2. You'll be able to map those Qradar custom fields using the Classification &amp;amp; Mapping XSOAR feature, which will also allow the optimal usage of pre-processing rules and more.&lt;BR /&gt;&lt;BR /&gt;In this care you I think that it all depends on the amount of custom fields, and based on that you'll know which approach is better for you.&lt;BR /&gt;&lt;BR /&gt;Please contact IBM regarding technical questions for Qradar's AQL, examples can be found here:&lt;BR /&gt;&lt;A href="https://www.ibm.com/docs/en/qsip/7.4?topic=aql-ariel-query-language," target="_blank"&gt;https://www.ibm.com/docs/en/qsip/7.4?topic=aql-ariel-query-language&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;thanks.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Feb 2022 20:37:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-qradar-ingestion/m-p/466989#M576</guid>
      <dc:creator>gfilippov</dc:creator>
      <dc:date>2022-02-19T20:37:09Z</dc:date>
    </item>
  </channel>
</rss>

