<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk custom index not getting incident in xsoar in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/splunk-custom-index-not-getting-incident-in-xsoar/m-p/473025#M655</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/209890"&gt;@Manikandan_sam&lt;/a&gt;&amp;nbsp;, is this the first time you are configuring the XSOAR integration with Splunk? If yes, you may want to change the First fetch timestamp to 2 or 3 days, to capture incidents that were created before. If not, please check if certain incidents were missed while others were created, and open a support case with screenshots and logs.&lt;/P&gt;</description>
    <pubDate>Mon, 14 Mar 2022 21:45:03 GMT</pubDate>
    <dc:creator>amore</dc:creator>
    <dc:date>2022-03-14T21:45:03Z</dc:date>
    <item>
      <title>Splunk custom index not getting incident in xsoar</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/splunk-custom-index-not-getting-incident-in-xsoar/m-p/472518#M651</link>
      <description>&lt;P&gt;I am using splunk 60 day free trial non-enterprise edition and created a new custom index in splunk and manually added a sample event csv format file in the new index and all date is 2 days ago sample data&lt;/P&gt;&lt;P&gt;splunk integration with xsoar does not generate any incident, is there a configuration and timestamp problem?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2022-03-11 at 1.33.40 PM.png" style="width: 451px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39603i6AD1E3B63DFFB102/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2022-03-11 at 1.33.40 PM.png" alt="Screen Shot 2022-03-11 at 1.33.40 PM.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2022-03-11 at 1.34.28 PM.png" style="width: 608px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39602iE656D6FED6419347/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2022-03-11 at 1.34.28 PM.png" alt="Screen Shot 2022-03-11 at 1.34.28 PM.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2022-03-11 at 1.37.39 PM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39604iE68F79D9F729348C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2022-03-11 at 1.37.39 PM.png" alt="Screen Shot 2022-03-11 at 1.37.39 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Mar 2022 01:15:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/splunk-custom-index-not-getting-incident-in-xsoar/m-p/472518#M651</guid>
      <dc:creator>Manikandan_sam</dc:creator>
      <dc:date>2022-03-12T01:15:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk custom index not getting incident in xsoar</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/splunk-custom-index-not-getting-incident-in-xsoar/m-p/473025#M655</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/209890"&gt;@Manikandan_sam&lt;/a&gt;&amp;nbsp;, is this the first time you are configuring the XSOAR integration with Splunk? If yes, you may want to change the First fetch timestamp to 2 or 3 days, to capture incidents that were created before. If not, please check if certain incidents were missed while others were created, and open a support case with screenshots and logs.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Mar 2022 21:45:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/splunk-custom-index-not-getting-incident-in-xsoar/m-p/473025#M655</guid>
      <dc:creator>amore</dc:creator>
      <dc:date>2022-03-14T21:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk custom index not getting incident in xsoar</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/splunk-custom-index-not-getting-incident-in-xsoar/m-p/473118#M658</link>
      <description>&lt;P&gt;yes this is my first time integrating splunk&lt;BR /&gt;that sample log file is a data day (March 3) for testing so I loaded it into splunk add data and created a custom index&lt;/P&gt;&lt;P&gt;example:&lt;/P&gt;&lt;P&gt;that the log file data is only from March 3rd and how to use timestamp lookup and I already use that custom query in splunk config&lt;/P&gt;&lt;P&gt;when i search xsoar cli !splunk-search query="index=notes" it shows index data and i can also parse the specific url and ip field in the playbook&lt;BR /&gt;&lt;BR /&gt;So is this the proper method to use Splunk custom index to get all the data into xsoar?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Mar 2022 07:51:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/splunk-custom-index-not-getting-incident-in-xsoar/m-p/473118#M658</guid>
      <dc:creator>Manikandan_sam</dc:creator>
      <dc:date>2022-03-15T07:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk custom index not getting incident in xsoar</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/splunk-custom-index-not-getting-incident-in-xsoar/m-p/473270#M659</link>
      <description>&lt;P&gt;Hello!&lt;BR /&gt;1. Please also try encapsulating the index name as per default example when creating new instance. eg.&lt;/P&gt;&lt;P class="" data-unlink="true"&gt;search `notes` | expandtoken&lt;BR /&gt;2. Reset timestamp - unless you know you have new data coming in or within the look back windows (15mins by default)&lt;BR /&gt;3. Double check you you have latest content pack installed&lt;BR /&gt;4. double check time on your new system (sync with NTP)&lt;BR /&gt;5. You can debug a test fetch with:&amp;nbsp;&lt;SPAN&gt;!&amp;lt;instance_name&amp;gt;-fetch debug-mode=true&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;reference - xsoar.pan.dev/docs/reference/articles/troubleshooting-guide&amp;nbsp;&lt;BR /&gt;Please let us know how you go!&lt;/P&gt;</description>
      <pubDate>Tue, 15 Mar 2022 15:07:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/splunk-custom-index-not-getting-incident-in-xsoar/m-p/473270#M659</guid>
      <dc:creator>jgomes</dc:creator>
      <dc:date>2022-03-15T15:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk custom index not getting incident in xsoar</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/splunk-custom-index-not-getting-incident-in-xsoar/m-p/474338#M670</link>
      <description>&lt;P&gt;thank for the replay&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;I tried this query giving error search `notes` | expandtoken&lt;BR /&gt;if i use this query search index="notes" it works correctly but not show any data&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2022-03-18 at 8.39.38 PM.png" style="width: 998px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39743iD5BEADAC306A4741/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2022-03-18 at 8.39.38 PM.png" alt="Screen Shot 2022-03-18 at 8.39.38 PM.png" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;LI&gt;my custom data is manually created (add data) uploaded csv file&lt;BR /&gt;i also reset the time but i still don't get it&lt;/LI&gt;&lt;LI&gt;yes content pack installed&lt;/LI&gt;&lt;LI&gt;yes new system (synchronization with NTP)&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2022-03-18 at 8.58.14 PM.png" style="width: 376px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39742i61851BA95347E046/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2022-03-18 at 8.58.14 PM.png" alt="Screen Shot 2022-03-18 at 8.58.14 PM.png" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;LI&gt;checked debug mode&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2022-03-18 at 9.00.32 PM.png" style="width: 770px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39741i1A6ABFF9C865773B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2022-03-18 at 9.00.32 PM.png" alt="Screen Shot 2022-03-18 at 9.00.32 PM.png" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;my custom data is from 3rd March and time also different but i uploaded it today and 2 days ago my raw file is showing in cli command but when i changed settings again it shows empty index&lt;/P&gt;&lt;P&gt;how to change my timestamp and get data&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2022-03-18 at 9.06.56 PM.png" style="width: 548px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39744i9B1072773A090839/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2022-03-18 at 9.06.56 PM.png" alt="Screen Shot 2022-03-18 at 9.06.56 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Fri, 18 Mar 2022 12:09:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/splunk-custom-index-not-getting-incident-in-xsoar/m-p/474338#M670</guid>
      <dc:creator>Manikandan_sam</dc:creator>
      <dc:date>2022-03-18T12:09:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk custom index not getting incident in xsoar</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/splunk-custom-index-not-getting-incident-in-xsoar/m-p/474693#M674</link>
      <description>&lt;P&gt;The error indicates permission related to the Index or macro..&lt;BR /&gt;I do see you have the 'first fetch' look back to 3 months which should find data otherwise. If this was the first fetch.&lt;BR /&gt;I suggest testing the query in Splunk API directly and double check your API permissions.&amp;nbsp;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.5/RESTTUT/RESTsearches" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.5/RESTTUT/RESTsearches&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Do you get same error on your original search query without using expand token?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jgomes_0-1647874915534.png" style="width: 329px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39772iAACD0F8A46B36062/image-dimensions/329x125/is-moderation-mode/true?v=v2" width="329" height="125" role="button" title="jgomes_0-1647874915534.png" alt="jgomes_0-1647874915534.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Perhaps try that again with larger window.. like 1 month+ to cover time the data datetime range&lt;BR /&gt;&lt;BR /&gt;If XSOAR has fetched once already (the radio button for fetch in integration) then it will fetch the look back window once, then every minute (for the last minute) by default. Here you should delete instance and create a new one, so the first fetch goes back one month as configured.&amp;nbsp; First use test to ensure no permission issues. Hope this helps.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 15:11:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/splunk-custom-index-not-getting-incident-in-xsoar/m-p/474693#M674</guid>
      <dc:creator>jgomes</dc:creator>
      <dc:date>2022-03-21T15:11:10Z</dc:date>
    </item>
  </channel>
</rss>

