<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic sentinel integration, azure-sentinel-update-incident, not able to set to active in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/sentinel-integration-azure-sentinel-update-incident-not-able-to/m-p/465607#M565</link>
    <description>&lt;P&gt;I can close an azure incident in xsoar war-room with the following:&lt;/P&gt;&lt;P&gt;!azure-sentinel-update-incident incident_id="xx-xxxxx-xxxxx" status="Closed" classification="Undetermined"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However when i try to re-open the incident in azure from war-room with the following i get the subsequent error:&lt;/P&gt;&lt;P&gt;!azure-sentinel-update-incident incident_id="xx-xxxxx-xxxxx" status="Active"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Failed to execute azure-sentinel-update-incident command. Error: [BadRequest 400] classification can only be set for incidents with status 'Closed'.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Closing a ticket in azure requires classification, where as re-opening the incident in azure "clears" the previous set classification.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;It feels like there is some sequencing issue with the xsoar "update incident" command above where it's confused about wiping / not setting the classification when re-opening the ticket.&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Goal is to be able to set an Azure Incident back to active status from xsoar war-room and then eventually script it to happen when a xsoar ticket is re-opened.&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Any insight is appreciated, thanks Boyd&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Mon, 14 Feb 2022 17:44:04 GMT</pubDate>
    <dc:creator>jboyd98</dc:creator>
    <dc:date>2022-02-14T17:44:04Z</dc:date>
    <item>
      <title>sentinel integration, azure-sentinel-update-incident, not able to set to active</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/sentinel-integration-azure-sentinel-update-incident-not-able-to/m-p/465607#M565</link>
      <description>&lt;P&gt;I can close an azure incident in xsoar war-room with the following:&lt;/P&gt;&lt;P&gt;!azure-sentinel-update-incident incident_id="xx-xxxxx-xxxxx" status="Closed" classification="Undetermined"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However when i try to re-open the incident in azure from war-room with the following i get the subsequent error:&lt;/P&gt;&lt;P&gt;!azure-sentinel-update-incident incident_id="xx-xxxxx-xxxxx" status="Active"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Failed to execute azure-sentinel-update-incident command. Error: [BadRequest 400] classification can only be set for incidents with status 'Closed'.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Closing a ticket in azure requires classification, where as re-opening the incident in azure "clears" the previous set classification.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;It feels like there is some sequencing issue with the xsoar "update incident" command above where it's confused about wiping / not setting the classification when re-opening the ticket.&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Goal is to be able to set an Azure Incident back to active status from xsoar war-room and then eventually script it to happen when a xsoar ticket is re-opened.&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Any insight is appreciated, thanks Boyd&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 14 Feb 2022 17:44:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/sentinel-integration-azure-sentinel-update-incident-not-able-to/m-p/465607#M565</guid>
      <dc:creator>jboyd98</dc:creator>
      <dc:date>2022-02-14T17:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: sentinel integration, azure-sentinel-update-incident, not able to set to active</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/sentinel-integration-azure-sentinel-update-incident-not-able-to/m-p/466987#M574</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;Further instructions were sent over the support case you've opened, since this discussion board is public- let's continue the discussion over the private support case, on which logs can be shared,&lt;BR /&gt;thanks.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Feb 2022 20:21:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/sentinel-integration-azure-sentinel-update-incident-not-able-to/m-p/466987#M574</guid>
      <dc:creator>gfilippov</dc:creator>
      <dc:date>2022-02-19T20:21:08Z</dc:date>
    </item>
    <item>
      <title>Re: sentinel integration, azure-sentinel-update-incident, not able to set to active</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/sentinel-integration-azure-sentinel-update-incident-not-able-to/m-p/467702#M580</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/208132"&gt;@jboyd98&lt;/a&gt;,&amp;nbsp;I was unable to reproduce this issue using the latest version of the Azure Sentinel content pack (&lt;SPAN&gt;1.3.1). Please make sure you have updated the pack to the latest version.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Feb 2022 01:05:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/sentinel-integration-azure-sentinel-update-incident-not-able-to/m-p/467702#M580</guid>
      <dc:creator>asawyer</dc:creator>
      <dc:date>2022-02-23T01:05:51Z</dc:date>
    </item>
  </channel>
</rss>

