<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: QRadar Integration Magnitude Query not returning expected results in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/qradar-integration-magnitude-query-not-returning-expected/m-p/477262#M683</link>
    <description>&lt;P&gt;Can you kindly share the integration instance settings? namely the query used for fetch. If set correctly, XSOAR should not be returning any incidents from the API with 'magnitudes' under threshold - used to filter 'fetch'&lt;BR /&gt;&lt;BR /&gt;I also suggest test query in Qradar API playground to ensure it performs as expected. If it doesn't, cross reference the search/query syntax with Qradar documentation, test again Qradar API playground, then update you integration instance in XSOAR.&lt;BR /&gt;&lt;BR /&gt;Hope this helps.&lt;/P&gt;</description>
    <pubDate>Thu, 31 Mar 2022 14:43:04 GMT</pubDate>
    <dc:creator>jgomes</dc:creator>
    <dc:date>2022-03-31T14:43:04Z</dc:date>
    <item>
      <title>QRadar Integration Magnitude Query not returning expected results</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/qradar-integration-magnitude-query-not-returning-expected/m-p/476980#M680</link>
      <description>&lt;P&gt;Got a QRadar integration.&amp;nbsp;&lt;BR /&gt;It's suppose to pull back offenses with magnitude &amp;gt; 4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, our metrics are much higher than what the client expects.&lt;BR /&gt;&lt;BR /&gt;When reviewing this case got pulled into XSOAR:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jboyd98_0-1648657803907.png" style="width: 572px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39929i21E82625B56D0A8E/image-dimensions/572x79/is-moderation-mode/true?v=v2" width="572" height="79" role="button" title="jboyd98_0-1648657803907.png" alt="jboyd98_0-1648657803907.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;However, when exporting QRadar, the incident has the following:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jboyd98_1-1648657953036.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39930iBEA610A471851EC3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jboyd98_1-1648657953036.png" alt="jboyd98_1-1648657953036.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the second column you can see magnitude has a value of 2; so in theory I don't think this should have ever created an incident within XSOAR.&lt;BR /&gt;&lt;BR /&gt;Any thoughts?&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 16:33:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/qradar-integration-magnitude-query-not-returning-expected/m-p/476980#M680</guid>
      <dc:creator>jboyd98</dc:creator>
      <dc:date>2022-03-30T16:33:43Z</dc:date>
    </item>
    <item>
      <title>Re: QRadar Integration Magnitude Query not returning expected results</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/qradar-integration-magnitude-query-not-returning-expected/m-p/477262#M683</link>
      <description>&lt;P&gt;Can you kindly share the integration instance settings? namely the query used for fetch. If set correctly, XSOAR should not be returning any incidents from the API with 'magnitudes' under threshold - used to filter 'fetch'&lt;BR /&gt;&lt;BR /&gt;I also suggest test query in Qradar API playground to ensure it performs as expected. If it doesn't, cross reference the search/query syntax with Qradar documentation, test again Qradar API playground, then update you integration instance in XSOAR.&lt;BR /&gt;&lt;BR /&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 14:43:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/qradar-integration-magnitude-query-not-returning-expected/m-p/477262#M683</guid>
      <dc:creator>jgomes</dc:creator>
      <dc:date>2022-03-31T14:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: QRadar Integration Magnitude Query not returning expected results</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/qradar-integration-magnitude-query-not-returning-expected/m-p/477296#M684</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jboyd98_0-1648741397540.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39964i4FFA68F8DF719289/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jboyd98_0-1648741397540.png" alt="jboyd98_0-1648741397540.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jboyd98_1-1648741429034.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39965i51CBF1F87CA0EBDC/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jboyd98_1-1648741429034.png" alt="jboyd98_1-1648741429034.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Whats confusing is if look at example incident&amp;nbsp;&lt;SPAN class=""&gt;201769&lt;/SPAN&gt;, the magnitude is recorded as &lt;STRONG&gt;5&lt;/STRONG&gt; under the incident's QRadar Offense tab.&lt;BR /&gt;&lt;BR /&gt;Then if I go run the following in the playground it shows a magnitude of &lt;STRONG&gt;2&lt;/STRONG&gt;.&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;!qradar-offenses-list offense_id=201769 fields=magnitude&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Magnitude&lt;/TD&gt;&lt;TD&gt;&lt;SPAN class=""&gt;2&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;BR /&gt;Not familiar with QRadar; can a user modify the magnitude of an offense?&lt;BR /&gt;Only thing I can think is that we're recording the incident when it's created and then the magnitude is changing on the qradar side.&lt;/DIV&gt;&lt;DIV class=""&gt;Though xsoar recorded 400+ incidents for March, and QRadar only has 13 offenses that are &amp;gt;4 in March.&amp;nbsp; Client says they're not changing.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 31 Mar 2022 15:53:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/qradar-integration-magnitude-query-not-returning-expected/m-p/477296#M684</guid>
      <dc:creator>jboyd98</dc:creator>
      <dc:date>2022-03-31T15:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: QRadar Integration Magnitude Query not returning expected results</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/qradar-integration-magnitude-query-not-returning-expected/m-p/477746#M685</link>
      <description>&lt;P&gt;Can a user modify the&amp;nbsp; magnitude of an offense?&lt;/P&gt;&lt;P&gt;No, This is a calculation based on the Severity, Relevance and Credibility.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the details you have given so far, there is a discrepancy between Q and XSOAR. What you can do here is to use the same query in the QR interactive API guide and find out if the returned result is the same if it is this has to be raised with QR support.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Query Examples&amp;nbsp; :&amp;nbsp;&lt;A href="https://www.ibm.com/docs/en/qsip/7.3.3?topic=api-filter-syntax" target="_blank"&gt;https://www.ibm.com/docs/en/qsip/7.3.3?topic=api-filter-syntax&lt;/A&gt;&lt;/P&gt;&lt;P&gt;API Access guide : &lt;A href="https://www.ibm.com/docs/en/qradar-on-cloud?topic=api-accessing-interactive-documentation-page" target="_blank"&gt;https://www.ibm.com/docs/en/qradar-on-cloud?topic=api-accessing-interactive-documentation-page&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Apr 2022 08:19:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/qradar-integration-magnitude-query-not-returning-expected/m-p/477746#M685</guid>
      <dc:creator>vidurasupun</dc:creator>
      <dc:date>2022-04-03T08:19:40Z</dc:date>
    </item>
  </channel>
</rss>

